Attacker takes over multisig minutes after creation, drains up to $40M slowly

cointelegraphPublished on 2025-12-18Last updated on 2025-12-18

Abstract

A crypto attacker took control of a multisig wallet just minutes after its creation 44 days ago, ultimately draining up to an estimated $40 million. Blockchain analysis reveals the wallet was created by the victim on November 4th, but ownership was transferred to the attacker only six minutes later. The attacker then patiently drained and laundered the funds in stages, using Tornado Cash over several weeks. Security experts note the wallet was configured as a "1-of-1" multisig, requiring only one signature, which defeats its purpose. Possible attack vectors include malware, phishing, or poor security practices like storing keys in plaintext. The incident highlights growing security concerns, especially as new research shows AI models are already capable of autonomously finding and exploiting smart contract vulnerabilities.

A crypto attacker apparently took over a whale’s multisig wallet minutes after it was created 44 days ago, and has been draining and laundering funds in stages since.

In a Thursday post on X, blockchain security firm PeckShield reported that a whale’s multisig wallet had been drained of roughly $27.3 million due to a private key compromise. PeckShield noted that the attacker has laundered about $12.6 million, or 4,100 Ether (ETH), through Tornado Cash and retained around $2 million in liquid assets, while also controlling a leveraged long position on Aave (AAVE).

However, new findings from Yehor Rudytsia, head of forensic at Hacken Extractor, indicate the total losses may exceed $40 million and that the incident likely began much earlier, with first signs of theft dating back as far as Nov. 4.

Rudytsia told Cointelegraph that the multisig wallet labeled as “compromised” may never have been meaningfully controlled by the victim. Onchain data shows the multisig was created by the victim’s account on Nov. 4 at 7:46 am UTC, but ownership was transferred to the attacker just six minutes later. “Very likely the theft actor created this multisig and transferred funds there, then promptly swapped the owner to be himself,” Rudytsia said.

Attacker laundering funds in batches. Source: PeckShield

Related: Spear phishing is North Korean hackers’ top tactic: How to stay safe

Attacker plays the long game

Once in control, the attacker appears to have acted patiently. They made Tornado Cash deposits in batches over several weeks, starting with 1,000 ETH on Nov. 4 and continuing through mid-December in smaller, staggered transactions. Around $25 million in assets also remains on the multisig still controlled by the attacker, according to Rudytsia.

He also raised concerns about the wallet structure. The multisig was configured as a “1-of-1,” meaning only a single signature was required to approve transactions, “which is not a multisig conceptually,” Rudytsia added.

Abdelfattah Ibrahim, a decentralized application (DApp) auditor at Hacken, said several attack vectors remain possible. These include malware or infostealers on the signer’s device, phishing attacks that trick users into approving malicious transactions, or poor operational security practices such as storing keys in plaintext or using the same machine for multiple signers.

“Preventing this would involve isolating signing devices as cold devices and verifying transactions beyond the UI,” Ibrahim said.

Related: Balancer community proposes plan to distribute funds recovered from hack

AI models capable of smart contract exploits

As Cointelegraph reported, a recent research by Anthropic and the Machine Learning Alignment & Theory Scholars (MATS) group found that today’s leading AI models are already capable of developing real, profitable smart contract exploits.

In controlled tests, Anthropic’s Claude Opus 4.5, Claude Sonnet 4.5 and OpenAI’s GPT-5 collectively generated exploits worth $4.6 million, showing that autonomous exploitation is technically feasible using commercially available models.

In further testing, Sonnet 4.5 and GPT-5 were deployed against nearly 2,850 recently launched smart contracts with no known vulnerabilities. The models uncovered two previously unknown zero-day flaws and produced exploits worth $3,694, slightly more than the $3,476 API cost required to generate them.

Magazine: 2026 is the year of pragmatic privacy in crypto — Canton, Zcash and more

Related Questions

QHow much was initially reported to be stolen from the multisig wallet, and through which service were the funds laundered?

AInitially, roughly $27.3 million was reported stolen, and the funds were laundered through Tornado Cash.

QAccording to Yehor Rudytsia, what was the critical flaw in the multisig wallet's configuration that made it vulnerable?

