Profanity May Be The Cause Of Crypto Trading Firm Wintermute’s $160 Million Hack

Wintermute, a London-based cryptocurrency firm that trades billions of dollars’ worth of digital assets daily, lost $160 million in a hack early on Tuesday. Founder and CEO Evgeny Gaevoy says he learned of the hack a few minutes after it took place, around 6:00 AM London time.

An hour later, he announced the theft on Twitter without saying how it happened. All told, the hacker stole about $120 million worth of Wintermute’s “stable coins” including USDC and USDT, $20 million worth of its bitcoin and ether and another $20 million worth of lesser-known cryptocurrencies.

Gaevoy explained to Forbes that, although the investigation is still ongoing, the hack likely originated with a service called Profanity, which generates “vanity addresses” for digital cryptocurrency accounts to make them easier to work with. Otherwise, crypto accounts are roughly 30-character strings of varied letters and numbers.

Last week, a blog post by another crypto firm revealed a security vulnerability with Profanity’s code. The gist of the problem: someone with enough computing power can generate all the possible keys or passwords created for a Profanity vanity address. Then they can scan the associated accounts to see how much money they hold and steal the funds.

Wintermute had been using Profanity not to create easy-to-remember names for digital accounts, but to lower its trading transaction costs, since that’s another feature of Profanity’s service, Gaevoy says. When Wintermute learned of the vulnerability last week, they took steps to technologically “blacklist” their Profanity accounts, shielding them from being liquidated.

However, due to their own “human error,” one of the 10 accounts didn’t get blacklisted, according to Gaevoy, which probably resulted in the $160 million heist. These trading accounts were part of Wintermute’s “decentralized finance” or DeFi business, where it makes rapid trades on decentralized exchanges like Uniswap and Sushi Swap that aren’t controlled by a single entity.

Since the DeFi ecosystem is young, highly experimental and designed to be more openly accessible than traditional finance, it doesn’t have the same safeguards that centralized exchanges like Coinbase has. “You don’t have any circuit breakers. You don’t have any two-factor authentication to help store your keys,” Gaevoy says.

In 2021, DeFi hacks totaled $1.3 billion, according to research by security firm Certik. Analytics firm Chainalysis estimates that North Korea-linked groups stole $1 billion from DeFi protocols in the first eight months of 2022. Some tried and true security practices in crypto, such as using external hardware wallets or “multi-sig” applications that need to be digitally signed by multiple parties before a transaction is approved, can’t be used for the type of automated trading Wintermute does.

“You need to sign transactions on the fly, within seconds,” says Gaevoy. So they had to invent their own tech tools and security protocols. “Ultimately, that’s the risk we took. It was calculated.” DeFi has been a flourishing part of Wintermute’s business in prior years. “It didn’t work out this year,” he admits.

The Wintermute CEO has some leads on who the hacker might be, and he’s investigating them “both internally and with the use of external partners.” He’s hoping that the hacker will become a “white hat” who returns most of the funds, and he’s now offering a 10% bounty, or $16 million, if the hacker gives back the remaining $144 million. He tweeted that Wintermute “would prefer to resolve this in a simple way, but the window of opportunity to do so is closing fast due to the high profile of this exploit.”

Despite the new $160 million hole in its balance sheet, Gaevoy says Wintermute is on sound financial footing, with more than $350 million in equity. “We are one of the very few crypto-native proprietary trading firms that can actually take this punch,” the CEO says. For a couple hours after the hack, the company paused its OTC trading desk, where it facilitates large trades between other parties. But that has resumed to its normal operation.

I lead our fintech coverage at Forbes and also cover crypto. I edit our annual Fintech 50 and 30 Under 30 for fintech, and I’ve written frequently about leadership and corporate

Source: Profanity May Be The Cause Of Crypto Trading Firm Wintermute’s $160 Million Hack

.

Critics by  

As per 1inch’s findings, the private keys linked to vanity addresses could be calculated with brute force attacks. A hacker managed to steal $3.3 million worth of cryptocurrencies from several Ethereum addresses generated with the “Profanity” tool. The funds were drained even after the decentralized exchange aggregator 1inch warned users about discovering a severe vulnerability putting millions of dollars at risk.

It had previously advised users owning wallet addresses generated with the Profanity tool to transfer their assets to a different wallet.

1inch Security Report

In early 2022, 1inch contributors observed that Profanity used a random 32-bit vector to seed 256-bit private keys and suspected it could be unsafe. Upon further investigation, more suspicious activity was noted, signaling that Profanity wallets were compromised.

