On-Chain Detective ZachXBT: A certain wallet was stolen through "social engineering attack" involving $282 million worth of BTC and LTC

動區BlockTempo
BTC-1,26%
LTC-1,42%
TRU-29,74%

Blockchain detective ZachXBT reveals that a coin holder experienced a suspected hardware wallet social engineering attack in mid-January, losing over $282 million worth of Litecoin and Bitcoin in one go.
(Background: TrueBit protocol suspected hacking! 8,535 ETH transferred abnormally, $TRU instantly cut in half)
(Additional context: North Korean hackers set a record in 2025 by stealing $2.02 billion in cryptocurrency, with a money laundering cycle of about 45 days)

Independent on-chain investigator ZachXBT pointed out that around 11:00 PM UTC on January 10, a large-scale crypto asset theft occurred. A victim was suspected of falling for a social engineering scam related to hardware wallets, losing over $282 million worth of Litecoin (LTC) and Bitcoin (BTC).

Based on on-chain information compiled by this investigator, after the assets were stolen, the attacker began converting large amounts of LTC and BTC into Monero (XMR) through multiple “instant exchange” services, causing XMR prices to spike significantly in a short period.

Meanwhile, some Bitcoin was transferred across chains via Thorchain to networks like Ethereum, Ripple, and Litecoin, increasing the difficulty of tracking.

The stolen addresses exposed in this incident include approximately 2.05 million LTC and 1,459 BTC, marked as:

BTC: bc1qluxw46r55wf3dnk9c652vrt4duadm3hpuktf86

BTC: bc1qpsmh26ja0fzzf286zulmt9eywujc2pggj40wzm

LTC: ltc1qly43c2prj4c2e85dcspzpjd36jnapnenldnr70

This event demonstrates that even using hardware wallets, which are considered relatively secure self-custody tools, large assets can still be transferred and laundered quickly if targeted by sophisticated social engineering attacks during authentication, private key management, or customer support processes. Privacy coins and cross-chain mechanisms further enhance anonymity.

For professional and institutional investors, relying solely on “cold wallets” is no longer sufficient. Designing stricter manual procedures and permission controls will be a key focus in subsequent discussions of such incidents.

(##

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Data: In the past 7 days, a certain CEX’s net outflow of reserve assets exceeded $228 million, and the Gate BTC wallet balance fell by 3.88%

Based on the data, over the past 7 days, Gate exchange’s BTC wallet balance fell by 3.88%, becoming the exchange with the largest decline. At the same time, only 3 exchanges recorded net inflows; among them, one CEX saw inflows of up to $346 million, while Gate recorded net outflows of $154 million.

GateNews9m ago

BIT posts an analysis of Bitcoin ETF fund flows, with net inflows resuming in March

Gate News update, on April 13, BIT posted on X, saying that Bitcoin ETF fund flows have just turned positive again, and that it may achieve a continuous second month of net inflows. BIT noted that the current trend is highly similar to the same period in 2025, when early-year fund inflows were lackluster but were later followed by a concentrated surge of nearly $30 billion, driving a rebound after the tariff policy was implemented in April, and continuing through October. BIT said that net inflows resumed in March, which was the first time it turned positive since the pullback that began last October.

GateNews58m ago
Comment
0/400
No comments