Crypto Whale Multisig Wallet Drained in a Sophisticated Attack An attacker has successfully compromised a whale’s multisig wallet just minutes after its creationCrypto Whale Multisig Wallet Drained in a Sophisticated Attack An attacker has successfully compromised a whale’s multisig wallet just minutes after its creation

Whale Multisig Hacked in Minutes: Attack Drains $40M in Stages

Whale Multisig Hacked In Minutes: Attack Drains $40m In Stages

Crypto Whale Multisig Wallet Drained in a Sophisticated Attack

An attacker has successfully compromised a whale’s multisig wallet just minutes after its creation, draining approximately $27.3 million and executing staged laundering activities over the past 44 days. The incident raises concerns over security practices in the crypto ecosystem and highlights evolving threats targeting high-value wallets.

Blockchain security firm PeckShield reported that the attacker has laundered around $12.6 million, or roughly 4,100 ETH, primarily through Tornado Cash. The attacker also retains about $2 million in liquid assets and has engaged in leveraged trading on Aave. New forensic analyses suggest the total loss could surpass $40 million, with initial signs of theft traced back to early November.

Yehor Rudytsia, head of forensic investigations at Hacken Extractor, explained that the wallet labeled as “compromised” might not have been under the victim’s control from the outset. On-chain data shows that the multisig wallet was created on November 4 at 7:46 am UTC, but ownership was transferred to the attacker just six minutes later. Rudytsia explained, “Very likely, the attacker created the multisig wallet, transferred funds to it, and then took control of it almost immediately.”

Attacker laundering funds in batches. Source: PeckShield

Following control of the wallet, the attacker exhibited patience, making Tornado Cash deposits over several weeks, beginning with 1,000 ETH on November 4 and continuing through early December in smaller, staggered transactions. Persistent funds remain on the compromised wallet, now under the attacker’s control. Rudytsia also raised concerns about the wallet’s configuration. The multisig was set as a “1-of-1,” requiring only a single signature for transaction approval—a design that doesn’t technically qualify as multisig and significantly lowers security.

Security experts at Hacken warn that various attack vectors are still viable, including malware infections, phishing, and operational errors such as storing private keys insecurely or using the same device for multiple signers. Abdelfattah Ibrahim, a DApp auditor, emphasized that locking devices in cold storage and verifying transactions outside a user interface are critical mitigation strategies.

Emerging Risks from AI-Generated Exploits

Recent research by Anthropic and the Machine Learning Alignment & Theory Scholars (MATS) demonstrates that advanced AI models can autonomously develop and execute profitable smart contract exploits. In controlled tests, models such as Anthropic’s Claude Opus 4.5, Claude Sonnet 4.5, and OpenAI’s GPT-5 collectively generated exploits valued at $4.6 million, illustrating the potential for autonomous hacking.

In further assessments, these AI models identified previously unknown zero-day vulnerabilities when tested against nearly 2,850 new smart contracts, producing exploits valued at just under $4,000, with costs lower than the expense of generating these exploits. This emerging threat underscores the need for enhanced security measures as AI capabilities rapidly advance within the blockchain space.

This article was originally published as Whale Multisig Hacked in Minutes: Attack Drains $40M in Stages on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.

Market Opportunity
Ambire Wallet Logo
Ambire Wallet Price(WALLET)
$0.00857
$0.00857$0.00857
+1.42%
USD
Ambire Wallet (WALLET) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Shocking OpenVPP Partnership Claim Draws Urgent Scrutiny

Shocking OpenVPP Partnership Claim Draws Urgent Scrutiny

The post Shocking OpenVPP Partnership Claim Draws Urgent Scrutiny appeared on BitcoinEthereumNews.com. The cryptocurrency world is buzzing with a recent controversy surrounding a bold OpenVPP partnership claim. This week, OpenVPP (OVPP) announced what it presented as a significant collaboration with the U.S. government in the innovative field of energy tokenization. However, this claim quickly drew the sharp eye of on-chain analyst ZachXBT, who highlighted a swift and official rebuttal that has sent ripples through the digital asset community. What Sparked the OpenVPP Partnership Claim Controversy? The core of the issue revolves around OpenVPP’s assertion of a U.S. government partnership. This kind of collaboration would typically be a monumental endorsement for any private cryptocurrency project, especially given the current regulatory climate. Such a partnership could signify a new era of mainstream adoption and legitimacy for energy tokenization initiatives. OpenVPP initially claimed cooperation with the U.S. government. This alleged partnership was said to be in the domain of energy tokenization. The announcement generated considerable interest and discussion online. ZachXBT, known for his diligent on-chain investigations, was quick to flag the development. He brought attention to the fact that U.S. Securities and Exchange Commission (SEC) Commissioner Hester Peirce had directly addressed the OpenVPP partnership claim. Her response, delivered within hours, was unequivocal and starkly contradicted OpenVPP’s narrative. How Did Regulatory Authorities Respond to the OpenVPP Partnership Claim? Commissioner Hester Peirce’s statement was a crucial turning point in this unfolding story. She clearly stated that the SEC, as an agency, does not engage in partnerships with private cryptocurrency projects. This response effectively dismantled the credibility of OpenVPP’s initial announcement regarding their supposed government collaboration. Peirce’s swift clarification underscores a fundamental principle of regulatory bodies: maintaining impartiality and avoiding endorsements of private entities. Her statement serves as a vital reminder to the crypto community about the official stance of government agencies concerning private ventures. Moreover, ZachXBT’s analysis…
Share
BitcoinEthereumNews2025/09/18 02:13
SEI Technical Analysis Feb 6

SEI Technical Analysis Feb 6

The post SEI Technical Analysis Feb 6 appeared on BitcoinEthereumNews.com. SEI is consolidating at the $0.08 level under general downtrend pressure; although RSI
Share
BitcoinEthereumNews2026/02/07 02:43
South Korean Crypto Exchange Accidentally Gave Away $95 Billion in Bitcoin

South Korean Crypto Exchange Accidentally Gave Away $95 Billion in Bitcoin

The post South Korean Crypto Exchange Accidentally Gave Away $95 Billion in Bitcoin appeared on BitcoinEthereumNews.com. In brief South Korean exchange Bithumb
Share
BitcoinEthereumNews2026/02/07 02:16