According to Superfortune's statement on May 29, the security attack was caused by a signer's private key leakage rather than address poisoning. The attacker independently held the private key and submitted a fraudulent transaction 43 minutes after the correct one, using a spoofed address with matching first and last four characters to deceive the Safe interface preview.
Stolen funds totaling approximately 2784 ETH are currently held in three cold wallets on Ethereum, with roughly 170,000 USDT transferred across chains. The attacker created numerous counterfeit addresses and sent fake transfer events using Unicode-forged token symbols to confuse tracking, indicating a sophisticated, pre-built infrastructure operation rather than an opportunistic attack.