AThe multisig was configured as a '1-of-1,' meaning only a single signature was required to approve transactions, which is not a true multisig and provided no security benefit.

QWhat does the on-chain data reveal about the timing of the attacker taking control of the wallet relative to its creation?

AThe on-chain data shows the multisig was created by the victim's account on Nov. 4 at 7:46 am UTC, but ownership was transferred to the attacker just six minutes later.

QWhat are some of the possible attack vectors that could have led to this private key compromise, as suggested by Abdelfattah Ibrahim?

APossible attack vectors include malware or infostealers on the signer’s device, phishing attacks, or poor operational security practices like storing keys in plaintext or using the same machine for multiple signers.

QWhat did research from Anthropic and MATS demonstrate about the capabilities of current AI models regarding smart contracts?

AThe research found that leading AI models like Claude Opus 4.5 and GPT-5 are capable of developing real, profitable smart contract exploits, generating a total of $4.6 million in exploits in controlled tests.

Related Reads

You Bet on the News, the Pros Read the Rules: The True Cognitive Gap in Losing Money on Polymarket

The article explains that the key to profiting on Polymarket, a prediction market platform, lies not just predicting real-world events correctly, but in meticulously understanding the specific rules that govern how each market will be resolved. It illustrates this with examples, such as a market on Venezuela's 2026 leader, where the official rules defining "officially holds" the office overruled the intuitive answer of who was in practical control. Other examples include debates over the definition of a "token" or what constitutes an "agreement." The core argument is that a "reality vs. rules" gap creates pricing discrepancies that savvy traders ("车头" or "whales") exploit. The platform has a formal dispute resolution process managed by UMA token holders to settle ambiguous outcomes. This process involves proposal submission, a challenge window, a discussion period, and a final vote. However, the article highlights a critical flaw in this system compared to a traditional court: the lack of separation between the arbiters (UMA voters) and the interested parties (traders with financial stakes in the outcome). This conflict of interest undermines the discussion phase, leads to herd mentality, and results in opaque final decisions without explanatory rulings. Consequently, the system lacks a body of precedent, making it difficult for users to learn from past disputes. The ultimate takeaway is that success on Polymarket requires a lawyer-like scrutiny of the rules to identify and capitalize on the cognitive gap between how events appear and how they are contractually defined for settlement.

marsbit58m ago

You Bet on the News, the Pros Read the Rules: The True Cognitive Gap in Losing Money on Polymarket

