MultiversX Tracker is Live!

$6.28M in stETH and aEthWBTC Stolen Today

All Cryptocurrencies

by COINS NEWS 13 Views

$6.28M in stETH and aEthWBTC Stolen Today

Early this AM a single victim lost about 6.28M from a phishing scam. This might be the single biggest TVL from a wallet drainer this year.

This appears to be the work of Inferno/Angel Drainer.

Wallets

  • 0x0d18D7C855668EB1Ba06005b199838F38E00D7e3 - 6.28M user
  • 0x9d606626888142029dFea0B20dcfE298FfDb9e4F - Malicious Inferno/Angel Contract
  • 0xa2e8Dfc32767f43611ABb43F66308E7Eb9C224F8 - Inferno/Angel ADMIN Wallet
  • 0x1623915E35Ed39Bfa381010Ce224f89734889aC9 - Inferno/Angel Customer Wallet

How did this Scam Happen?

Above is a breakdown of one of the theft transactions on Etherscan. There's an 80/20 split in favor of the CUSTOMER.

Most of these phishing scams tend to take place when a user mistakenly interacts with a malicious contract or website. In recent times, I've seen a lot of fake websites popup on the Google Search portal where the user is tricked into giving token approval for their assets.

The victim here is clearly a Whale, he may of been of victim of a "Spearphishing attack". The user lost all of their stETH and aEthWBTC, which represented the largest value tokens the user had in their walllet.

Following the Funds

There's been a lot of on-chain movement from when the funds were initially moved. Big hacks/scams like this tend to attract the attention of many cybersecurity professionals. Here's what I'm seeing so far.

Above is a look inside the User's wallet. I pulled out the transactions related to the theft and labeled in the image above. Much of the stolen funds are ending up in BTC or on TRON.

The funds continue to be laundered as I write this post. I'll focus on the information I have now. I'll go back and update if anymore interesting activity takes place.

Angel/Inferno Drainer Admin

The Angel/Inferno ADMIN funds tend to get moved very methodically, UNLESS, there's a big heist like this one.

I'm showing most of the funds from the initial theft wallet of 0xa2e8Dfc32767f43611ABb43F66308E7Eb9C224F8 - Inferno/Angel ADMIN Wallet, (about 1MM) is sitting in ETH here - 0xA0578383aCdcBAc22614d78aF73532fa40e8FEa8.

There's other decentralized wallets with about 200K - 300K in ETH owned by the Inferno/Angel ADMIN as well. I marked those off in the chart below.

Above is a look at movement from 0xa2e8Dfc32767f43611ABb43F66308E7Eb9C224F8 - The Inferno/Angel ADMIN wallet. Much of the funds are sitting in decentralized wallets in ETH, waiting to be laundered. Others have already been laundered through 1inch Protocol.

A small portion of the funds, about 200K worth of ETH, were sent to 1inch a few hours for the next phase of the laundering process.

Angel/Inferno Customer

The bulk of the user's funds went to the Customer, about 80%. Customers of drainer platforms tend to want to launder funds as soon as possible. This particular Customer has been VERY busy since the beginning of the post.

Here's the information I have so far.

Most of the funds the Customer received is currently staked on LIDO in the form of stETH.

Above is a look at the most recent txns inside 0x1623915E35Ed39Bfa381010Ce224f89734889aC9 - Inferno/Angel Customer Wallet. The Customer staked about 753 on LIDO while the rest of the funds were laundered out to various networks.

The rest of the funds were laundered with various methods. I'm showing about 110 ETH going directly to Tornado Cash, 83 ETH getting routed through Bridgers, and about 110 ETH through Near Intent.

Some of the funds go to Bridgers/Near Intent then Tornado Cash. For example, the Near Intent outputs land in BTC here - bc1quzjv00c5vsalcst4dj0p8p2r5rwchat89aamwe, swapped back to ETH, then sent to Tornado Cash.

Additionally, some of the funds end up on the TRON network landing in TRX here - TEuR8RSWJMHTCvYL77wmY17XXPzJfwD98f. Again those funds go through another round of laundering.

Above is activity inside 0x1623915E35Ed39Bfa381010Ce224f89734889aC9 - Inferno/Angel Customer Wallet. Much of the laundering is happening real-time and there will be much more to update in the future.

I'll continue to update as more information comes in.

Stay safe out there!

P.S. - I see you sent back the other victim back his $600.

submitted by /u/jbtravel84
[link] [comments]

Get BONUS $200 for FREE!

You can get bonuses upto $100 FREE BONUS when you:
πŸ’° Install these recommended apps:
πŸ’² SocialGood - 100% Crypto Back on Everyday Shopping
πŸ’² xPortal - The DeFi For The Next Billion
πŸ’² CryptoTab Browser - Lightweight, fast, and ready to mine!
πŸ’° Register on these recommended exchanges:
🟑 Binance🟑 Bitfinex🟑 Bitmart🟑 Bittrex🟑 Bitget
🟑 CoinEx🟑 Crypto.com🟑 Gate.io🟑 Huobi🟑 Kucoin.



Comments