The post Crypto investor hit by $50M USDT scam, attacker funnels funds through Tornado Cash appeared on BitcoinEthereumNews.com. A crypto investor became a victimThe post Crypto investor hit by $50M USDT scam, attacker funnels funds through Tornado Cash appeared on BitcoinEthereumNews.com. A crypto investor became a victim

Crypto investor hit by $50M USDT scam, attacker funnels funds through Tornado Cash

A crypto investor became a victim of a major $50 million USDT fraud after sending funds to a poisoned address by mistake. SlowMist, a blockchain security firm, revealed that, within 30 minutes of receiving the $50 million USDT, the attacker converted the whole sum into DAI via MetaMask Swap.

The blockchain security firm stated that the hacker converted the entire sum into 16,690 ETH and channeled 16,680 ETH through Tornado Cash to conceal the transaction trail. Etherscan on-chain data revealed that the transaction timestamps show that the attack happened within minutes. 

Web3 wallets targeted in high-value hacks

Initially, on-chain data revealed that the user submitted a small test transaction of 0.005 USDT to the correct address. A few minutes later, the victim transferred $50 million to a poisoned address, 0xBaFF2F13638C04B10F8119760B2D2aE86b08f8b5, which was copied from the transaction history. Etherscan revealed that the test transaction occurred at 06:20:35 and the massive transfer occurred at 06:32:59.

The wallet has been active for almost two years of on-chain activity. The victim mostly used the wallet for USDT transactions. Web3 Antivirus revealed that the $50 million was withdrawn from Binance just before the tainted transfer. For the time being, the stolen USDT remains at the target address.

The attack follows the recent attack on the 0G Foundation. The 0G Foundation reported on December 13 that the incentive contract was violated due to a targeted attack that occurred on December 11. The firm stated that the attacker stole 520,010 0G tokens, 9.93 ETH, and USDT worth approximately $4,200 by exploiting the emergency withdrawal provision of the 0G reward contract, which is used to distribute alliance benefits. 

Similar to the recent attack, the firm mentioned that the tokens were then bridged and distributed through Tornado Cash.

The 0G Foundation explained that the attacker moved laterally via internal IP addresses due to a serious Next.js vulnerability (CVE-2025-66478) that was exploited on December 5. The report stated that the breach affected services such as calibration, validator nodes, Gravity NFT services, node sales services, computing, Aiverse, Perpdex, Ascend, etc. 

However, according to the report, the attack did not affect the core chain infrastructure or user funds.

The report revealed that Foundation immediately took action by shutting down and rebuilding the impacted services, as well as revoking and rotating all compromised keys. Additionally, the company purchased and implemented an enhanced AliCloud Firewall + Security Suite and addressed critical dependencies, including Next.js.

On May 3, the Web3 anti-fraud platform Scam Sniffer announced that a whale had lost 1,155 WBTC, equivalent to approximately $70 million. According to Scam Sniffer, the $70 million loss happened as a result of a phishing attack using the same address with the same first and final digits.

On-chain data revealed that the funds were transferred from the victim’s address 0x1E227979f0b5BC691a70DEAed2e0F39a6F538FD5 to a phishing address 0xd9A1C3788D81257612E2581A6ea0aDa244853a91. Notably, the victim’s target transfer address was 0xd9A1b0B1e1aE382DbDc898Ea68012FfcB2853a91.

Analysis using the on-chain tracing tool MistTrack showed that the hacker swapped 1,155 WBTC for 22,955 ETH and moved them to ten different addresses.

Crypto thefts increase, most targeting personal wallets 

Blockchain analytics company Chainalysis said that cryptocurrency theft totaled more than $3.41 billion between January and early December 2025. According to the blockchain intelligence firm, the amount exceeds the $3.38 billion from the previous year.

Chainalysis claimed that $1.5 billion hack of the Bybit exchange accounted for approximately 44% of the annual total of crypto hacks. The blockchain intelligence firm argued that the top three attacks accounted for 69% of all service losses, demonstrating the growing seriousness of significant breaches.

According to Chainalysis, assaults against private keys on centralized cryptocurrency services and personal cryptocurrency wallets have significantly increased this year. The firm stated that personal wallet compromises have increased rapidly from just 7.3% of the total stolen value in 2022 to 44% in 2024.

The blockchain analytics firm claimed that at least 80,000 distinct victims were involved in 158,000 instances of personal wallet intrusions. The overall amount of money taken from people decreased to $713 million from $1.5 billion the year before.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It’s free.

Source: https://www.cryptopolitan.com/crypto-investor-hit-by-50m-usdt-scam/

Market Opportunity
Scamcoin Logo
Scamcoin Price(SCAM)
$0.000834
$0.000834$0.000834
-0.83%
USD
Scamcoin (SCAM) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

The post Polygon Tops RWA Rankings With $1.1B in Tokenized Assets appeared on BitcoinEthereumNews.com. Key Notes A new report from Dune and RWA.xyz highlights Polygon’s role in the growing RWA sector. Polygon PoS currently holds $1.13 billion in RWA Total Value Locked (TVL) across 269 assets. The network holds a 62% market share of tokenized global bonds, driven by European money market funds. The Polygon POL $0.25 24h volatility: 1.4% Market cap: $2.64 B Vol. 24h: $106.17 M network is securing a significant position in the rapidly growing tokenization space, now holding over $1.13 billion in total value locked (TVL) from Real World Assets (RWAs). This development comes as the network continues to evolve, recently deploying its major “Rio” upgrade on the Amoy testnet to enhance future scaling capabilities. This information comes from a new joint report on the state of the RWA market published on Sept. 17 by blockchain analytics firm Dune and data platform RWA.xyz. The focus on RWAs is intensifying across the industry, coinciding with events like the ongoing Real-World Asset Summit in New York. Sandeep Nailwal, CEO of the Polygon Foundation, highlighted the findings via a post on X, noting that the TVL is spread across 269 assets and 2,900 holders on the Polygon PoS chain. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 Key Trends From the 2025 RWA Report The joint publication, titled “RWA REPORT 2025,” offers a comprehensive look into the tokenized asset landscape, which it states has grown 224% since the start of 2024. The report identifies several key trends driving this expansion. According to…
Share
BitcoinEthereumNews2025/09/18 00:40
OpenVPP accused of falsely advertising cooperation with the US government; SEC commissioner clarifies no involvement

OpenVPP accused of falsely advertising cooperation with the US government; SEC commissioner clarifies no involvement

PANews reported on September 17th that on-chain sleuth ZachXBT tweeted that OpenVPP ( $OVPP ) announced this week that it was collaborating with the US government to advance energy tokenization. SEC Commissioner Hester Peirce subsequently responded, stating that the company does not collaborate with or endorse any private crypto projects. The OpenVPP team subsequently hid the response. Several crypto influencers have participated in promoting the project, and the accounts involved have been questioned as typical influencer accounts.
Share
PANews2025/09/17 23:58
Will XRP Price Increase In September 2025?

Will XRP Price Increase In September 2025?

Ripple XRP is a cryptocurrency that primarily focuses on building a decentralised payments network to facilitate low-cost and cross-border transactions. It’s a native digital currency of the Ripple network, which works as a blockchain called the XRP Ledger (XRPL). It utilised a shared, distributed ledger to track account balances and transactions. What Do XRP Charts Reveal? […]
Share
Tronweekly2025/09/18 00:00