News

How a Trader Lost $1,200 in 100 Seconds

A fool and his money are soon parted. When it comes to dealing with cryptocurrency, it’s important to know exactly what you’re doing. However, not only new crypto users fall victim to lurking predators, even a crypto OG will slip up once in awhile.

Here’s a story about a reddit user – tycooperaow – losing over $1,200 in a matter of seconds.

It all started with a mnemonic passphrase that was accidentally left on a github repository. The reddit user forgot to take out the secret passphrase out of his code, which effectively gives control to all the coins in the wallet it unlocks. Unfortunately for tycooperaow, the hackers were able to scan the mnemonic using their bot which searched every recent public github for a potential crypto mnemonic.

Once the bot confirms a match, it will automatically siphon off all funds to the hackers’ addresses.

Related Post

Looking at the compromised address‘s transaction history, we can see the rogue transaction sending out 0.038ETH. That is roughly $1,000 at the time of writing.

The caveat here, is that the bot only scans for ether, it doesn’t scan for all tokens attached to the address. The user in question still has roughly $600 in DeFi tokens locked up in the address. However, the user can’t create a transaction to send those tokens to an alternate address because any gas sent gets siphoned off by the bot.

If you have any idea how the reddit user can get those tokens out, please help him out by posting in his stackexchange question.

The best lesson we can learn from the this unfortunate event is to never leave your mnemonic in your code, especially one you might publicly submit to github. A better solution would have been to use environment variables and define them outside the code.

Source: Reddit

Mark Arguinbaev

I'm a 29 year old cryptocurrency entrepreneur. I was introduced to Bitcoin in 2013 and have been involved with it ever since. Fun Fact: I mined cryptocurrency using my college dorm room's free electricity.

Share
Published by
Mark Arguinbaev

Recent Posts

Solana Spot ETFs Extend Their Winning Streak as Bitcoin and Ethereum Face Heavy Outflows

Solana continues to heat up. The market is watching the ecosystem closely as institutional demand…

22 hours ago

Crypto Fear & Greed Index Crashes to a Two-Year Low as Market Volatility Deepens

The crypto market has entered one of its most fear (full) phases in years. After…

22 hours ago

Wolf Capital CEO Sentenced: Travis Ford Gets Five Years for $9.4M Crypto Ponzi Scheme

The crypto world sees another major collapse. This time, the man at the center is…

2 days ago

BlackRock’s BUIDL Fund Lands on BNB Chain, Bringing Tokenized U.S. Treasury Yields On-Chain

BNB Chain just added one of the biggest names in global finance to its streets,…

2 days ago

ADA Shoots for $2, Zero Knowledge Proof’s Whitelist Blows Up Overnight: Why Experts Are Calling ZKP the Next 1000x Crypto!

ADA Shoots for $2, Zero Knowledge Proof’s Whitelist Blows Up Overnight: Why Experts Are Calling…

2 days ago

Cypherpunk Technologies Bets Big on Privacy With $50M Zcash Investment

Cypherpunk Technologies ($LPTX) is making a bold move in the privacy sector. The company revealed…

3 days ago