Superfortune Confirms Attack Caused by Private Key Leakage, Not Address Poisoning; 2784 ETH Missing

GUA11.72%
ETH1.85%
SAFE2.24%

According to Superfortune's statement on May 29, the security attack was caused by a signer's private key leakage rather than address poisoning. The attacker independently held the private key and submitted a fraudulent transaction 43 minutes after the correct one, using a spoofed address with matching first and last four characters to deceive the Safe interface preview.

Stolen funds totaling approximately 2784 ETH are currently held in three cold wallets on Ethereum, with roughly 170,000 USDT transferred across chains. The attacker created numerous counterfeit addresses and sent fake transfer events using Unicode-forged token symbols to confuse tracking, indicating a sophisticated, pre-built infrastructure operation rather than an opportunistic attack.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments