CASE FILE · CW-016

Cross-Chain Money Flow

Entries
3
Evidence
9
01/Entry

3 A threat actor has stolen ~$500K over the past month by compromising 15+ X accounts (Kick, Cursor, Alex Blania, The Arena, Brett, etc) from sending targeted phishing emails which impersonated the X team to steal credentials and then launch meme coin scams.

Dossier evidenceDossier evidence
02/Entry

3 Each of the 15 ATOs were directly connected by mapping out the deployer address for each scam. The attacker bridged back and forth between Solana and Ethereum in an attempt to obfuscate the funding source.

Dossier evidence
03/Entry

3 An example of a phishing email received by X users can be seen below and the emails all follow the same script: >send fake copyright infringement email >create a sense of urgency >trick user into visiting phishing site and resetting 2FA/password Makes sure to limit email address reuse between services as well as using security keys for 2FA on important accounts whenever possible.

Dossier evidenceDossier evidence

Update: Yat Siu (co-founder of Animoca) likely fell for the same phishing email a few hours ago as the scam token was deployed by the same address as the Kick & Vanar CEO ATOs Deployer address BL1hs3jw58d1S9xw7cKRUx9wXY94se9Ydt7bCgN1W3pL

Dossier evidence

Update: Another two X accounts fell victim to the same phishing email by the same scammer as the address which deployed tokens was funded by the other ATOs Accounts: BasementRon (UFD) & Kyle Mann (Babylon Bee EIC) Deployer address bBDMV7zzwiW7uQU53FYBNjiK9bsK3McPzkwb6yJ57XE BL1hs3jw58d1S9xw7cKRUx9wXY94se9Ydt7bCgN1W3pL

Dossier evidenceDossier evidenceDossier evidence