If Crypto OGs Are Being Hacked, Where Does That Leave the Rest of Us?
There’s reportedly been a nasty bug going around OG crypto holders, affecting arguably the most critical part of Web3 infrastructure: the MetaMask wallet. Over 5,000 ETH (worth approximately $10.5 million) have been stolen from crypto veterans since December, crypto-skeptical newsite Protos reported, citing an informal investigation done by MyCrypto founder Taylor Monahan.
It appears that developers at ConsenSys, the private blockchain software technology that’s built much of Ethereum’s open-source tooling, including the MetaMask wallet and Infura application toolkit, are investigating the exploit, which appears to be “deliberately” targeting people who should know the ins-and-outs of crypto self-custody and security.
This article is excerpted from The Node, CoinDesk’s daily roundup of the most pivotal stories in blockchain and crypto news. You can subscribe to get the full newsletter here.
“This is NOT a low-brow phishing site or a random scammer. It has NOT rekt a single noob. It ONLY rekts OGs,” Monahan, who goes by “Tay” on Twitter, wrote. The attack is widespread, affecting keys created between 2014 and 2022 and affecting 11 blockchains, according to Tay’s preliminary investigation.
I mention this exploit not to spread fear, uncertainty and doubt. Right now it appears average or occasional users of MetaMask are not being targeted. But it is a moment to remember a few wallet best practices and to take stock of your holdings. Because of the sophisticated nature of the attack and the pedigree of the victims, the fallout could be severe.
The most important thing right now is not only making everyday crypto users feel safe and secure, but ensuring they actually are. I’ve reached out to several ConsenSys developers for ideas about asset security, and will update the piece on CoinDesk.com if/when they get back.
As mentioned, much about the attack and attacker(s) are still unknown, and it’s not clear whether this is a coordinated effort by several skilled hackers or perpetrated by someone with inside knowledge of the MetaMask operation. Monahan suggests the perpetrator may have received a cache of data that is helping them access users’ private keys or wallet recovery phrases. She added emphatically that the issue is not related to MetaMask’s underlying cryptography or a social engineering scam, as with phishing.
However, there are a few commonalities among the victims: Most of the attacks have occurred on the weekend, and has the exploiter swapping assets within a victim’s wallet for ETH (often bypassing staked positions, non-fungible tokens and lesser-known coins), consolidating that ETH and then transferring it out. Often the attacker has gone back hours, days or weeks after an initial attack to sweep remaining funds, Monahan said.
The “theft and post-theft on-chain movement is VERY distinct,” Monahan said, hoping to open the doors to identifying the attacker and recovering assets. She added that several “recovery” attempts have been very successful so far.
ConsenSys has not yet confirmed the attack, but Monahan could be said to be speaking for the organization in some capacity. ConsenSys acquired Monahan’s startup MyCrypto in February 2022, having implemented MyCrypto’s “scam blocklist” (aka CryptoScamDB), which is used to protect MetaMask users from visiting known scam URLs in 2017, according to an announcement at the time. So she knows what she’s talking about.
As for best practices, Monahan wrote in all caps: “PLEASE DON’T KEEP ALL YOUR ASSETS IN A SINGLE KEY OR SECRET PHRASE FOR YEARS.” If that is mostly useful only in retrospect, she also cautions users to split up their assets, use a hardware wallet and migrate their funds off accounts connected to the internet.
As the nature of the exploit is revealed, it’s likely this story will only get bigger. Apparently many long-time crypto users have been affected over a period of months without much word filtering out into the wider world. As long as crypto continues to have value, wallet users will continue to face such threats. A record $3.8 billion in crypto was stolen last year through scams, hacks and theft, according to Chainalysis’ latest accounting.
CoinDesk recently published a list of “Projects to Watch,” meaning protocols and companies we feel relatively good about recommending to users. I wrote about the increasingly popular Rainbow wallet, which is spreading mostly by word-of-mouth, in part due to its easy interface and built-in security features.
Rainbow, like many crypto wallets, has rolled out a series of security features to help protect wallets including pop-up messages that warn users about suspicious addresses they may be interacting with, as well as ID tools to prevent people from sending assets to incorrect or dead addresses. Basic security features like this should be the norm across crypto (to be clear, MetaMask is among the wallets with similar protections).
But it also seems like crypto users and malicious actors will constantly be playing a game of cat and mouse. With every technological solution used to protect the uninformed, there is likely a workaround. And if Monahan is correct, even years of hands-on experience is no guarantee you will be safe. There are best practices to follow and pitfalls to avoid – but at this point, scamming is clearly endemic to crypto.
Where does that leave Web3? It’s not like banks or fintech apps are immune to hacks or scammers – but users should be able to trust even “trustless” technologies.
Learn more about Consensus 2023, CoinDesk’s longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.
DISCLOSURE
Please note that our
privacy policy,
terms of use,
cookies,
and
do not sell my personal information
has been updated
.
The leader in news and information on cryptocurrency, digital assets and the future of money, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a
strict set of editorial policies.
CoinDesk is an independent operating subsidiary of
Digital Currency Group,
which invests in
cryptocurrencies
and blockchain
startups.
As part of their compensation, certain CoinDesk employees, including editorial employees, may receive exposure to DCG equity in the form of
stock appreciation rights,
which vest over a multi-year period. CoinDesk journalists are not allowed to purchase stock outright in DCG
.
Daniel Kuhn is a features reporter and assistant opinion editor for CoinDesk’s Layer 2.
He owns BTC and ETH.