8.43 million USDT, not stolen, he clicked 'Agree' himself
8.43 million USDT,
not stolen, it was gone after he clicked 'Agree' himself.
He just couldn't understand:
He was using a Ledger cold wallet,
The private key was never online, the mnemonic was written on paper, never took screenshots, never sent to anyone...
How could it be stolen?
After reviewing his on-chain operation records,
the answer is just two words: authorization.
It turns out that in order to conveniently view his assets,
he installed a browser extension wallet, connected it to the Ledger device,
the extension looked 'very legitimate':
✅ Supports cold wallet synchronization
✅ Simple interface, can view coin types + prices
✅ Plenty of community recommendations
He thought it was just 'viewing', with no risk.
But little did he know —
at the moment of connection, he clicked 'Authorize Signature' once,
and this contract gave away the transfer rights of all his assets.
—
⚠️ Truth revealed:
🔻 What he signed was a 'SetApprovalForAll' standard contract
🔻 The authorized entity was a hacker's deployed aggregation contract
🔻 Three days later, the cold wallet just received 8.43 million USDT
🔻 The hacker called the contract and withdrew all the balance at once
🔻 The user received no notifications on his phone, the wallet record only had one 'call event'
He didn't click 'Transfer',
but the authorization contract was like a 'pre-signed blank check'.
The other party could withdraw without needing his confirmation.
—
📌 After we took over, we did:
✅ Analyzed the contract call paths + authorization sources
✅ Labeled the victim's address + contract interaction objects
✅ Extracted the flow of funds, confirmed aggregation wallet + exchange paths
✅ Assisted in issuing judicial reports + cross-platform freezing communication
Currently, some assets have already been frozen at the exchange.
—
💥 He wasn't careless, he trusted too much that cold wallets are 'absolutely safe'.
The hacker didn't break in violently,
but used every step that seemed 'very safe' to slowly push you into a trap.
#白宫数字资产报告 #以太坊十周年 #BTC #ETH #USDT