Superfortune: The leakage of the attacker's private key rather than address poisoning is not the work of an insider

By: rootdata|2026/05/30 04:45:01
0
Share
copy

Superfortune, incubated by Manta, recently released an update on the X platform regarding a security incident, stating that the attack was not carried out by internal personnel and that no team members were involved. The claim about the team secretly selling tokens is incorrect. The team has also not had any contact with Web3Port.

The investigation confirmed that the attack was not due to address poisoning, but rather a leak of the signer's private key. The attacker independently held the private key and submitted a transaction with a forged address 43 minutes after the correct transaction. The forged address shares the first and last four characters with the correct address (starting with 0x70AE and ending with 5C15) to disguise itself in the Safe interface preview. The stolen funds are fully traceable and are currently stored in three cold wallets on Ethereum, containing approximately 2784 ETH, along with about 170,000 USDT that were cross-chain transferred out.

The attacker also created a large number of counterfeit addresses and sent false transfer events to these addresses using Unicode-forged token symbols in an attempt to confuse tracking. This counterfeit address construction technique is the same as the method used when attacking this project. The attacker had pre-built a large-scale infrastructure, indicating that this was an industrialized operation rather than an opportunistic attack.

-- Price

--

You may also like

A Perspective on the Indian Cryptocurrency Market: Descending into Silence or Moving Towards Maturity?

The Indian cryptocurrency industry has not gone silent; it is steadily maturing towards diversification.

It took me a year to see the painful truth about Agent payments

Among the four major tracks of Agent purchasing, Agent API, Agent inter-payment, and Agent finance, currently only Agent finance has real users and willingness to pay. But worse than having no demand is that the real competition point has never been payment...

Morning News | Bitmine issues preferred shares to raise $300 million; Polymarket accuses Kalshi of industrial espionage

Overview of Important Market Events on June 4th

Privacy coin trust crisis! ZEC plummets over 56% in a single day

The recent increase in ZEC is nearly 3 times, and the vulnerability news may have just provided an opportunity to exit.

Who is leading the price discovery in the cryptocurrency market? Measured delays on platforms like Binance and Hyperliquid

There is a saying circulating on crypto Twitter: Hyperliquid has replaced Binance and become the center of crypto price discovery. Arrakis conducted a cross-platform test using the tick-by-tick transaction data from 29 perpetual markets, and the truth lies within milliseconds.

Anthropic launches IPO: Business miracle or valuation bubble?

Human economy is transitioning from a carbon-based drive to a dual-engine drive of carbon-based and silicon-based, which is what is truly happening behind Anthropic's IPO.

Contents

Popular coins

Latest Crypto News

Read more
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com