The whole process: How to Lose 1155 BTC in 80 Minutes
Author: 胡飞瞳 Source: https://mp.weixin.qq.com/s/jCtgFy5e5o3TxmHTOk_rLQ On the evening of May 3rd, Beijing time, due to an inadvertent operation, a whale mistakenly transferred 1155 BTC to a phishing wallet address, valued at approximately $71 million at the time of the incident. Such a large sum of money virtually evaporated in an instant, serving as a significant lesson to the industry. Chronology of Events Let’s first examine the sequence of events (May 3rd, all times in Beijing time): ● 17:14:47 — Wallet address 0x1E227979f0b5BC691a70DEAed2e0F39a6F538FD5 (whale) transferred 0.5 ETH to address 0xd9A1b0B1e1aE382DbDc898Ea68012FfcB2853a91 and created the address. ● 17:17:59 — Wallet address 0xd9A1C3788D81257612E2581A6ea0aDa244853a91 (hacker) transferred 0 ETH to wallet address 0x1E227979f0b5BC691a70DEAed2e0F39a6F538FD5. ● 18:31:35 — Wallet address 0x1E227979f0b5BC691a70DEAed2e0F39a6F538FD5 (whale) transferred 1155.28802767 WBTC to address 0xd9A1C3788D81257612E2581A6ea0aDa244853a91 by calling the WBTC contract. ● May 4th, 10:51:11 — Address 0xd9A1C3788D81257612E2581A6ea0aDa244853a91 (hacker) transferred all WBTC to a new address: 0xfB5bcA56A3824E58A2c77217fb667AE67000b7A6. Explanation Here’s a breakdown from the hacker’s perspective: 1. The hacker continuously monitored the whale’s activity on the blockchain and noticed the creation of a new address by the whale on the evening of May 3rd. The hacker immediately took action. 2. By bruteforce-randomly generating private keys and addresses, the hacker obtained an address similar to the one generated by the whale (please carefully examine the addresses highlighted in red in steps 1 and 2 above, they are identical except for minor differences). The hacker then transferred 0 ETH to the whale’s wallet address to create a transaction history containing the phishing address 0xd9A1C3788D81257612E2581A6ea0aDa244853a91. 3. Upon confirming the receipt of 0.5 ETH in their address, the whale began transferring WBTC to a new address. At this point, a fatal mistake occurred. In the transfer history, the whale found an address with the same numbers before and after as their target address and mistakenly copied and pasted the phishing address. 4. The hacker monitored their phishing address and was pleasantly surprised to find a “huge harvest” — 1155 BTC. They likely celebrated immediately, had some beers, slept, and then transferred the WBTC to another new address. Implications Have you noticed a crucial aspect? Look at the timeline. After the whale created a new address, the hacker prepared the phishing address in about 3 minutes and completed the transfer to the whale. This indicates several points: ● The hacker was well-prepared, with the entire process automated. The script was likely prepared in advance. ● The hacker had access to significant computational power. The addresses generated here share specific bytes (the first two bytes and the last three bytes), which equates to roughly 2⁴⁰ calculations. GPUs would undoubtedly be required, and in large numbers. ● Therefore, this is likely not an individual’s action but rather organized behavior. The blockchain brings decentralization and eliminates intermediaries, allowing individuals to control their wealth and data. However, it also requires a heightened sense of security. High levels of personal security awareness and knowledge are essential. This whale demonstrated strong security awareness by periodically changing addresses and conducting tests and confirmations before large transfers. However, one copy-paste mistake undid everything. Some Security Tips for Transfers This $71 million lesson serves as a wake-up call for every holder of digital assets. Hackers and phishing attempts are ubiquitous, and you are the first and only responsible party for your property. Here are some security tips for wallet security, especially for wallets holding large amounts: ● Generate private keys and mnemonic phrases offline and store them offline. ○ Most wallets now have offline signature capabilities. ○ Hardware wallets can also be used, but backup the private keys when using them. ● If there is suspicion that the private key or mnemonic phrase may be compromised, replace it as soon as possible and transfer the assets. ● Store transfer addresses in an address book and add notes. Do not copy addresses temporarily. ● Choose addresses from the address book for transfers and always perform test transfers. Confirm success with the recipient before proceeding. ● For large transfers, consider splitting them into multiple transactions. ● Do not click directly on transfer links or online transactions sent by others. ○ Phishing often involves forging similar links or addresses. ● For larger fund management, consider using multi-signature methods. ○ This is suitable for company or organization fund management. ○ Individual assets can also be managed in this way. For example, individuals can hold multiple private keys and give signing authority to friends who do not know each other to prevent loss of assets due to personal key loss. ● CEX and DEX website addresses should be obtained through official channels, and deposit addresses should be confirmed repeatedly. Test transfers are also necessary steps. Follow us Wu Blockchain is free today. But if you enjoyed this post, you can tell Wu Blockchain that their writing is valuable by pledging a future subscription. You won't be charged unless they enable payments. |
Older messages
ZK-EVM Upgrade Narrative to zkVM: Why Are These Five Core Projects Worth Attention?