“The 1inch contributors checked the richest vanity addresses on popular networks and came to the conclusion that most of them were not created by the Profanity tool. But Profanity is one of the most popular tools due to its high efficiency. Sadly, that could only mean that most of the Profanity wallets were secretly hacked.”

According to 1inch, Profanity happens to be a popular and “highly efficient” tool with which users are able to create millions of addresses per second. However, the procedure used by Profanity to generate the addresses was not flawless either and was susceptible to attacks.

The security disclosure report published by 1inch last week also noted that the vulnerability may have enabled hackers to “secretly” steal millions of dollars from Profanity users’ wallets for years. The contributors are currently trying to determine all the compromised vanity addresses.

Soon after the warning, blockchain investigator ZachXBT notified the attack draining over $3 million in funds. Fortunately, his tweet helped a user save $1.2 million in crypto and NFTs from the hacker who had access to their wallet.

Profanity Devs Abandon Project

According to Tal Be’ery, ZenGo’s security lead and chief technology officer, the malicious entities could have been “sitting” on the vulnerability in an attempt to get their hands on as many private keys as possible of bug-ridden Profanity-generated vanity addresses before the vulnerability was detected. However, they cashed out after it was publicly exposed by 1inch.

Meanwhile, one of the Profanity developers, who goes by the pseudonym ‘johguse’ on Github, said that they have already “abandoned” the project a few years ago. The comment regarding the same read

“This project was abandoned by me a couple of years ago. Fundamental security issues in the generation of private keys have been brought to my attention. I strongly advise against using this tool in its current state. This repository will soon be further updated with additional information regarding this critical issue.”

.

Related News:

