Sophisticated Crypto Theft Targeting High-Net-Worth Individuals

Holland & Knight LLP
Contact

Holland & Knight LLP

Highlights

  • A recent court case has unveiled a new level of sophistication in attacks targeting high-net-worth cryptocurrency holders. In a meticulously orchestrated scheme, hackers managed to steal more than $40 million in bitcoin from an individual, despite the owner's use of hardware wallets, which are generally considered one of the most secure methods for cryptocurrency storage.
  • The attackers employed a multifaceted approach that included false "death" notifications, a hardware wallet security compromise, support ticket manipulation and multiplatform coordination.
  • This case demonstrates that even holders of hardware wallets may be vulnerable to sophisticated social engineering attacks. Cryptocurrency holders who receive unexpected communications about their holdings or unusual account notifications should not click links or provide information but instead should contact their digital asset security advisor directly through previously established channels.

Earlier this year, a complaint was filed in the U.S. District Court for the District of New Jersey alleging a cryptocurrency theft where an unknown hacker stole approximately $40 million in bitcoin from the victim's cryptocurrency wallets. The attack involved a series of sophisticated phishing emails designed to impersonate legitimate communications from Google and a hardware cryptocurrency wallet provider.

The scheme began with the victim receiving a phishing email from a fake Google Workspace Alerts account falsely claiming that he was deceased and mentioning that there was a legal matter involved with his Google account.

The victim later received another phishing email that appeared to come from the support account of the victim's hardware cryptocurrency wallet provider attempting to trick him into providing his extended public key by claiming that his private key recovery service had been initiated – a service to which he had never subscribed. The victim suspected the email was a phishing attempt and contacted the hardware cryptocurrency wallet provider via their legitimate support channel to inform them of the scam. In response, he received a series of misleading emails that attempted to further convince him to follow the fraudulent instructions. These included emails misrepresenting that the original phishing email was genuine and persuading the victim that he should provide his extended public key to protect his assets.

The victim also sought advice from a Reddit group dedicated to issues with the hardware cryptocurrency wallet provider, where he received conflicting advice from users, including one encouraging him to follow the fraudulent instructions. Approximately an hour after the victim communicated his situation on Reddit, the victim discovered that both the account of the user – who responded to his post – and the victim's own Reddit account had been deleted.

The incident prompted the victim to take immediate action to secure his assets. He moved his crypto assets from his hardware cryptocurrency wallet to a different wallet and began changing other passwords to prevent further unauthorized access. Despite his efforts, his cryptocurrency wallets were eventually compromised, and 521.99931468 bitcoin was transferred from his wallets to an address controlled by the hacker.

Key Security Lessons

This case demonstrates that even hardware wallets are vulnerable when combined with sophisticated social engineering attacks. Holland & Knight recommends the following precautions:

  • If you receive unexpected communications about your cryptocurrency holdings or unusual account notifications, do not click links or provide information.
  • Never share extended public keys or private keys with anyone, regardless of how legitimate the request appears.
  • Use multiple authentication factors for all cryptocurrency-related accounts.
  • Verify support communications through alternate channels before responding to emails about account security.
  • Establish emergency response procedures in advance to quickly freeze accounts if you suspect compromise.
  • Consider multi-signature arrangements requiring multiple parties to authorize high-value transactions.
  • Store cryptocurrency in hardware wallets (cold storage) and back up recovery phrases offline in physically secure, tamper-evident environments.
  • Consider using multiple types of hardware wallets to spread holdings across different platforms to prevent a single point of failure from being catastrophic.
  • Avoid publicly revealing your involvement in cryptocurrency on social media platforms, as attackers typically target individuals who advertise their involvement in cryptocurrency.

 

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Holland & Knight LLP

Written by:

Holland & Knight LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Holland & Knight LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide