Cointime

Download App
iOS & Android

A Reader’s Tokens Worth $88 Million Got Hacked, This Is Her Story

Validated Individual Expert

This one is wild. One of my readers reached out to me to share this. Here is a report of what happened and what you have to watch out for so that the same thing doesn’t happen to you.

To preserve her anonymity, I use a different name. With the exception of a few details, I am reporting the facts as they actually happened.

All it took was one fake smart contract to get Janice in a world of trouble.

“I was distracted and pressed OK without properly checking. And that’s how the hacker got in.”

Janice lives in the United States and started putting a part of her money into Crypto when the technology took off a couple of years ago.

To store and keep track of her assets, she used various tools such as Zapper, Rainbow, Gemini, and Gnosis Safe. Janice would let things run on autopilot for most of the time. “I left my Bitcoins and other Cryptos untouched. In March 2022 was the last time I popped in to check things and that was it.” Because she had invested a lot, Janice received a lot of payouts and the various platforms would send her notifications to keep her updated.

And that was where the problems started.

One of the messages Janice received was fake and was linked to a malicious contract. Without her noticing what was going on, a hacker used this access control exploit to get access to several of her wallets, and started draining them.

The hacker uses a malicious ERC721 smart contract.

“Every day the hacker would take the payouts I received and use some fake ERC721 contracts to put them in pools. There he used the money to scam others by minting sketchy NFTs and buying ENS-Domains.”

Because she had left her coins untouched for the most part, all of this was going on unnoticed by Janice for a long time. Until she realized that something was fishy when various Crypto platforms started to message her.

The hacker’s contract currently holds more than $88 million.

“Once I realized what was happening, I scrambled to get things back under control. I contacted all these platforms to freeze everything. Luckily, my main holdings are not affected but it still hurts to see that person steal a part of my money and use it to scam other people.”

What made the whole process more difficult to handle was the fact that Janice owned tons of different Cryptocurrencies. This made it harder to pinpoint where the problem was.

But there is more.

How did the hacker know about Janice’s holdings in the first place?

For Janice, it looks like an inside job. “Nobody knew about my Crypto holdings. I always kept a very low profile. The only ones who knew where these platforms.” Janice believes that someone working for one of the portfolio platforms and exchanges she has been using managed to plant the fake smart contract shortly after she deposited her funds.

In hindsight, leaving all her assets on different platforms was a big mistake. Not only did this give the hacker access. Due to the following freeze of all her wallets, Janice can’t access a part of her funds.

Now she has to prove that she is the rightful owner. Fortunately, Janice is a hoarder of data. She kept all the exchange logs, bank statements, tax protocols, and more. So chances are looking good.

But still, to sort things out takes a lot of time. Time which the hacker uses to steal more money from her.

“I haven’t slept much the last few nights. Putting this all back together is very exhausting and it makes me so angry.”

But Janice also takes the incident as an opportunity to learn from it — in the future she will keep my assets on hardware wallets.

Comments

All Comments

Recommended for you

  • Calculating Virtual GDP

    Cost Accounting Method

  • State of BNB Chain Q1 2024

    The metrics in this report will focus on BNB Smart Chain (BSC). BSC is an EVM-compatible, layer-1 blockchain secured by a form of Proof-of-Staked-Authority (PoSA) that combines aspects of Proof-of-Authority (PoA) and Delegated Proof-of-Stake (DPoS). In PoSA on BSC, the validator set is of fixed size and is elected by stake weight (staked plus bonded). In addition, validators must continue staking assets to secure the network, and validators chosen to produce blocks are rotated (not based on stake weight). For a full primer on the BNB Chain ecosystem, refer to our Ecosystem report.

  • Holesky SafeStake Testnet & Private mainnet: Why participate now?

    One of SafeStake’s great strengths in the last two years has undoubtedly been the hard work at the development level to deliver a highly resilient and decentralized staking framework and protocol, facilitating the onboarding of thousands of users to the fascinating world of ETH staking with DVT technology.