Washington Monument Vandalized With Red Paint, ProfanityNBC Washington

20:38 Tue, 20 Sep
13:49 Mon, 19 Sep
05:10 Mon, 19 Sep
15:57 Sun, 18 Sep
00:45 Wed, 14 Sep
13:35 Thu, 01 Sep
00:08 Wed, 31 Aug
17:15 Fri, 26 Aug
10 Bold Actions In Positive Life & Work                https://jvz3.com/c/202927/383942/
360Apps                https://jvz2.com/c/202927/263380
3D Pal Toons                https://jvz6.com/c/202927/381689/
4brandcommercial        https://jvz1.com/c/202927/375487
7 Minutes Kit                    https://jvz8.com/c/202927/374505/
9 figure Success                        https://jvz8.com/c/202927/384653/
Ad Raven                       https://jvz4.com/c/202927/382796/
Ada leadz                           https://jvz8.com/c/202927/376381
ADA Web                        https://jvz3.com/c/202927/383751/
AdRaven                          https://jvz3.com/c/202927/382851/
Adsense Machine                  https://jvz2.com/c/202927/290487
Adtivate Agency                   https://jvz3.com/c/202927/383706/
AdzHero                      https://jvz2.com/c/202927/366972/
AffiliateMatic                 https://jvz3.com/c/202927/381148/
Agency Client Finder                        https://jvz3.com/c/202927/384619/
AgencyScale                          https://jvz4.com/c/202927/383111/
Agencyscale                      https://jvz1.com/c/202927/383113/
AIWA Commercial              https://jvz2.com/c/202927/365061
AIWA22                           https://jvz6.com/c/202927/377907/
ALL-in-One HD Stock                   https://jvz4.com/c/202927/381560
Animaxime                   https://jvz2.com/c/202927/383307/
Appimize                            https://jvz8.com/c/202927/370227
Appoint B Agency                     https://jvz1.com/c/202927/384630/
Appointomatic               https://jvz6.com/c/202927/374258
Appowls                     https://jvz4.com/c/202927/381231/
AppOwls                https://jvz4.com/c/202927/381976/ Bundle
Art Of Living                       https://jvz4.com/c/202927/382425/
Audiencetoolkit              https://jvz6.com/c/202927/302715
Aweber Crash Course                     https://jvz6.com/c/202927/383057/
Backlinkindexer           https://jvz6.com/c/202927/88118
BevTraders                               http://www.bevtraders.com/?ref=arminham
Big Audio Club                       https://jvz6.com/c/202927/380087/
BigAudio Club                   https://jvz2.com/c/202927/380877/
Boost Optimism                    https://jvz2.com/c/202927/380692/
BrandElevate                  https://jvzoo.com/c/202927/381812
BrandElevate                https://jvz4.com/c/202927/381807/
Bybit Crypto Trade                  https://www.bybit.com/en-US/invite?ref=ALEXP
CanvaKitz                     https://jvz4.com/c/202927/379051/
ChatterPal Commercial                 https://jvz8.com/c/202927/324615
Clientfinda                     https://jvz8.com/c/202927/370806
Clipsreel                             https://jvz3.com/c/202927/372682
Commission smasher          https://jvz3.com/c/202927/376879
Content Gorilla              https://jvz2.com/c/202927/330783
Content Tool Kit                     https://jvz3.com/c/202927/329145/
CourseAlly eLearning                      https://jvz4.com/c/202927/384759/
CourseReel                          https://jvz6.com/c/202927/355256/
CourseReel                        https://jvz2.com/c/202927/355249
Courserious                       https://jvz8.com/c/202927/360397/
Coursova                         https://jvz1.com/c/202927/376527
Creaitecontentcreator          https://jvz1.com/c/202927/376986
Credit Repair                        https://jvz8.com/c/202927/377815/
Crypto Kit                     https://jvz8.com/c/202927/383809/
Crypto Rocket                     https://jvz6.com/c/202927/378113/
Crypto Underworld                           https://jvz8.com/c/202927/374345/
Dealcheck                                  https://dealcheck.io?fp_ref=armin16
Design beast               https://jvz6.com/c/202927/371547
Designa Suite License                  https://jvz2.com/c/202927/297271
Develop Self Empowerment                 https://jvz6.com/c/202927/383094/
DFY Content Club                 https://jvz6.com/c/202927/381337/
DFY Suite                                    https://jvz2.com/c/202927/337292
DFY Suite                      https://jvz2.com/c/202927/381194/
DFY Suite                    https://jvz3.com/c/202927/381194/
Diabetes Guide                       https://jvz2.com/c/202927/358870/
Diddly Pay’s DLCM                  https://jvz2.com/c/202927/315596
Diet fitness diabetes              https://jvz1.com/c/202927/286851
Domainname                  https://jvz6.com/c/202927/377005
Dominate Email             https://jvz4.com/c/202927/386980/
Dropshiply                   https://jvz3.com/c/202927/383483/
DUX Forex Signals                        https://jvz3.com/c/202927/128215/
EBook Agency                        https://jvz2.com/c/202927/384573/
Ejaculation Total                     https://jvz2.com/c/202927/75989/
Email Monetizer                     https://jvz2.com/c/202927/386337/
EngagerMate                         https://jvz8.com/c/202927/328172
EngageYard                     https://jvz2.com/c/202927/383051/
Extreme Adz                 https://jvz8.com/c/202927/379244/
Extreme Coupon                  https://jvz1.com/c/202927/216101/
EZ Local Appointmen                            https://jvz2.com/c/202927/385180/   t
Ezy                https://jvz1.com/c/202927/381935/
Ezy MultiStores               https://jvzoo.com/c/202927/381935
Facebook Cash Machine                 https://jvz4.com/c/202927/382333/
Facedrip                          https://jvz1.com/c/202927/376325/
FaceSwap                 https://jvz4.com/c/202927/381768/
Fade To Black                   https://jvz2.com/c/202927/344541
Fanpage                          https://jvz4.com/c/202927/144349
Fitness Nutrition                    https://jvz4.com/c/202927/353334/
Followup Builder                         https://jvz3.com/c/202927/386313/
Forex Atlatian                        https://jvz8.com/c/202927/25069/
Forex Blizz                             https://jvz8.com/c/202927/144577/
Forex Blue Stark                      https://jvz3.com/c/202927/47481/
Forex expert                   https://jvz1.com/c/202927/376877
Forex Hybrid Scalper                        https://jvz6.com/c/202927/95037/
Forex Joustar                     https://jvz8.com/c/202927/381617/
Forex Joustar                  https://jvz6.com/c/202927/381617/
Forex Mastery                    https://jvz2.com/c/202927/144621/
Forex Scouts                         https://jvz6.com/c/202927/132677/
forrk                                              https://jvz1.com/c/202927/373449
FusionMT4                             https://jvz2.com/c/202927/372523/
FX Goldminer                      https://jvz1.com/c/202927/381439/
Galactic                         https://jvz1.com/c/202927/188236/
Gaming job                    https://jvz2.com/c/202927/184902  s
Genesis Mining                         https://www.genesis-mining.com/a/2535466
Givvy Mobile Lottery             https://givvy-numbers.app.link/qNDZMGGbhsb
Gluten free                              https://jvz4.com/c/202927/296191
GMB Magic                        https://jvz2.com/c/202927/377194
Graphic Alta           https://jvz2.com/c/202927/324492/
Heal Your Emptiness                         https://jvz6.com/c/202927/384848/
High Converting Emails                  https://jvz3.com/c/202927/386305/
HostLegends                       https://jvz4.com/c/202927/384755/
Hostley Domain Creator                        https://jvz1.com/c/202927/379223/
Human Synthesys Studio                      https://jvz8.com/c/202927/367353/
ImageX                      https://jvz6.com/c/202927/363237/
IMSyndicator                   https://jvz1.com/c/202927/370769
Inboxr                            https://jvz2.com/c/202927/312692
Insta Keyword                https://jvz6.com/c/202927/351606/
Instant Website                https://jvz2.com/c/202927/377557
InstantWebsiteBundle          https://jvz6.com/c/202927/377557
iTraffic X                          https://jvz2.com/c/202927/320466
keysearch                                    https://jvz3.com/c/202927/194909
Klippyo Kreators                         https://jvz8.com/c/202927/327447
KoinCart                            https://jvz2.com/c/202927/383555/
Leadvalet                         https://jvz3.com/c/202927/385580/
Levidio Royal Podcasting                        https://jvz6.com/c/202927/384025/
Linkable DFY                       https://jvz6.com/c/202927/385873/
Linkomatic                            https://jvz2.com/c/202927/380937/
LiteTrading                                 https://www.litefinance.com/?uid=929237543
Live Your Truth                       https://jvz6.com/c/202927/379020
Living An Intentional Life              https://jvzoo.com/c/202927/382455
Living an International Life                  https://jvz8.com/c/202927/382455/
Local Leader                   https://jvz4.com/c/202927/383751/
Local Sites                  https://jvz4.com/c/202927/380543/
LocalAgencyBox                 https://jvz2.com/c/202927/359468
LocalCentric                            https://jvz2.com/c/202927/379339/
Marketingblocks             https://jvz6.com/c/202927/374934
MarketPresso                  https://jvz2.com/c/202927/369837
Mat1 Simple Funnel                            https://jvz2.com/c/202927/380197/
Maxslides                         https://jvz8.com/c/202927/376842
Mech Forex Robot                           https://jvz6.com/c/202927/383447/
MediaCloudPro                 https://jvz2.com/c/202927/343635
Megasuite                         https://jvz3.com/c/202927/383953/
Mobi First                          https://jvz2.com/c/202927/353694/
Motion Kingdom Studio                    https://jvz4.com/c/202927/383177/
Movid Animation                     https://jvz6.com/c/202927/380385/
MT4Code System                  https://jvz2.com/c/202927/376925
My Passive Income                  https://jvz1.com/c/202927/384099/
MyMailIt                              https://jvz3.com/c/202927/292919
MyTrafficJacker               https://jvz2.com/c/202927/353558
Next Drive                      https://jvz4.com/c/202927/371095/
NichBox               https://jvz2.com/c/202927/370705/
Organic Life Guide                 https://jvz8.com/c/202927/366872/
Photokit                           https://jvz4.com/c/202927/373207/
PicsAds                         https://jvz2.com/c/202927/385468/
PigMoney Metho                     https://jvz4.com/c/202927/377665/   d
PigMoneyMethod                        https://jvz2.com/c/202927/377665/
Pitchdeck                      https://jvz3.com/c/202927/347847/
Pixal                     https://jvz2.com/c/202927/378775/
Pixivid                           https://jvz6.com/c/202927/385213/
PlanB Muscle Growth              https://jvz1.com/c/202927/36517/
PlayerNeos                 https://jvz2.com/c/202927/376962
Podcast Advantage                        https://jvz8.com/c/202927/379995/
Podcast Advantage              https://jvz1.com/c/202927/379995/
Podcast Masterclass               https://jvz3.com/c/202927/379998/
PodKastr                 https://jvz1.com/c/202927/369500/
Postradamus                              https://jvz6.com/c/202927/108695
Power Reviews                     https://jvz8.com/c/202927/384625/
