Bitcoinist
2025-09-13 06:00:50

THORChain Founder Loses $1.35M After Deepfake Zoom And Telegram Scam

A co-founder of THORChain had roughly $1.35 million taken from a forgotten MetaMask wallet after attackers used a hacked Telegram account and a fake Zoom meeting to gain access to his stored keys, according to reports. The theft was first flagged on-chain and later confirmed by multiple news outlets and investigators. THORChain: Multi-Stage Scam Based on reports, the scheme began when an associate’s Telegram was compromised and a malicious meeting link was circulated. The target joined what appeared to be a legitimate video call, but the feed was fake. Attackers then exploited access to the victim’s iCloud Keychain and browser profile to extract private keys tied to an old wallet, which was drained of about $1.35 million in crypto. $1.35M was stolen from a Thorchain cofounder. Yet another reminder: if your keys are stored in a software wallet, you’re only one malicious code execution away from losing everything. In this case, the victim didn’t even sign a malicious transaction, the malware simply stole the… pic.twitter.com/nLS4nWNFyt — Charles Guillemet (@P3b7_) September 12, 2025 Investigators And On-Chain Sleuths Chime In Blockchain investigators quickly traced movements and posted findings on social platforms, with some early on-chain sleuths estimating the visible value at roughly $1.2 million before later reports put the total near $1.35 million. Analysts flagged links to North Korea–connected actors based on patterns and prior behavior, though attribution in such cases can be complex and takes time to confirm. #PeckShieldAlert A @thorchain user’s personal wallet was exploited, resulting in a loss of ~$1.2M pic.twitter.com/R385BRHoHu — PeckShieldAlert (@PeckShieldAlert) September 12, 2025 Security Community Issues Warning Leaders in the crypto security scene warned the industry to treat remote meeting links and sudden file requests with deep caution. A senior wallet developer highlighted that storing private keys in software that syncs to cloud services makes a user vulnerable if those cloud accounts are accessed by malware or other exploits. That warning was echoed across developer and security feeds after the theft was disclosed. THORSwap Offers Bounty To Recover Funds Reports have disclosed that a related project put up a reward to help recover the stolen funds, and community members began tracking transactions to identify where the assets moved. Public appeals and bounties have become a common community response when large sums are siphoned off and on-chain tracing points to identifiable wallets. Wider Pattern Of Deepfake And Zoom Scams This incident is part of a growing string of attacks that use fake video calls and impersonation to trick targets into running malicious code or revealing credentials. Major cases elsewhere have cost victims millions, including an earlier story in which deepfakes and fake calls led to a multi-million loss at a corporate level. Security researchers say criminals are now combining social engineering with AI tools to make scams more convincing. Featured image from IT Security Guru , chart from TradingView

Crypto 뉴스 레터 받기
면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.