Friday, May 17, 2024
By 0XNATALIE, Researcher at @ChainFeedsxyz Source: In the search for solutions to blockchain scalability and computational efficiency, zero-knowledge proof (ZKP) technology is particularly significant.
WuBlockchain Weekly: CPI Falls as Expected, El Salvador Mines 473.5 Bitcoins Using Volcano Energy, Eigen Layer Rej…
Friday, May 17, 2024
1. US April CPI YoY at 3.4% link The United States released its April non-seasonally adjusted CPI with a year-on-year rate of 3.4%, in line with expectations and unchanged from the previous value of
What is Notcoin, the rarely supported by both Binance and OKX?
Tuesday, May 14, 2024
Author: Chain Teahouse Compiled by: Wublockchain Original link:https://mp.weixin.qq.com/s/OpmeLQ39zWJPOHeeVtxAHQ 1. Project Introduction Notcoin is a click-based game on Telegram, very popular and
CEX Data Report for April: Spot trading volume decreased by 38%, while derivatives trading volume and website traf…
Monday, May 13, 2024
Data compiled by the Wublockchain team shows: In April, the spot trading volume of major exchanges decreased by 37.9% month-on-month. The top three changes were Gate +13.7%, Bitget -11.1%, and HTX-14.5
Asia's weekly TOP10 crypto news (May 6 to May 12)
Sunday, May 12, 2024
1. Hong Kong Regulatory News This Week 1.1 Issuer: Rumors of Hong Kong ETF Being Included in Shanghai-Hong Kong Stock Connect are Unfounded link The CEO of Harvestglobal, one of the issuers of Hong
You Might Also Like
Weekly Project Updates: Babylon Launches Airdrop Registration, Berachain Initiates Phase One of Governance, and Me…
Saturday, March 1, 2025
In the recent theft incident of Bybit, hackers laundered money by exchanging ETH for BTC through THORChain, bringing huge trading volume and fees to THORChain. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Bitcoin pullback could be set up for $370k bull run price target
Friday, February 28, 2025
Bitcoin's 27% slide raises prospects for rebound, aligns with historical cycle patterns. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
WuBlockchain Weekly: SEC Terminates Lawsuits Against Multiple Crypto Companies, Bitcoin Drops Below $80,000, OKX S…
Friday, February 28, 2025
On Friday, OKX market data revealed that BTC fell below $80000, reaching a low of $78258, with the current price at $80514, reflecting a 24-hour decline of 7.22%. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
FBI confirms North Korea-backed Lazarus hackers stole $1.5 billion from Bybit
Thursday, February 27, 2025
FBI tracks Ethereum laundering spree by North Korean hackers amid rising threat of cyber warfare in the crypto world. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Interview with MicroStrategy Founder Michael Saylor: The Company Holding the Most Bitcoin in the World
Thursday, February 27, 2025
In this interview, Colin from WuBlockchain had an in-depth discussion with MicroStrategy founder Michael Saylor about the company's ongoing Bitcoin acquisition strategy, the growing adoption of
Abu Dhabi Invests $436.9M In Bitcoin ETF
Thursday, February 27, 2025
February 17th, 2025 Sign Up Your Weekly Update On All Things Crypto TL;DR Abu Dhabi Invests $436.9M In Bitcoin ETF Changpeng Zhao Sparks Meme Coin Rumours Coinbase Finally Lists POPCAT & PENGU
📈 BTC’s realised price (average acquisition price) reached an all-time high of $43,000; State of Wisconsin Invest…
Thursday, February 27, 2025
BTC's realised price reached an all-time high of $43000; Abu Dhabi's Mubadala Investment disclosed its BTC ETF holdings; South Korea to allow universities and charities to sell crypto donations
HashKey Exchange's Interpretation of the Hong Kong SFC Virtual Asset Roadmap
Thursday, February 27, 2025
We are pleased to see the Hong Kong government release the forward-looking and pragmatic “ASPI-Re” roadmap for advancing the virtual asset industry. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Argentina’s stock market plummets amid President Javier Milei’s LIBRA memecoin scandal
Thursday, February 27, 2025
Argentina's economic landscape shaken as Milei's LIBRA endorsement turns into multi-billion dollar fiasco. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Heated AMA Debate: 0G Team Responds to Allegations of CFX Soft Rug, Overvaluation, and Token Commitment Concerns
Thursday, February 27, 2025
This AMA primarily focused on the relationship between Conflux and 0G Labs, discussing 0G Labs' high valuation, fundraising structure, technical direction, and community concerns over transparency.