  • Modular Data Layer for Gaming and AI, Carv, Raises $10M in Series A Funding

    Santa Clara-based Carv has secured $10m in Series A funding led by Tribe Capital and IOSG Ventures, with participation from Consensys, Fenbushi Capital, and other investors. The company plans to use the funds to expand its operations and development efforts. Carv specializes in providing gaming and AI development with high-quality data enhanced with human feedback in a regulatory-compliant, trustless manner. Its solution includes the CARV Protocol, CARV Play, and CARV's AI Agent, CARA. The company is also preparing to launch its node sale to enhance decentralization and bolster trustworthiness.

  • The US GDP seasonally adjusted annualized rate in the first quarter was 1.6%

    The seasonally adjusted annualized initial value of US GDP for the first quarter was 1.6%, estimated at 2.5%, and the previous value was 3.4%.

  • The main culprit of China's 43 billion yuan illegal money laundering case was arrested in the UK, involved in the UK's largest Bitcoin money laundering case

    Local time in the UK, Qian Zhimin appeared in Westminster Magistrates' Court for the first time under the identity of Yadi Zhang. She was accused of obtaining, using or possessing cryptocurrency as criminal property from October 1, 2017 to this Tuesday in London and other parts of the UK. Currently, Qian Zhimin is charged with two counts of illegally holding cryptocurrency. Qian Zhimin is the main suspect in the Blue Sky Gerui illegal public deposit-taking case investigated by the Chinese police in 2017, involving a fund of 43 billion yuan and 126,000 Chinese investors. After the case was exposed, Qian Zhimin fled abroad with a fake passport and held a large amount of bitcoin overseas. According to the above Financial Times report, Qian Zhimin denied the charges of the Royal Prosecution Service in the UK, stating that she would not plead guilty or apply for bail.

  • Nigeria’s Central Bank Denies Call to Freeze Crypto Exchange Users’ Bank Accounts

    In response to the news that "the Central Bank of Nigeria has issued a ban on cryptocurrency trading and requested financial institutions to freeze the accounts of users related to Bybit, KuCoin, OKX, and Binance exchanges," the Central Bank of Nigeria (CBN) stated in a document that the CBN has not officially issued such a notice, and the public should check the official website for the latest information to ensure the reliability of the news. According to a screenshot reported by Cointelegraph yesterday, the Central Bank of Nigeria has requested all banks and financial institutions to identify individuals or entities trading with cryptocurrency exchanges and set these accounts to "Post-No-Debit" (PND) status within six months. This means that account holders will not be able to withdraw funds or make payments from these accounts. According to the screenshot, the Central Bank of Nigeria has listed cryptocurrency exchanges that have not obtained operating licenses in Nigeria, including Bybit, KuCoin, OKX, and Binance. The Central Bank of Nigeria will crack down on the illegal purchase and sale of stablecoin USDT on these platforms, especially those using peer-to-peer (P2P) transactions. In addition, the Central Bank of Nigeria pointed out that financial institutions are prohibited from engaging in cryptocurrency transactions or providing payment services to cryptocurrency exchanges.

  • Universal verification layer Aligned Layer completes $20 million Series A financing

    Ethereum's universal verification layer Aligned Layer has completed a $20 million Series A financing round, led by Hack VC, with participation from dao5, L2IV, Nomad Capital, and others. The Aligned Layer mainnet is scheduled to launch in the second quarter of 2024. As the EigenLayer AVS, Aligned Layer provides Ethereum with a new infrastructure for obtaining economically viable zero-knowledge proof verification for all proof systems.

  • The total open interest of Bitcoin contracts on the entire network reached 31.41 billion US dollars

    According to Coinglass data, the total open position of Bitcoin futures contracts on the entire network is 487,500 BTC (approximately 31.41 billion US dollars).Among them, the open position of CME Bitcoin contracts is 143,600 BTC (approximately 9.23 billion US dollars), ranking first;The open position of Binance Bitcoin contracts is 109,400 BTC (approximately 7.07 billion US dollars), ranking second.

  • Bitcoin mining difficulty increased by 1.99% to 88.1T yesterday, a record high

    According to BTC.com data reported by Jinse Finance, the mining difficulty of Bitcoin has increased by 1.99% to 88.1T at block height 840,672 (22:51:52 on April 24), reaching a new historical high. Currently, the average network computing power is 642.78EH/s.