Cryptocurrency [loss] $15M+

Tweet thread by MistTrack

2023-05-15 [vendor] HitBTC phishing website [chain] ethereum, bitcoin
Primary Source ↗
Financial Loss $15.0M (15,000,000 USD)
Blockchain(s) Ethereum, Bitcoin

Incident Details

Blockchain security firm SlowMist has reported that a phishing website appearing to be the real cryptocurrency exchange HitBTC has stolen more than $15 million worth of Bitcoin, Tether, and Ether from users believing it to be the real thing. Users who didn’t notice they were accessing a site with the URL hitbt2c.lol instead of hitbtc.com approved transactions to swap their crypto assets, only to find the site drained their wallets.

Total loss estimated at $15,000,000.

Technical Details

Initial Attack Vector
Phishing attack
Vendor / Product
HitBTC phishing website

Timeline

  1. 2023-05-15 Breach occurred
  2. 2023-05-15 Publicly disclosed