bitcoin
Bitcoin (BITCOIN)
$108,494 3.66%
ethereum
Ethereum (ETHEREUM)
$2,649 5.52%
binancecoin
BNB (BINANCECOIN)
$657.41 2.11%
solana
Solana (SOLANA)
$156.66 4.69%
ripple
XRP (RIPPLE)
$2.30 6.99%
shiba-inu
Shiba Inu (SHIBA-INU)
$0.000012 3.25%
pepe
Pepe (PEPE)
$0.000011 3.01%
bonk
Bonk (BONK)
$0.000016 6.79%
bitcoin
Bitcoin (BITCOIN)
$108,494 3.66%
ethereum
Ethereum (ETHEREUM)
$2,649 5.52%
binancecoin
BNB (BINANCECOIN)
$657.41 2.11%
solana
Solana (SOLANA)
$156.66 4.69%
ripple
XRP (RIPPLE)
$2.30 6.99%
shiba-inu
Shiba Inu (SHIBA-INU)
$0.000012 3.25%
pepe
Pepe (PEPE)
$0.000011 3.01%
bonk
Bonk (BONK)
$0.000016 6.79%
bitcoin
Bitcoin (BITCOIN)
$108,494 3.66%
ethereum
Ethereum (ETHEREUM)
$2,649 5.52%
binancecoin
BNB (BINANCECOIN)
$657.41 2.11%
solana
Solana (SOLANA)
$156.66 4.69%
ripple
XRP (RIPPLE)
$2.30 6.99%
shiba-inu
Shiba Inu (SHIBA-INU)
$0.000012 3.25%
pepe
Pepe (PEPE)
$0.000011 3.01%
bonk
Bonk (BONK)
$0.000016 6.79%
Disclosure
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.
Crypto Investor Loses $6.5 Million After Falling for a Cold Wallet Scam

Highlights:

  • A user has lost funds after buying a tampered cold wallet through Douyin.
  • Investigators linked the stolen crypto to Huiwang, a dark web network that remains active under new domain names.
  • SlowMist warned that discounted cold wallets often contain malware and advised users to buy only from trusted sources.

Blockchain security firm SlowMist has confirmed that a crypto user has been defrauded of $6.5 million after buying a cold wallet on Douyin. The wallet appeared to be new and factory sealed. However, attackers had already compromised its private key. Hours after the user transferred funds into the wallet, attackers stole the entire amount.

Advertisement

Banner

The case mirrors a 2023 incident involving a Trezor Model T wallet. Attackers flawlessly sealed that wallet and loaded it with modified firmware and predetermined recovery phrases. After weeks went by, the victim lost his money without suspecting the tampering.

One of the X users, a good friend of the victim, gave details regarding the incident. In his account, the victim had bought the wallet using the e-commerce functionality of Douyin, the Chinese version of TikTok. The seller included a price cut and advertised the device as factory sealed. Assuming that it was authentic, the user sent cryptocurrencies to the wallet. Shortly afterward, the victim lost the crypto.

Hella described the device as a “carefully designed hot trap.” The attackers had access to the private key from the beginning. Once the user activated the wallet, they moved the funds quickly. The listing that offered the wallet had no clear signs of fraud, making it difficult to detect.

Investigators Trace Laundering Path to Huiwang’s Dark Web Network

SlowMist, a blockchain security firm that offers cybersecurity audits, worked to trace the stolen funds after the theft. The attackers laundered the money using an existing network controlled by Huiwang, or the Huione Group. Authorities have also linked the group with Haowang Guarantee, a darknet marketplace. The network still operates under new names despite reports that authorities had shut it down. Chainalysis data indicate that its volumes have increased even though Huiwang was flagged over money laundering concerns.

The laundering route allowed the attackers to hide the stolen funds quickly. With multiple layers in place, tracing each transaction became harder over time. The group behind the network uses Telegram to manage operations. This platform helps them remain hidden while conducting illegal transactions.

SlowMist Urges Caution as Cold Wallet Scams Multiply

SlowMist’s chief information security officer, known as 23pds on X, warned users to avoid cheap cold wallets from unofficial sellers. He stated that choosing a low-cost option may result in huge losses. Scammers often load these wallets with built-in malware or saved recovery phrases. Attackers often employ this tactic to drain funds once the user activates the tampered device.

He added that such cold wallet scams are hard to prevent. Many devices are shipped by third-party sellers who may not know they are part of a larger scheme. He reminded users to buy wallets from verified sources. He emphasized that many online sellers offer unsafe wallets despite making them look genuine.

eToro Platform

Best Crypto Exchange

  • Over 90 top cryptos to trade
  • Regulated by top-tier entities
  • User-friendly trading app
  • 30+ million users
9.9

5 Stars

eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.

Advertisement

Banner

Advertisement

Banner

Advertisement

Banner