marsbit58m ago

Trading

Spot
Futures

Hot Articles

What is DOGE M

Doge Matrix ($doge m): The New Breed of Community-Driven Cryptocurrency Introduction In the ever-evolving landscape of cryptocurrency, new projects constantly emerge, each aiming to capture the interest of investors and enthusiasts alike. One of the latest entrants to this domain is Doge Matrix, represented by the ticker symbol $doge m. This project has attracted attention thanks to its roots in the popular meme culture surrounding Dogecoin, establishing its place within the web3 space. This article aims to provide a comprehensive analysis of Doge Matrix, covering its overview, creator, investors, functionality, timeline, and notable aspects. What is Doge Matrix ($doge m)? Doge Matrix is a community-driven cryptocurrency project that seemingly builds upon the widespread appeal of Dogecoin, a digital currency known for its Shiba Inu mascot and its meme origins. While the overarching objectives of Doge Matrix are not extensively defined, it is characterised by a commitment to harnessing community involvement and support. Unlike traditional cryptocurrencies that often emphasise utility or intrinsic value through underlying technologies, Doge Matrix positions itself within a space that embraces the cultural phenomenon of cryptocurrencies, particularly appealing to those who resonate with the ethos of meme-based assets. Drawing on the strengths of the Dogecoin community, Doge Matrix operates as part of a broader ecosystem, inviting participation and engagement from users who share an interest in cryptocurrency and the digital landscape. Who is the Creator of Doge Matrix ($doge m)? The identity of the creator of Doge Matrix remains unknown. This lack of transparency is not an uncommon occurrence in the cryptocurrency space, where some projects are launched without revealing the identities of their founders. The absence of information regarding the founding team can raise questions among potential investors about the project’s accountability and direction. Who are the Investors of Doge Matrix ($doge m)? As it stands, there is no publicly available information detailing the investors or investment foundations that back Doge Matrix. The project appears to rely primarily on community support rather than institutional investment. This model aligns with the community-driven nature of the initiative, fostering an environment where the direction of the project is shaped by its participants rather than being dictated by a select few financial backers. How Does Doge Matrix ($doge m) Work? The specifics regarding the operational mechanisms of Doge Matrix are somewhat vague, reflecting a broader trend of projects in the meme coin space where innovative functionalities are not always clearly articulated. Nonetheless, Doge Matrix seems designed to tap into the existing cryptocurrency ecosystem by encouraging user participation while tapping into the familiar cultural references associated with Dogecoin. Its potentially unique characteristics derive from community interactions rather than technological advancements, emphasising shared experiences and collaboration among token holders. While the exact innovations have not been explicitly outlined, the project appears to create a space where community members can engage, share ideas, and propel the project's potential forward. Timeline of Doge Matrix ($doge m) Reflecting on the project’s timeline reveals notable events that have defined its journey thus far: November 25, 2024: Doge Matrix reached its all-time high value, marking a significant milestone in its early history. January 1, 2025: Conversely, Doge Matrix hit its all-time low value, illustrating the volatility often associated with cryptocurrencies, especially in the early stages of a project's lifecycle. Ongoing: The project continues to be actively traded and supported by its community, although specific future milestones or objectives have yet to be disclosed. Key Points About Doge Matrix ($doge m) Community Focus At the heart of Doge Matrix is a commitment to community engagement. The project thrives on the premise of collaboration and shared objectives among its members, emphasising the importance of collective effort. Unlike centralised projects that often have a defined leadership structure, Doge Matrix at present showcases a more fluid approach to governance, where every community member's voice matters. Volatility The cryptocurrency market is notorious for its volatility, and Doge Matrix is no exception. Its price history reflects significant fluctuations between high and low values, which is typical of many new cryptocurrencies but underscores the risks associated with investment in emerging tokens. Lack of Detailed Information One of the most striking features about Doge Matrix is the scarcity of detailed information regarding its technological underpinnings and operational mechanisms. This ambiguity necessitates that potential investors conduct thorough due diligence before engaging with the project. Conclusion In summary, Doge Matrix ($doge m) illustrates a new wave of cryptocurrency projects that lean heavily on community engagement and cultural relevance. While lacking in certain specifics—such as clear leadership, defined objectives, and detailed functionality—the project has managed to generate interest within the crypto community, leveraging the established appeal of meme culture. As with any investment in the cryptocurrency space, understanding the inherent risks and conducting comprehensive research is essential for potential participants. Doge Matrix stands as a reminder of the dynamic, sometimes unpredictable nature of the crypto industry, marked by constant evolution and enthusiasm for community-driven initiatives.

