Hacker Steals $1.7 Million Worth of NFTs From DeFi Veteran Arthur Cheong

  |  
Last updated: Mar 30, 2023
  |  
3 Min Read

A hacker managed to swipe over $1,700,000 worth of non-fungible tokens (NFTs) from Defiance Capital founder Arthur Cheong.

Early Tuesday morning, someone was able to access an Ethereum wallet belonging to Cheong and seize his NFTs. The NFTs were then dumped on opensea.io and other marketplaces for well below market price. Profits were then converted into Wrapped Ethereum (WETH), Lido DAO token, LooksRare (LOOKS) and DYDX.

Blockchain security firm Peckshield identified Cheong's wallet as compromised, showing a list of the shady transactions.

According to Cheong and others helping him with the investigation, the hack was executed via spear phishing. While regular phishing scams are sent en masse with no specific victim in mind, spear phishing focuses on one target and uses social engineering tactics tailored to the person. They often appear as emails from seemingly legitimate origins and can use emotional manipulation to sway the victim into opening them, such as emails about missing person reports or fake “urgent” tax notices.

As the head of a large investment firm, Cheong and others in the industry often receive sales pitches via email in the form of PDFs, Docx, or links to websites that ultimately contain malware. He believes his PC was compromised by opening an attachment from one of these emails, which allowed the hackers to then access hot wallets on his computer.

"Found out the likely root cause for the exploit, it's a targeted social engineering attack,” Cheong said.

"Received a spear-phishing email that really seems to be sent by one of our portco with content that seems like general industry-relevant content.

They are likely targeting all crypto [people]."

Image@Arthur_0x/Twitter 

Unfortunately, Cheong says none of his anti-virus software pegged the email or the document as malicious.

While so far it appears to be mere speculation, Cheong says that he has a feeling that the hack stems from Lazarus, a North Korean-based hacking group infamous for pulling off many exploits dating all the way back to 2009. The group has been traced to a collection of various cryptocurrency scams, mostly targeted at South Korean exchanges and platforms.

As one commenter on Twitter said, "Not gonna lie, a bit shook by this. If someone as smart as Arthur is getting compromised, what hope do the plebs have?"

 Newsletter Inline

Coin bureau logo circle.jpg

The Coin Bureau news team comprises a group of talented writers and analysts committed to delivering timely and accurate information about the world of cryptocurrency. Led by a seasoned editor-in-chief with extensive experience in financial journalism, the team boasts diverse backgrounds and skills, from technical analysis to industry insights.

Disclaimer: These are the writer’s opinions and should not be considered investment advice. Readers should do their own research.

Previous article
SEC Proposes Sweeping Greenhouse Gas Reporting Rules Which Would Affect Crypto Mining
next article
Grayscale Launches New Smart Contract Fund With Cardano, Solana, Avalanche and More