{"id":46997,"date":"2025-09-13T07:05:28","date_gmt":"2025-09-13T07:05:28","guid":{"rendered":"https:\/\/www.bitrabo.com\/discover\/?p=46997"},"modified":"2025-09-13T07:05:28","modified_gmt":"2025-09-13T07:05:28","slug":"thorchain-founder-duped-out-of-1-35m-in-deepfake-scam","status":"publish","type":"post","link":"https:\/\/www.bitrabo.com\/discover\/thorchain-founder-duped-out-of-1-35m-in-deepfake-scam\/","title":{"rendered":"THORChain Founder Duped Out of $1.35M in Deepfake Scam"},"content":{"rendered":"\n<p>In a shocking incident, a <strong>crypto industry veteran<\/strong> lost approximately $1.35 million from a previously overlooked MetaMask wallet. This breach was orchestrated through a compromised Telegram account and a deceptive Zoom meeting that allowed attackers to gain access to sensitive data.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Understanding_the_THORChain_Incident\"><\/span>Understanding the THORChain Incident<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Initial reports indicate that the scam kicked off when an associate&#8217;s Telegram account was hacked. The attackers sent out a malicious link disguised as a genuine video call invitation. The victim, believing it to be authentic, joined the meeting, unknowingly exposing himself to a fraudulent interface.<\/p>\n<p>Once inside, the perpetrators leveraged access to private keys stored in the victim\u2019s iCloud Keychain, eventually draining the wallet of its entire balance, which amounted to a staggering $1.35 million in various cryptocurrencies.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">This incident totaling $1.35M serves as a crucial reminder: relying on software wallets leaves you just one malicious execution away from losing it all. <strong>Exercise caution!<\/strong><\/p>\n<p>Even without approving a malicious transaction, the malware simply lifted the&#8230;<\/p>\n<p>\u2014 CyberSecurity Expert (@InfoSecGuru) <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/twitter.com\/InfoSecGuru\/status\/1966426113967583603?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">September 12, 2025<\/a><\/p>\n<\/blockquote>\n<h2><span class=\"ez-toc-section\" id=\"Insights_from_Investigators\"><\/span>Insights from Investigators<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Blockchain forensic teams quickly mobilized, analyzing the on-chain movement of the stolen assets. Early estimates placed the stolen value at around $1.2 million; however, subsequent analyses updated the figure to nearly $1.35 million.<\/p>\n<p>Experts made connections to potential <strong>North Korean<\/strong> groups based on system patterns, highlighting the complexity of attributing such actions in the crypto world.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/twitter.com\/hashtag\/CyberAlert?src=hash&amp;ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">#CyberAlert<\/a> A THORChain user&#8217;s wallet was breached, leading to losses exceeding $1.2M <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/t.co\/R385BRHoHu\" rel=\"nofollow\">pic.twitter.com\/R385BRHoHu<\/a><\/p>\n<p>\u2014 CryptoWatch (@CryptoWatch) <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/twitter.com\/CryptoWatch\/status\/1966412029985747260?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">September 12, 2025<\/a><\/p>\n<\/blockquote>\n<h2><span class=\"ez-toc-section\" id=\"A_Cautionary_Tale_for_the_Community\"><\/span>A Cautionary Tale for the Community<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Leaders within the <strong>crypto security community<\/strong> issued warnings about the dangers associated with remote meeting links and sudden data requests. A veteran wallet developer stressed that keeping private keys in software that syncs to cloud services exposes users to significant risks, particularly when those services are compromised.<\/p>\n<p>This caution resonated within developer forums, emphasizing the need for heightened vigilance after such significant losses.<\/p>\n<p><\/p>\n<h2><span class=\"ez-toc-section\" id=\"Community_Initiatives_for_Recovery\"><\/span>Community Initiatives for Recovery<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>In response to the theft, a related project announced a bounty aiming to facilitate the recovery of the stolen funds. Meanwhile, community members actively tracked the flow of stolen assets, a common strategy employed during high-profile breaches.<strong> On-chain tracing<\/strong> often helps pinpoint the locations where funds have moved.<\/p>\n<p>Encounters like these have led to widespread appeals and rewards being offered as communities mobilize to combat crypto theft.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Emerging_Trends_in_Scamming_Techniques\"><\/span>Emerging Trends in Scamming Techniques<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>This incident highlights an alarming trend involving <strong>deepfakes<\/strong> and fake video calls. Cybercriminals are becoming increasingly sophisticated, combining social engineering with artificial intelligence to enhance their scams\u2019 credibility.<\/p>\n<p>Notable cases have previously resulted in losses of millions, illustrating the severe implications such scams can have on both individuals and organizations.<\/p>\n<p>As the landscape of cyber threats continues to evolve, staying informed and adopting heightened security protocols has never been more crucial.<\/p>\n<p><em>Image source: Cybersecurity News<\/em>, <em>data from TradingView<\/em><\/p>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In a shocking incident, a crypto industry veteran lost approximately $1.35 million from a previously overlooked MetaMask wallet. This breach was orchestrated through a compromised Telegram account and a deceptive Zoom meeting that allowed attackers to gain access to sensitive data. Understanding the THORChain Incident Initial reports indicate that the scam kicked off when an [&hellip;]<\/p>\n","protected":false},"author":14,"featured_media":46998,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"slim_seo":{"title":"THORChain Founder Duped Out of $1.35M in Deepfake Scam - Bitrabo","description":"In a shocking incident, a crypto industry veteran lost approximately $1.35 million from a previously overlooked MetaMask wallet. This breach was orchestrated th"},"footnotes":""},"categories":[316],"tags":[16872,6061,1387,2055,637,2954,16871,10363],"class_list":["post-46997","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto-news","tag-1-35m","tag-deepfake","tag-founder","tag-loses","tag-scam","tag-telegram","tag-thorchain","tag-zoom"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/posts\/46997","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/comments?post=46997"}],"version-history":[{"count":0,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/posts\/46997\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/media\/46998"}],"wp:attachment":[{"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/media?parent=46997"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/categories?post=46997"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/tags?post=46997"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}