‼️ $550,017 stolen due to signing a malicious approval
The funds were split across 3 wallets, in an 80/15/5 cut
Funds getting auto-split like this is typical for a drainer-as-a-service
Wallet 1 (80%, probably the worker):
Swapped a small part to $ETH and left it there
Rest was bridged and a small test amount has already gone through one swap service (likely a test)
0x98b2761559A348968C994D9856dCfc96B6f13C55
Wallet 2 (15%, probably the drainer operator):
Swapped everything to $ETH and hasn't moved since
0x93b6B24DC6E6a1D5d72399e3A35498c4DbA1d6D1
Wallet 3 (5%, likely also part of the operator's team):
Same pattern, swapped to $ETH and hasn't moved
0x8e3F313f791Ac8Cc3F1617FfA85f92Ab35C9Dd2e
You buy a hardware wallet to keep your keys offline, only to have the company leak your personal info to the world.
This is where Cupcake by Cake Wallet shines. It runs on your old second phone. That's it. No new device. No data leaks. Just privacy.
The US government just filed a lawsuit to arrest an ETH crypto wallet (address 0xf322a3328f617b9f3d44a088373d1106b6c5e97e).
It currently holds $2,117,677.97 in USDT.
Why? The funds are allegedly the proceeds of another crypto pig-butchering scam operation.
Yesterday we re-run a check which aims to detect which exchanges from https://t.co/JQY2pcYTIG are affiliated with each other
The check revealed two clusters:
- QuickEx – Swapgate
- BitXchange – ETZ-Swap – Explace – MIXED – NeverKYC – OctoSwap – PegasusSwap
🚨 $24.15M USDC drained from an Arbitrum bridge — — 5 compromised keys
5 hot-validator signatures carried 7,142/10,000 power (>2/3 quorum). The contract did exactly what it was told — the keys were
the weak point.
Two-phase attack, both traced on-chain:
1⃣ Propose (carries the 5 sigs + full 7-validator set, powers sum to 10,000)
2⃣ 200s dispute window → Execute (releases 24.15M USDC, bridged out via CCTP)
Sigs are in the propose tx, not the withdrawal tx 👇
Propose: https://t.co/cvDGFLObZX
Execute: https://t.co/MRC2x7qWPt
Stolen funds: 0x627654B2782bfC57580ecD11d40869b350B6ebAC now on ETH chain. 12,467.43703738 ETH
YOU CAN FORM A COMPANY WITH $XMR!?
THIS IS FUCKING HUGE FOR THE SPACE @Anon_Firm.
A COMPLETE PRIVATE PROCESS AND YOU EVEN GET A MAILING ADDRESS FROM THEM
ANON FIRM KEEPS WHO FORMED THE COMPANY, HOW MUCH MONEY IT EARNS, THE REAL ADDRESS AND PHONE NUMBER PRIVATE
Use Code Mav or tell them Mav sent you for 10% off 👀🔥
⚠️ JUST IN: The Tornado Cash 100 ETH pool now holds 222.3K ETH ($392M+)
Stolen cryptocurrency from two of the largest exploits this year is being laundered via Tornado Cash in real time, with millions being deposited every hour.
HE SWAPPED $2 MILLION OF ETH FOR LIT - AND LOST IT ALL
Trader 0xfF8 withdrew $2M of ETH from Binance, then swapped his entire stack to LIT. He received $14.1K of LIT.
He lost 99% of his funds because the 0x router sent his order through a low liquidity AVAIL pool. Titan Builder’s MEV bot backran his trade and profited $2M.
As we approach our final whitepaper V3 release and launch I present the official launch specs for @MoneroUSD .
-Maximum privacy at every layer
-Fast txs and finality
-High TPS (Visa class)
-“Free” tx fees. (Miners are paid through reserve yields).
Also more surprises 😉.
MONERO AUDIT COMING
The same researcher that discovered Zcash bug will look into Monero codebase.
We welcome this audit and are going to donate to the effort.
Monero has already been one of the most attacked crypto ecosystems over the years.
This audit by one of the leading experts in the field would strengthen its place in privacy space.
FBI, Europol, IRS, CipherTrace, Chainalysis, and Elliptic have all tried to break Monero's privacy,
six of the most well-funded surveillance operations on Earth,
and they're still publishing research papers instead of arrests.