Phishing Ring Takedown
- Entries
- 9
- Evidence
- 17
In Dec 2022, a victim had 14 X BAYC NFTs phished in a social engineering scheme where purchased X accounts were used to convince the victim they wanted to license the IP rights for a film. The scammer directed the victim to a phishing site where they had them sign a message draining their assets. Theft address 0x9335da37d37bc5d46850eaee48f8b9ccbe94d9a2



In Sep 2023, Sam Curry a well known whitehat and former Yuga Labs security engineer was detained at the airport by law enforcement for questioning and was served with a grand jury subpoena (later dropped). In reality as part of his security work at Yuga, he had been investigating the theft and used a private key put in the JavaScript of the website by the threat actor. LE then had mistakenly reviewed logs from OpenSea which included his home IP address and used this to incorrectly link him as the suspect.


It’s unfortunate to see how a security researcher was detained when stronger leads on a threat actor potentially responsible exists. They should request all data related to Fugazi Gambler’s social media accounts and dig into the P2P transaction history based on the forensic tracing above.











