43-minute window period, the attacker has thoroughly studied the Safe interface, and now 2784 ETH is still lying in the cold wallet.

View Original
MarsBitNews
Superfortune: The attacker’s signature was compromised due to the signer’s private key being leaked, not due to address poisoning; it was not done by an insider.
Superfortune updated on X stating that the attack was carried out by non-internal personnel, with no involvement from the team, and that rumors about token sales are false.
Upon investigation: the attack was not due to address poisoning, but because the signer's private key was leaked, and the attacker held the private key alone, sending forged address transactions 43 minutes later.
The forged address shares the first and last four characters with the real address, used to disguise on the Safe interface.
Stolen funds are still traceable, currently held in three Ethereum cold wallets with approximately 2,784 ETH, and about 170k USDT cross-chain transferred out.
The attacker heavily mimicked addresses, using Unicode fake symbols to confuse tracking, indicating industrial-scale operations rather than opportunistic attacks.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned