ChainBleedv0.1 · open intel
← back to feed·PRIVATE-KEY2023-03-01 · 3y ago
Incident · SLOWMIST

iToken

Insider Manipulation
Estimated loss
VERDICT —OUT OF SCOPE
Root cause is private-key / signer compromise — the on-chain contract behaved exactly as written. No pre-deployment source audit or bytecode review reaches the key-custody perimeter; this is operational-security territory (HSM/MPC hygiene, key rotation, hot-wallet isolation). Bytecode would show nothing wrong.
▰ METHOD
PRIVATE KEY
PRIVATE-KEY
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

Forensic narrative

According to the official WeChat account of Ping An Xuhui, employees Zhang, Dong, and Liu from Company A decided in early March 2023 to insert a backdoor program into a certain cryptocurrency wallet software to obtain users' private keys. The three individuals illegally obtained over 27,000 mnemonic phrases and more than 10,000 private keys, successfully converting over 19,000 digital wallet addresses. In April 2024, the Xuhui District People's Court sentenced Liu, Zhang, and Dong to three years in prison for the crime of illegally obtaining data from a computer information system and fined each of them 30,000 RMB. It is worth noting that Company A is suspected to be the former Huobi company. In an exclusive report by WuShuo in 2023, it was revealed that due to the installation of trojans by former employees, some users' mnemonic phrases or private keys of iToken (formerly Huobi Wallet) were leaked. HTX responded that the trojan installation was the personal act of former Huobi employees before the acquisition, leading to the theft of others' mnemonic phrases and private keys. Attack method (per SlowMist): Insider Manipulation. Reported loss: -.

Primary source
https://www.wublock123.com/index.php?m=content&c=index&a=show&catid=10&id=29686
Sourced from
slowmist
Technical record
chain
protocol
iToken
bug_class
private-key
date_occurred
2023-03-01
loss_usd
source_id
sm:itoken::2023-03-01
Related — same bug class· private-key
2026-04-30
1mo ago
MULTI
Wasabi Perps
Admin Key Compromised
private-key
$5.50M
OUT OF SCOPE
2026-04-30
1mo ago
ETH
Wasabi Protocol
Private Key Leakage
private-key
$5.70M
OUT OF SCOPE
2026-04-29
1mo ago
Syndicate Labs
Private Key Leakage
private-key
$380.0K
OUT OF SCOPE
2026-04-21
1mo ago
SUI
Volo Vault
Admin Key Compromised
private-key
$3.50M
OUT OF SCOPE
2026-04-21
1mo ago
SUI
Volo Vaults
Private Key Leakage
private-key
$3.50M
OUT OF SCOPE
2026-04-16
1mo ago
MULTI
Grinex
Hot wallet hack
private-key
$15.00M
OUT OF SCOPE
ChainBleed — live web3 threat intelligence