鏈上研究人員 ZachXBT 注意到另一起錢包耗盡攻擊,涉及數十個地址。這些看似隨機的運輸都與 Last Pass 數據泄露有關,可能會暴露多個錢包。
ZachXBT 報告稱,從包含Bitcoin和Ethereum生態系統資產的個人錢包中總共被盜走536 萬美元。所有看似隨機的地址都有一個共同點——使用 Last Pass 作爲密碼存儲和保護。 2022 年數據泄露後,錢包列表被泄露。
ZachXBT 還將攻擊者dent爲一個有凝聚力的實體,即“最後通行證威脅行爲者”。攻擊者採用了類似的方法來耗盡錢包,然後立即通過Ethereum和Bitcoin進行即時兌換。這次攻擊影響了多個代幣,但黑客正試圖簡化他們的持有量。
顯然,一些錢包所有者還在該服務上存儲了私鑰,從而泄露了對錢包的直接訪問權限。實際的攻擊發生在數據泄漏很久之後,可能有更多的錢包可能被暴露,但尚未耗盡。
最近一批被耗盡的錢包包括具有 ENS 名稱的加密貨幣影響者,以及活躍的DEX和DeFi用戶。儘管經驗豐富,但暴露的地址導致了全部損失。自動從智能trac接收資金或獎勵的錢包可能尤其面臨風險。
在其中一個案例中, 收到的資金來自 OpenSea 用戶,可能來自 NFT 的銷售。在這種情況下,接收錢包可能是自動化的,並且已經鏈接到 NFT 市場。此後不久,錢包就被掏空,資金直接用於匿名交換。
迄今爲止,共有 40 多個地址被耗盡。在某些情況下,這些地址顯示出受到監視的證據,因爲資金耗盡是在最近存入資金後發生的。一些錢包從交易所接收資金用於存儲或作爲中間持有,並在傳入交易後的短時間內被耗盡。
ZachXBT 已trac到較早一批 22 個地址,即使在牛市早期階段,損失也超過 620 萬美元。其他鏈上研究人員也對可能暴露的錢包發出了警報。
Path敲響警鐘已經過去兩年了。
從那時起,我們已經調查了數千起此類盜竊案。
包括最近幾個小時內還有 2 個。
如果您使用過 LastPass,請將您的資金遷移至新錢包。
請告訴你的朋友。
請。求求你了。 🙏 https://t.co/5xd5oYxbwb
— 泰💖 (@tayvano_) 2024 年 12 月 16 日
The only solution for users is to abandon all potentially exposed wallets. The risk remains for anyone using Last Pass before the exploit in 2022. All funds must be moved to new addresses, as the old ones are already monitored for incoming transactions.
The latest wallet attack follows a previous batch of wallets linked to Last Pass data. In October 2023, a total of 25 wallets were drained of $4.4M worth of digital coins and tokens. As previously reported, some of the wallets had substantial funds and belonged to crypto insiders, even VCs and DeFi developers.
The previous hack did not alert all wallet owners exposed to Last Pass. ZachXBT has previously warned about potentially exposed wallets, though the hackers still managed to attack more accounts.
Unlike other hacking attempts, the wallets were drained directly onto exchange accounts. This suggests the hacker had full control and decided to trade the funds as a way of concealing them. In one case, a wallet was drained of 15 ETH, which were sent directly to a swapping address.
Another wallet lost 32 ETH, which was sent to the FixedFloat hot wallet. The exchange was used for other wallets as well. The exchange itself is not affected and is completely neutral to the hack. However, the DEX is a regular target for hackers, used to transform funds and cover their tracks. Previously, analysts have tracked funds from an attack against Rocket Pool to the same DEX.
FixedFloat offers a simplified swap service with relatively high fees, without requiring an account or KYC. The exchange itself has been a target of hackers, when it was exploited in March for $26M in ETH and BTC.
A Step-By-Step System To Launching Your Web3 Career and Landing High-Paying Crypto Jobs in 90 Days.