Data leak [loss] $3M+

Tweets by MyAlgo

2023-02-27 [vendor] Algorand wallet drains
Primary Source ↗
Financial Loss $3.3M (3,292,000 USD)
Affected 25 individuals/accounts

Incident Details

Over a period of several days, around 25 accounts on the Algorand blockchain have been drained of funds. The attack appears to be targeted at high-value accounts, and over 13 million ALGO (~$3.3 million) has been drained so far.John Woods, the CTO of the Algorand Foundation, acknowledged the spate of hacks, writing, “I agree that there’s too many of these hacks to be a coincidence”. However, he stated that he was confident it was not an issue with Algorand itself. The Algorand wallet provider MyAlgo subsequently urged users to withdraw funds from wallets that use mnemonic phrases for recovery, suggesting that there may have been an issue with their software.

Total loss estimated at $3,292,000.

Technical Details

Initial Attack Vector
Smart contract exploit / hack
Vendor / Product
Algorand wallet drains

Timeline

  1. 2023-02-27 Breach occurred
  2. 2023-02-27 Publicly disclosed