Powrsuite                       https://jvz1.com/c/202927/376361
PR Rage                        https://jvz4.com/c/202927/343405
prime stocks                              https://jvz8.com/c/202927/369164  prime stocks
Profile mate                           https://jvz4.com/c/202927/358049
Promovidz                      https://jvz8.com/c/202927/375692/
Push Button Traffic         https://jvz2.com/c/202927/301402
QR Verse                      https://jvz3.com/c/202927/383865/
Quintex Capital                         https://quintexcapital.com/?ref=arminham
Quit Smoking                           https://jvz3.com/c/202927/359081/
Reputor                 https://jvz8.com/c/202927/380159/
ReVideo                     https://jvzoo.com/c/202927/381761
ReviewReel                        https://jvz6.com/c/202927/382663/
Rewriter                      https://jvz4.com/c/202927/353373/
RSI SEO                              https://jvz6.com/c/202927/384381/
Scriptdio                       https://jvz4.com/c/202927/385387/
Seniors Income                        https://jvz2.com/c/202927/383888/
Senuke                                  https://jvz6.com/c/202927/279944
ShopABot                           https://jvz2.com/c/202927/291955
ShopFunnels                        https://jvz3.com/c/202927/384069/
SocialAgency360                 https://jvz1.com/c/202927/385357/
SociCake                       https://jvz2.com/c/202927/321987
Socifeed                          https://jvz6.com/c/202927/375706
SociJam                    https://jvz2.com/c/202927/309649
Soronity                                 https://jvz6.com/c/202927/368736
SqribbleEbook                 https://jvz6.com/c/202927/283867
Stackable Picture                        https://jvz1.com/c/202927/385046/
Steven Alvey’s                      https://jvz2.com/c/202927/351754
Stoodaio                                    https://jvz1.com/c/202927/372094
Storymate                         https://jvz3.com/c/202927/320972
StreamPilot                        https://jvz2.com/c/202927/385431/
Studioninja                       https://jvz1.com/c/202927/374965
Sunday Freebie                             https://jvz1.com/c/202927/267113/
Super backdrop                https://jvz8.com/c/202927/376524
Superbackdrop                 https://jvz8.com/c/202927/376524
Survai                      https://jvz8.com/c/202927/380933/
Syndranker                          https://jvz3.com/c/202927/378143/
Talkingfaces                      https://jvz2.com/c/202927/375358
Talkingfaces                    https://jvz3.com/c/202927/375550
The Internet Marketing                https://jvz2.com/c/202927/289944
Tonai Voice Content           https://jvz8.com/c/202927/383119/
Toon Video Maker                   https://jvz2.com/c/202927/357201
TrafficFor                https://jvz8.com/c/202927/381950/
TrafficForU                   https://jvz3.com/c/202927/381950/
Trendio                       https://jvz3.com/c/202927/381003/
TubePal                        https://jvz6.com/c/202927/379863/
Tubeserp                        https://jvz3.com/c/202927/370472
TubeTargeter                   https://jvz6.com/c/202927/377211
TV Boss Fire                https://jvz6.com/c/202927/379480/
Ultrafunnels A.I                 https://jvz2.com/c/202927/381129/
VIADZ Ad Template                    https://jvz4.com/c/202927/379307/
Vidcentric                             https://jvz4.com/c/202927/376095
Viddeyo                                https://jvz6.com/c/202927/382326/
Videevolve                       https://jvz4.com/c/202927/381011/
Video Campaignor      https://jvz4.com/c/202927/387058/
Video Games                            https://jvz3.com/c/202927/184902/
VideoEnginePro                https://jvz2.com/c/202927/372916
VideoGameSuite                     https://jvz3.com/c/202927/366537/
VideoRobot Enterprise                https://jvz8.com/c/202927/291061
VidKreate                        https://jvz6.com/c/202927/386029/
VidMingo                           https://jvz6.com/c/202927/378359/
VidSnatcher                           https://jvz3.com/c/202927/342585
VidVoicer                      https://jvz1.com/c/202927/379983/
Vidzura                       https://jvz4.com/c/202927/385754/
Viral dash                            https://jvz6.com/c/202927/375959
Viral Quotes            https://jvz2.com/c/202927/386984/
VirtualReel                       https://jvz8.com/c/202927/376849
Vocalic                    https://jvz2.com/c/202927/383848/
VoiceBuddy                      https://jvz1.com/c/202927/342854
WebCop                         https://jvz4.com/c/202927/378683/
Webinarkit                       https://jvz3.com/c/202927/383937/
Webprimo                   https://jvz1.com/c/202927/379455/   Website Builder
WordPress Mastery                       https://jvz1.com/c/202927/386249/
WOW Backgrounds                      https://jvz3.com/c/202927/381615/
WowBackgraounds                       https://jvz2.com/c/202927/381556/
WP GDPR                                https://jvz8.com/c/202927/299907
WP Simulator                    https://jvz3.com/c/202927/46987/
Writer Arc           https://jvz1.com/c/202927/386602/
writing job                                  https://jvz8.com/c/202927/213027
XBrain Forex                           https://jvz3.com/c/202927/372305/
XFUNNELS                         https://jvz2.com/c/202927/310335
Xinemax                    https://jvz1.com/c/202927/381749/
YoDrive                    https://jvz2.com/c/202927/384700/
Your 3DPal                https://jvz2.com/c/202927/381685/
YTSuite                       https://jvzoo.com/c/202927/381179

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

%d bloggers like this: