On-Chain Detective ZachXBT: A certain wallet was stolen through "social engineering attack" involving $282 million worth of BTC and LTC

動區BlockTempo
BTC6,73%
LTC3,35%
TRU1,91%

Blockchain detective ZachXBT reveals that a coin holder experienced a suspected hardware wallet social engineering attack in mid-January, losing over $282 million worth of Litecoin and Bitcoin in one go.
(Background: TrueBit protocol suspected hacking! 8,535 ETH transferred abnormally, $TRU instantly cut in half)
(Additional context: North Korean hackers set a record in 2025 by stealing $2.02 billion in cryptocurrency, with a money laundering cycle of about 45 days)

Independent on-chain investigator ZachXBT pointed out that around 11:00 PM UTC on January 10, a large-scale crypto asset theft occurred. A victim was suspected of falling for a social engineering scam related to hardware wallets, losing over $282 million worth of Litecoin (LTC) and Bitcoin (BTC).

Based on on-chain information compiled by this investigator, after the assets were stolen, the attacker began converting large amounts of LTC and BTC into Monero (XMR) through multiple “instant exchange” services, causing XMR prices to spike significantly in a short period.

Meanwhile, some Bitcoin was transferred across chains via Thorchain to networks like Ethereum, Ripple, and Litecoin, increasing the difficulty of tracking.

The stolen addresses exposed in this incident include approximately 2.05 million LTC and 1,459 BTC, marked as:

BTC: bc1qluxw46r55wf3dnk9c652vrt4duadm3hpuktf86

BTC: bc1qpsmh26ja0fzzf286zulmt9eywujc2pggj40wzm

LTC: ltc1qly43c2prj4c2e85dcspzpjd36jnapnenldnr70

This event demonstrates that even using hardware wallets, which are considered relatively secure self-custody tools, large assets can still be transferred and laundered quickly if targeted by sophisticated social engineering attacks during authentication, private key management, or customer support processes. Privacy coins and cross-chain mechanisms further enhance anonymity.

For professional and institutional investors, relying solely on “cold wallets” is no longer sufficient. Designing stricter manual procedures and permission controls will be a key focus in subsequent discussions of such incidents.

(##

View Original
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

a16z Crypto is raising $2 billion for its fifth fund

a16z Crypto, the blockchain investment arm of Andreessen Horowitz, is raising its fifth fund, targeting approximately $2 billion, with plans to close in the first half of 2026. Although the size is smaller than the previous $4.5 billion mega fund, the fundraising cycle will be shortened to adapt to the rapid changes in the crypto industry.

GateNews42m ago

Data: 930 BTC transferred from an anonymous address, then routed through a relay and sent to another anonymous address

ChainCatcher reports that, according to Arkham data, at 07:21, 930 BTC (worth approximately $67.59 million) was transferred from an anonymous address (starting with 3GTQBv5B4...) to two anonymous addresses (starting with bc1q908dtg... and bc1q2catyz...).

GateNews57m ago
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)