CASE FILE · CW-013

Phishing Ring Takedown

Entries
9
Evidence
17
01/Entry

In late 2023 a former Yuga Labs security researcher was stopped at the airport after law enforcement mistakenly linked them to a $1.1M phishing theft from a Bored Ape owner. Here’s an investigation into where the stolen funds went and who’s actually responsible.

Dossier evidenceDossier evidenceDossier evidence
02/Entry

In Dec 2022, a victim had 14 X BAYC NFTs phished in a social engineering scheme where purchased X accounts were used to convince the victim they wanted to license the IP rights for a film. The scammer directed the victim to a phishing site where they had them sign a message draining their assets. Theft address 0x9335da37d37bc5d46850eaee48f8b9ccbe94d9a2

Dossier evidenceDossier evidenceDossier evidence
03/Entry

In Sep 2023, Sam Curry a well known whitehat and former Yuga Labs security engineer was detained at the airport by law enforcement for questioning and was served with a grand jury subpoena (later dropped). In reality as part of his security work at Yuga, he had been investigating the theft and used a private key put in the JavaScript of the website by the threat actor. LE then had mistakenly reviewed logs from OpenSea which included his home IP address and used this to incorrectly link him as the suspect.

Dossier evidenceDossier evidence
04/Entry

Immediately after the theft the scammer sold the NFTs and deposited the stolen funds to Tornado (4 X 100 ETH, 5 X 100K DAI, 8 X 10 ETH, 2 X 1 ETH, 3 X 0.1 ETH). A high confidence 1:1 demix for Tornado can be found due to unique amounts + consolidation of funds post-mix.

Dossier evidenceDossier evidence
05/Entry

The stolen funds were then transferred to Secret Bridge (low volume privacy tool) and also two instant exchanges were used. After everything was immediately deposited to 20+ Gate deposit addresses and other services.

Dossier evidenceDossier evidence
06/Entry

A timing analysis was performed and matching Gate withdrawals were found shortly after the deposits. This can be verified as one of the addresses accidentally linked the deposits to the withdrawals. 0x5e72520038ec800986a9f1021fe2b8e3cd298c8d

Dossier evidence
07/Entry

All of the Gate withdrawals were consolidated to a single address and split two ways. 0x4f9051a58b416eaa0216081d7030679f17e9b069 A portion of the funds was cashed out via Remitano, a P2P platform.

Dossier evidence
08/Entry

One of the addresses who received a six figure split of stolen funds is directly connected to the ENS fugazigambler.eth, X Account @FugaziGambler & TG ID 5970895400 The TG was matched to the ENS by confirming bets placed onchain to messages in a TG group for a project.

Dossier evidenceDossier evidenceDossier evidence
09/Entry

It’s unfortunate to see how a security researcher was detained when stronger leads on a threat actor potentially responsible exists. They should request all data related to Fugazi Gambler’s social media accounts and dig into the P2P transaction history based on the forensic tracing above.