The whole process: How to Lose 1155 BTC in 80 Minutes
Author: 胡飞瞳 Source: https://mp.weixin.qq.com/s/jCtgFy5e5o3TxmHTOk_rLQ On the evening of May 3rd, Beijing time, due to an inadvertent operation, a whale mistakenly transferred 1155 BTC to a phishing wallet address, valued at approximately $71 million at the time of the incident. Such a large sum of money virtually evaporated in an instant, serving as a significant lesson to the industry. Chronology of Events Let’s first examine the sequence of events (May 3rd, all times in Beijing time): ● 17:14:47 — Wallet address 0x1E227979f0b5BC691a70DEAed2e0F39a6F538FD5 (whale) transferred 0.5 ETH to address 0xd9A1b0B1e1aE382DbDc898Ea68012FfcB2853a91 and created the address. ● 17:17:59 — Wallet address 0xd9A1C3788D81257612E2581A6ea0aDa244853a91 (hacker) transferred 0 ETH to wallet address 0x1E227979f0b5BC691a70DEAed2e0F39a6F538FD5. ● 18:31:35 — Wallet address 0x1E227979f0b5BC691a70DEAed2e0F39a6F538FD5 (whale) transferred 1155.28802767 WBTC to address 0xd9A1C3788D81257612E2581A6ea0aDa244853a91 by calling the WBTC contract. ● May 4th, 10:51:11 — Address 0xd9A1C3788D81257612E2581A6ea0aDa244853a91 (hacker) transferred all WBTC to a new address: 0xfB5bcA56A3824E58A2c77217fb667AE67000b7A6. Explanation Here’s a breakdown from the hacker’s perspective: 1. The hacker continuously monitored the whale’s activity on the blockchain and noticed the creation of a new address by the whale on the evening of May 3rd. The hacker immediately took action. 2. By bruteforce-randomly generating private keys and addresses, the hacker obtained an address similar to the one generated by the whale (please carefully examine the addresses highlighted in red in steps 1 and 2 above, they are identical except for minor differences). The hacker then transferred 0 ETH to the whale’s wallet address to create a transaction history containing the phishing address 0xd9A1C3788D81257612E2581A6ea0aDa244853a91. 3. Upon confirming the receipt of 0.5 ETH in their address, the whale began transferring WBTC to a new address. At this point, a fatal mistake occurred. In the transfer history, the whale found an address with the same numbers before and after as their target address and mistakenly copied and pasted the phishing address. 4. The hacker monitored their phishing address and was pleasantly surprised to find a “huge harvest” — 1155 BTC. They likely celebrated immediately, had some beers, slept, and then transferred the WBTC to another new address. Implications Have you noticed a crucial aspect? Look at the timeline. After the whale created a new address, the hacker prepared the phishing address in about 3 minutes and completed the transfer to the whale. This indicates several points: ● The hacker was well-prepared, with the entire process automated. The script was likely prepared in advance. ● The hacker had access to significant computational power. The addresses generated here share specific bytes (the first two bytes and the last three bytes), which equates to roughly 2⁴⁰ calculations. GPUs would undoubtedly be required, and in large numbers. ● Therefore, this is likely not an individual’s action but rather organized behavior. The blockchain brings decentralization and eliminates intermediaries, allowing individuals to control their wealth and data. However, it also requires a heightened sense of security. High levels of personal security awareness and knowledge are essential. This whale demonstrated strong security awareness by periodically changing addresses and conducting tests and confirmations before large transfers. However, one copy-paste mistake undid everything. Some Security Tips for Transfers This $71 million lesson serves as a wake-up call for every holder of digital assets. Hackers and phishing attempts are ubiquitous, and you are the first and only responsible party for your property. Here are some security tips for wallet security, especially for wallets holding large amounts: ● Generate private keys and mnemonic phrases offline and store them offline. ○ Most wallets now have offline signature capabilities. ○ Hardware wallets can also be used, but backup the private keys when using them. ● If there is suspicion that the private key or mnemonic phrase may be compromised, replace it as soon as possible and transfer the assets. ● Store transfer addresses in an address book and add notes. Do not copy addresses temporarily. ● Choose addresses from the address book for transfers and always perform test transfers. Confirm success with the recipient before proceeding. ● For large transfers, consider splitting them into multiple transactions. ● Do not click directly on transfer links or online transactions sent by others. ○ Phishing often involves forging similar links or addresses. ● For larger fund management, consider using multi-signature methods. ○ This is suitable for company or organization fund management. ○ Individual assets can also be managed in this way. For example, individuals can hold multiple private keys and give signing authority to friends who do not know each other to prevent loss of assets due to personal key loss. ● CEX and DEX website addresses should be obtained through official channels, and deposit addresses should be confirmed repeatedly. Test transfers are also necessary steps. Follow us Wu Blockchain is free today. But if you enjoyed this post, you can tell Wu Blockchain that their writing is valuable by pledging a future subscription. You won't be charged unless they enable payments. |
Older messages
ZK-EVM Upgrade Narrative to zkVM: Why Are These Five Core Projects Worth Attention?
