A hacker group from China posing as a cybersecurity firm has allegedly stolen 7 million dollars via wallet supply‑chain attacks, targeting Trust Wallet and otherA hacker group from China posing as a cybersecurity firm has allegedly stolen 7 million dollars via wallet supply‑chain attacks, targeting Trust Wallet and other

China hacker group leaks $7M crypto theft operation targeting wallet supply chains​

2026/03/18 05:00
Okuma süresi: 3 dk
Bu içerikle ilgili geri bildirim veya endişeleriniz için lütfen [email protected] üzerinden bizimle iletişime geçin.

A hacker group from China posing as a cybersecurity firm has allegedly stolen 7 million dollars via wallet supply‑chain attacks, targeting Trust Wallet and other clients before an internal dispute triggered a whistleblower leak.

Summary
  • Operating under Wuhan Anshun Technology, the group presented itself as a security outfit while allegedly using Electron apps, browser plugins, and remote‑control tools to exfiltrate mnemonics and drain wallets across Ethereum, BNB Chain, Arbitrum and more.​
  • A disgruntled member claims the crew stole about 7 million dollars across 37 token types, then leaked internal details after a fight over profit splits and unpaid “severance,” saying they now plan to turn themselves in.​
  • Even as authorities stay quiet, the episode echoes recent supply‑chain and extension incidents involving Trust Wallet and others, underscoring that every update, plugin, and wrapper around self‑custody wallets is part of the real attack surface.

A Chinese hacker group posing as a cybersecurity firm has been exposed after an internal dispute led members to leak details of a multimillion‑dollar crypto theft operation. According to market reports, the group claims to have stolen around 7 million dollars in digital assets through supply chain attacks, with targets including popular wallet provider Trust Wallet.​

Operating under the corporate front Wuhan Anshun Technology, the group presented itself publicly as a security company focused on vulnerability research, network offense-and-defense exercises, and security services. Internally, however, members were allegedly conducting “gray market” activity, systematically stealing mnemonic phrases and raiding user wallets across multiple chains. The whistleblower says the team built automated tooling to bulk-scan mnemonic phrase assets and to identify high‑value portfolios across Ethereum, BNB Chain, Arbitrum and other networks.​

China fake cybersecurity firm accused of weaponizing wallet plugins and Electron supply chains

Per the leaked account, the group exploited supply chain vulnerabilities in Electron-based clients and browser plugins, combined with reverse engineering and remote-control programs, to exfiltrate wallet data and drain funds. The operation allegedly touched 37 different token types across several blockchains, with funds laundered via splitting and transfers to obscure the trail. The immediate trigger for the exposure was an internal fight over profit distribution and unpaid “severance” to one of the operators.

The whistleblower claims they clashed with the team leader over what they saw as unfair profit splits, then decided to publicly dump evidence after promised compensation was not delivered, stating they intend to turn themselves in to law enforcement. So far, the allegations have not been officially confirmed, and authorities have not publicly detailed any investigation progress. Industry commentators note that, confirmed or not, the episode again underscores the structural attack surface in wallet supply chains, plugin ecosystems, and desktop clients—especially for high‑value users who treat self‑custody software as “set and forget.”​

For retail and institutional users, the lesson is blunt: security risk is not just in private key handling, but in every update, extension, and client wrapper sitting between you and your keys. In a market where attackers are willing to build fake “security companies” as covers, rigorous supply‑chain auditing, minimal plugin use, and strict device‑level hygiene are no longer best practices—they are baseline survival requirements.

Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

The post IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge! appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 18:00 Discover why BlockDAG’s upcoming Awakening Testnet launch makes it the best crypto to buy today as Story (IP) price jumps to $11.75 and Hyperliquid hits new highs. Recent crypto market numbers show strength but also some limits. The Story (IP) price jump has been sharp, fueled by big buybacks and speculation, yet critics point out that revenue still lags far behind its valuation. The Hyperliquid (HYPE) price looks solid around the mid-$50s after a new all-time high, but questions remain about sustainability once the hype around USDH proposals cools down. So the obvious question is: why chase coins that are either stretched thin or at risk of retracing when you could back a network that’s already proving itself on the ground? That’s where BlockDAG comes in. While other chains are stuck dealing with validator congestion or outages, BlockDAG’s upcoming Awakening Testnet will be stress-testing its EVM-compatible smart chain with real miners before listing. For anyone looking for the best crypto coin to buy, the choice between waiting on fixes or joining live progress feels like an easy one. BlockDAG: Smart Chain Running Before Launch Ethereum continues to wrestle with gas congestion, and Solana is still known for network freezes, yet BlockDAG is already showing a different picture. Its upcoming Awakening Testnet, set to launch on September 25, isn’t just a demo; it’s a live rollout where the chain’s base protocols are being stress-tested with miners connected globally. EVM compatibility is active, account abstraction is built in, and tools like updated vesting contracts and Stratum integration are already functional. Instead of waiting for fixes like other networks, BlockDAG is proving its infrastructure in real time. What makes this even more important is that the technology is operational before the coin even hits exchanges. That…
Paylaş
BitcoinEthereumNews2025/09/18 00:32
What To Expect From The Fed Rate Decision Tomorrow

What To Expect From The Fed Rate Decision Tomorrow

The post What To Expect From The Fed Rate Decision Tomorrow appeared on BitcoinEthereumNews.com. The Fed is likely to hold interest rates steady for a second consecutive
Paylaş
BitcoinEthereumNews2026/03/18 06:22
Young pastor says entrenched conservatism 'made me question the whole system'

Young pastor says entrenched conservatism 'made me question the whole system'

Rural Alabama pastor Daniel Rogers refused to give up the church after being ousted by his home denomination, but it wasn’t an easy journey.Rogers is a member of
Paylaş
Alternet2026/03/18 06:41