$12M Wallet Hack, $7.5M Bridge Exploit, and Malware Targeting Crypto Users
Crypto exchanges and wallets continue to face security threats as hackers exploit vulnerabilities in their systems. This week's Cryptohack Roundup highlights three significant incidents, including a $12 million compromise of Triple-A wallet, an estimated $7.5 million exploit on the Verus-Ethereum Bridge, and the use of SparkKitty malware to steal seed phrases from cryptocurrency users.
The attack on Triple-A wallet, which affected multiple blockchain networks, resulted in losses of approximately $11.8 million. The incident was first reported by on-chain investigator Specter, who noted that fresh deposits continued flowing into the compromised wallets even after the attack began. The company has acknowledged the incident and assured customers that their funds are safe.
The Verus-Ethereum Bridge also suffered a security breach, with an attacker exploiting a vulnerability to steal about $7.5 million in crypto assets. This exploit targeted the same type of vulnerability as the May hack, which resulted in losses of approximately $11.6 million. However, this time, the stolen funds were deposited into Tornado Cash.
Meanwhile, cybersecurity firm Check Point discovered a malware strain called SparkKitty that targets cryptocurrency users by stealing wallet recovery phrases stored as images. The malware uses optical character recognition to scan photos and screenshots for sensitive information, which is then sent to attacker-controlled servers.