A Hacker Has Stolen $10 Million in Ethereum and No One Knows How - Decrypt (2024)

Decrypt’s Art, Fashion, and Entertainment Hub.

Discover SCENE

A $10 million hack targeting sophisticated crypto users has top security experts baffled.

Taylor Monahan, former CEO and founder of Ethereum wallet manager MyCrypto, said on Twitter Tuesday that over 5,000 in ETH had been stolen since December.

That’s over $10.4 million-worth of crypto at today’s prices.

The worrying part? It hit hardware wallets of users who prioritized security, according to Monahan.

AD

“For the past 48 hrs I’ve been unwinding a massive wallet draining operation,” wrote Monahan, who joined MetaMask after MyCrypto was acquired by the crypto wallet’s parent company ConsenSys last year. “Folks are those who are more crypto native than most” and “reasonably secure” were hit by the draining of funds, she tweeted.

For the past 48hrs I've been unwinding a massive wallet draining operation 😳😭

I don't know how big it is but since Dec 2022 it's drained 5000+ ETH and ??? in tokens / NFTs / coins across 11+ chains.

Its rekt my friends & OGs who are reasonably secure.

No one knows how. pic.twitter.com/MafntG7RkP

— Tay 💖 (@tayvano_) April 18, 2023

In other words, these aren’t crypto newbies clicking on obvious phishing links that are being drained. The attack is far more sophisticated than that, and it’s OGs who are being “rekt,” Monahan explained. “No one knows how.”

The security team behind popular crypto wallet MetaMask told Decrypt that the “unidentified exploit” hit crypto users “including, but not limited, to MetaMask users.”

AD

AD

“The on-chain behavior heavily suggests a private key compromise,” they said.

“What current investigations are showing is that it seems that this specific attack vector is pointing towards these users’ secret recovery phrases being compromised somewhere down the line, likely due to unintentionally insecure storage of said phrase.”

Private keys are used by crypto users to access their funds stored in a wallet—be it digital or physical—and authorize transactions.

Monahan also said that the attack targeted funds held on wallets created from 2014-2022. “My best guess [right now] is that someone has got themselves a fatty cache of data from 1+ [years] ago [and] is methodically draining the keys as they parse them from the treasure trove,” Monahan tweeted. She emphasized that, however, that this is only a guess, and no one yet has been able to “determine the source of their compromise.”

Her best advice? “Please don’t keep all your assets in a single key or secret phase for years,” she said.

MetaMask’s security team added that in order to protect funds, users must not store their private keys anywhere online or on any “internet-enabled device.”

“If you ever get to the point where your wallet is so old that you can’t remember if you’ve been 100% diligent with its keys at all times, then consider creating a new wallet,” they added.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

A Hacker Has Stolen $10 Million in Ethereum and No One Knows How - Decrypt (2024)
Top Articles
[Solved] In which country, Port Gwadar is located?
I. FINRA, Inc. | FINRA.org
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Energy Healing Conference Utah
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Movies - EPIC Theatres
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Holzer Athena Portal
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Nfsd Web Portal
Selly Medaline
Latest Posts
Article information

Author: Prof. Nancy Dach

Last Updated:

Views: 6221

Rating: 4.7 / 5 (77 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Prof. Nancy Dach

Birthday: 1993-08-23

Address: 569 Waelchi Ports, South Blainebury, LA 11589

Phone: +9958996486049

Job: Sales Manager

Hobby: Web surfing, Scuba diving, Mountaineering, Writing, Sailing, Dance, Blacksmithing

Introduction: My name is Prof. Nancy Dach, I am a lively, joyous, courageous, lovely, tender, charming, open person who loves writing and wants to share my knowledge and understanding with you.