Friday, May 17, 2024
By 0XNATALIE, Researcher at @ChainFeedsxyz Source: In the search for solutions to blockchain scalability and computational efficiency, zero-knowledge proof (ZKP) technology is particularly significant.
WuBlockchain Weekly: CPI Falls as Expected, El Salvador Mines 473.5 Bitcoins Using Volcano Energy, Eigen Layer Rej…
Friday, May 17, 2024
1. US April CPI YoY at 3.4% link The United States released its April non-seasonally adjusted CPI with a year-on-year rate of 3.4%, in line with expectations and unchanged from the previous value of
What is Notcoin, the rarely supported by both Binance and OKX?
Tuesday, May 14, 2024
Author: Chain Teahouse Compiled by: Wublockchain Original link:https://mp.weixin.qq.com/s/OpmeLQ39zWJPOHeeVtxAHQ 1. Project Introduction Notcoin is a click-based game on Telegram, very popular and
CEX Data Report for April: Spot trading volume decreased by 38%, while derivatives trading volume and website traf…
Monday, May 13, 2024
Data compiled by the Wublockchain team shows: In April, the spot trading volume of major exchanges decreased by 37.9% month-on-month. The top three changes were Gate +13.7%, Bitget -11.1%, and HTX-14.5
Asia's weekly TOP10 crypto news (May 6 to May 12)
Sunday, May 12, 2024
1. Hong Kong Regulatory News This Week 1.1 Issuer: Rumors of Hong Kong ETF Being Included in Shanghai-Hong Kong Stock Connect are Unfounded link The CEO of Harvestglobal, one of the issuers of Hong
You Might Also Like
Hong Kong lawmaker advocates including Bitcoin in national reserves
Monday, December 30, 2024
Wu Jie believes Hong Kong's strategic move towards Bitcoin integration could enhance economic resilience and attract innovative businesses. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Fair Release: Saviour of VC-Backed Tokens from Low-Float High-FDV
Monday, December 30, 2024
We embrace Bitcoin for how it saves the world economy from money-printing, yet in Web3/crypto, we're practising exactly what we preach against: token-printing through time-scheduled unlocks. ͏ ͏ ͏
The Best Performing Cryptocurrency Assets Of 2024
Monday, December 30, 2024
Monday Dec 30, 2024 Sign Up Your Weekly Update On All Things Crypto TL;DR In this issue, we dive into: The Best Performing Cryptocurrency Assets Of 2024 Bitcoin Floats Around $95K As Altcoins Stay In
Kimchi premium recovers as KRWUSD drops to 15-year low
Sunday, December 29, 2024
As the won depreciates, economic and political uncertainty in South Korea widen the kimchi premium gap. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
On-chain predictions for 2025: AI-agent, Pumpfun, Base, and Hypeliquid updates
Sunday, December 29, 2024
The year 2024 could potentially be the most significant year for on-chain development since the DeFi Summer, with narrative-driven investment opportunities emerging frequently on-chain. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
XRP Ledger shows signs of increasing usage, suggesting XRP price increase
Saturday, December 28, 2024
As the velocity metric nears a breakout on the descending trend line, XRP price could start an upward movement. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Top 10 Project News of 2024: Predictive Markets Shine in the Elections, Ethena Pioneers a New Paradigm for Stablec…
Saturday, December 28, 2024
In the 2024 US presidential election, the decentralized prediction market platform Polymarket once again demonstrated its remarkable foresight, successfully predicting the final outcome through the
BlackRock doubles down on IBIT exposure through its Global Allocation Fund
Friday, December 27, 2024
The fund now holds over $17 million worth of shares from the spot Bitcoin ETF, which is among the 35 largest funds to ever launch. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
WuBlockChain's Top 10 News of 2024: Spot ETFs for Bitcoin and Ethereum Approved, Trump Secures Presidency with Str…
Friday, December 27, 2024
Bitcoin reached an all-time high of $107796 around 2:00 AM on December 17. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Let's make money from crypto WITHOUT trading
Friday, December 27, 2024
CRYPTODAY 139 ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