{"id":34243,"date":"2025-06-29T10:31:37","date_gmt":"2025-06-29T10:31:37","guid":{"rendered":"https:\/\/dogewisperer.com\/?p=34243"},"modified":"2025-06-29T10:31:37","modified_gmt":"2025-06-29T10:31:37","slug":"nft-theft-fake-insiders-posing-as-it-experts-rack-up-1-million-zackxbt","status":"publish","type":"post","link":"https:\/\/dogewisperer.com\/?p=34243","title":{"rendered":"NFT Theft: Fake Insiders Posing As IT \u2018Experts\u2019 Rack Up $1 Million\u2013ZackXBT"},"content":{"rendered":"<div>\n<p>NFT projects lost roughly $1\u202fmillion in <a href=\"https:\/\/www.coingecko.com\/\" target=\"_blank\" rel=\"noopener nofollow\">crypto<\/a> over the past week when hackers posed as IT staff and struck at the heart of minting systems. The breach hit fan-token marketplace Favrr and Web3 initiatives Replicandy and ChainSaw, among others.<\/p>\n<p>According to onchain investigator and cybersecurity analyst ZackXBT, the attackers pushed out mass batches of NFTs, drove floor prices to zero, then cashed in their haul before teams could react.<\/p>\n<h2>NFT: Hackers Slip Into Web3 Teams<\/h2>\n<p>Based on reports, the group quietly joined development squads under false identities. They gained insider access to minting contracts. Then they minted thousands of tokens and NFTs in moments.<\/p>\n<p>The sudden flood crushed floor prices and let the thieves grab hot cash in minutes. It all unfolded in under a week, and about $1\u202fmillion vanished from these projects\u2019 treasuries.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">1\/ Multiple projects tied to Pepe creator Matt Furie &amp; ChainSaw as well as another project Favrr were exploited in the past week which resulted in ~$1M stolen<\/p>\n<p>My analysis links both attacks to the same cluster of DPRK IT workers who were likely accidentally hired as developers. <a href=\"https:\/\/t.co\/85JRm5kLQO\" rel=\"nofollow\" target=\"_blank\">pic.twitter.com\/85JRm5kLQO<\/a><\/p>\n<p>\u2014 ZachXBT (@zachxbt) <a href=\"https:\/\/twitter.com\/zachxbt\/status\/1938598925004607629?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">June 27, 2025<\/a><\/p>\n<\/blockquote>\n<h2>Mass Minting Drops Prices<\/h2>\n<p>Favrr suffered one of the biggest hits. The thieves dumped tokens so fast the market couldn\u2019t catch up. <a href=\"https:\/\/app.uniswap.org\/explore\/tokens\/ethereum\/0x2e32f96a4fbb9cd7cdc751971c015e282414b956\" target=\"_blank\" rel=\"noopener nofollow\">Replicandy<\/a> and ChainSaw saw similar moves. At Replicandy, floor values hit zero almost instantly.<\/p>\n<p>ChainSaw\u2019s stolen crypto still sits inactive in wallets, waiting for launderers to stir it back into exchanges. ZackXBT pointed out that nested services then further obscured the money trail.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">4\/ In total I estimate $310K+ from their projects was stolen and transferred primarily between the three address below.<\/p>\n<p>0xf6a9349c54d51f7f76bbd2afd755b5dd75e617ee<br \/>\n0x7e580f916a8e93871b72a694407fb7d790de96a6<br \/>\n0x58f4299465b261e79713e5c78a7629cd656aed36 <a href=\"https:\/\/t.co\/8noeV48MUY\" rel=\"nofollow\" target=\"_blank\">pic.twitter.com\/8noeV48MUY<\/a><\/p>\n<p>\u2014 ZachXBT (@zachxbt) <a href=\"https:\/\/twitter.com\/zachxbt\/status\/1938598958449983956?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">June 27, 2025<\/a><\/p>\n<\/blockquote>\n<p>Funds Trace And Freeze Challenges<\/p>\n<p>Onchain transfers moved funds through multiple exchanges and wallets. Analysts say tracing mixed outputs can take weeks. Exchanges must review huge logs.<\/p>\n<p>That slows or even blocks law enforcement from locking down accounts. In the Coinbase data leak back in May 2025, about 69,461 customers had personal info exposed.<\/p>\n<p>Contractors were bribed to hand over user data, leading to an extortion bid against the exchange.<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"size-full\" src=\"https:\/\/www.tradingview.com\/x\/HoL18kOo\/\" width=\"1835\" height=\"884\"><br \/>\nLessons From Broader Cyber Attacks<\/p>\n<p>The NFT\/<a href=\"https:\/\/hbr.org\/2022\/05\/what-is-web3\" target=\"_blank\" rel=\"noopener nofollow\">Web3<\/a> insider episode echoes Ruby Sleet\u2019s tactics. In November 2024, that group targeted aerospace and defense firms, then shifted to IT companies via fake hiring drives.<\/p>\n<p>They used <a href=\"https:\/\/www.kaspersky.com\/resource-center\/definitions\/what-is-social-engineering\" target=\"_blank\" rel=\"noopener nofollow\">social engineering<\/a> to plant malware and harvest credentials. Today\u2019s blockchain and NFT hacks show that open and irreversible ledgers magnify mistakes. When insiders gain privileges, there\u2019s often no undo button.<\/p>\n<p>Security experts warn teams to rethink trust models. Zero\u2011trust approaches limit each engineer\u2019s reach. Multi\u2011party approval gates could block sudden minting spikes.<\/p>\n<p>Real\u2011time activity monitors can flag odd behavior right away. And code reviews paired with identity checks for every new hire help close gaps before they\u2019re abused.<\/p>\n<p><em>Featured image from Vecteezy, chart from TradingView<\/em><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>NFT projects lost roughly $1\u202fmillion in crypto over the past week when hackers posed as IT staff and struck at the heart of minting systems. The breach hit fan-token marketplace Favrr and Web3 initiatives Replicandy and ChainSaw, among others. According to onchain investigator and cybersecurity analyst ZackXBT, the attackers pushed out mass batches of NFTs, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":0,"footnotes":""},"categories":[2],"tags":[3,4,5],"class_list":["post-34243","post","type-post","status-publish","format-standard","hentry","category-news","tag-crypto","tag-doge","tag-news"],"_links":{"self":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/34243","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=34243"}],"version-history":[{"count":0,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/34243\/revisions"}],"wp:attachment":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=34243"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=34243"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=34243"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}