363 Total ViewsPublished 2025.02.03Updated 2025.02.03

What is DOGE M

What is $M

Understanding Mantis ($M): A New Era in Cross-Chain Interoperability In the continually evolving landscape of Web3 and cryptocurrency, new projects strive to offer innovative solutions aimed at enhancing the user experience and expanding functional possibilities within the decentralised financial ecosystem. One such project garnering attention is Mantis ($M), a pioneering protocol founded on the principles of cross-chain interoperability and intent-based settlements. This article delves into the essential aspects of Mantis, including its core functionality, creators, investment backing, innovative features, and critical milestones. What is Mantis ($M)? Mantis is described as a multi-domain intent settlement protocol that simplifies cross-chain interactions, enabling users to execute complex financial transactions across various blockchain platforms seamlessly. The protocol operates through three primary layers: Intent Expression: Users can articulate their transaction goals using natural language facilitated by the DISE LLM, an advanced AI language model. For instance, a user might express a desire to swap Ethereum (ETH) for Solana (SOL) with a specific slippage tolerance of 1%. Execution: This layer employs a network of solvers that compete to fulfil user intents. Transactions are executed using mechanisms such as Coincidence of Wants (CoWs) and Order Flow Auctions (OFAs), which ensure that user demands are met optimally. Settlement: Leveraging the Inter-Blockchain Communication (IBC) protocol, Mantis enables atomic cross-chain transactions, allowing users to operate across various supported chains, including Ethereum, Solana, and Cosmos. Mantis is engineered to introduce native yield generation for idle assets, employing cryptographic proofs to maintain the integrity of transactions throughout the entire process. Creators & Development Team Mantis was conceived by the Composable Foundation, a research-driven organisation notable for its emphasis on blockchain interoperability solutions. This foundation collaborates with esteemed academic institutions, including Harvard University and the University of Lisbon, contributing to extensive research and development efforts that inform Mantis's architecture and functionality. The Composable Foundation’s commitment to fostering innovation in the blockchain space positions Mantis as a robust solution for the growing demand for interoperability among multiple blockchain networks. Investors & Backing While specific details about individual investors have not been publicly disclosed, Mantis enjoys substantial backing from various entities, including: Ecosystem grants from IBC-enabled chains, which support the protocol's growth and integration within decentralised finance ecosystems. Strategic partnerships with infrastructure providers that enhance Mantis's network capabilities and deployment strategies. Funding through the Composable Foundation's treasury, ensuring sustained financial support for ongoing development and operational costs. These collaborative efforts reflect a consensus among stakeholders about the importance of enhancing cross-chain functionality and the potential utility of Mantis's infrastructural innovations. Key Innovations Mantis sets itself apart through several pioneering innovations that enhance its functionality and utility: Chain-Agnostic Intents: Users can initiate transactions from any supported chain while settling on another. This flexibility empowers users, driving increased interaction among different platforms. AI-Powered Interface: The integration of DISE LLM allows users to conduct complex DeFi operations using natural language, thereby simplifying interactions and making blockchain technology accessible to a broader audience. Cross-Domain MEV Capture: Mantis creates an internal market for maximal extractable value (MEV) through competitions among solvers. This innovative approach allows for greater efficiency and value extraction in complex transactions. Modular Settlement Layer: The protocol supports various verification methods, including zero-knowledge proofs and optimistic rollups, providing a versatile framework that can adapt to emerging blockchain technologies. Historical Timeline Mantis's development is marked by several critical milestones that chart its trajectory and growth: | Year | Milestone | |————|————————————————————————-| | 2022 | Initial concept development within the Composable Foundation's research division. | | Q3 2024 | Launch of the testnet with bridging capabilities between Solana and Ethereum. | | Q1 2025 | Anticipated Token Generation Event (TGE) alongside the mainnet launch. | | Q2 2025 | Expected integration of DISE LLM and expansion of cross-chain capabilities. | | 2025 H2 | Planned support for over 15 chains through further IBC upgrades. | This timeline outlines Mantis's evolution, from conceptual discussions to active implementation and future growth phases. Ecosystem Growth Strategy Mantis's strategy for ecosystem growth includes several initiatives designed to encourage user participation and developer engagement: Credits System: Users can earn protocol credits by providing liquidity and engaging in referral programmes. These credits are redeemable for incentives in the future, fostering a robust user community. Modular Software Development Kit (SDK): This toolkit empowers developers to create applications based on intent-driven models utilising Mantis's infrastructure, thus promoting innovation within its ecosystem. Governance Model: As the protocol matures, $M token holders will have a voice in protocol governance, allowing them to vote on proposed upgrades and changes, thereby enhancing community engagement and decentralisation. Mantis represents a significant advancement in the realm of cross-chain architecture. By seamlessly integrating advanced AI algorithms with a robust settlement framework, Mantis seeks to tackle the problems of fragmentation within multi-chain ecosystems. Its innovative approach prioritises improved user experiences while adhering to the foundational principles of decentralisation and security, setting a new standard for the future interoperability of blockchain technologies. As Mantis continues its journey of growth and implementation, it promises to be a project to watch closely in the competitive landscape of Web3 and decentralised finance. With its focus on crossing boundaries and elevating user engagement, Mantis is poised to be an integral part of the future developments in the cryptocurrency space.

41 Total ViewsPublished 2025.03.18Updated 2025.03.18

What is $M

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of M (M) are presented below.

活动图片