Mkt Cap$2.36T+3.56%
24h Vol$80.62B
BTC Dom56.5%
ETH Dom9.1%
F&G20Extreme Fear
BTC$66,532.00+3.48% ETH$1,774.85+6.52% USDT$0.99940.00% BNB$623.74+2.09% XRP$1.24+8.80% USDC$0.99980.00% SOL$72.76+7.40% TRX$0.3208+0.91% FIGR_HELOC$1.01+0.00% HYPE$68.14+12.19% DOGE$0.09+4.00% USDS$0.9998+0.01% LEO$9.79+0.38% ZEC$532.26+26.95% RAIN$0.0136+3.85% ADA$0.1876+11.47% BTC$66,532.00+3.48% ETH$1,774.85+6.52% USDT$0.99940.00% BNB$623.74+2.09% XRP$1.24+8.80% USDC$0.99980.00% SOL$72.76+7.40% TRX$0.3208+0.91% FIGR_HELOC$1.01+0.00% HYPE$68.14+12.19% DOGE$0.09+4.00% USDS$0.9998+0.01% LEO$9.79+0.38% ZEC$532.26+26.95% RAIN$0.0136+3.85% ADA$0.1876+11.47%
ETH+6.52% DeFi

Vanity Addresses in the Spotlight Again as Hacker Gets Away With $950,000

$950,000 worth of Ether was stolen from a crypto wallet after a hacker exploited a bug in Profanity-generated vanity addresses.

Ethereum with downtown los angeles at night
Image courtesy of 123rf.
Editorial disclosureRead more

All reviews, research, news and assessments of any kind on The Tokenist are compiled using a strict editorial review process by our editorial team. Neither our writers nor our editors receive direct compensation of any kind to publish information on tokenist.com. Our company, Tokenist Media LLC, is community supported and may receive a small commission when you purchase products or services through links on our website. Click here for a full list of our partners and an in-depth explanation on how we get paid.

Neither the author, Tim Fries, nor this website, The Tokenist, provide financial advice. Please consult our website policy prior to making financial decisions.

Just a week after the Wintermute hit, $950,000 worth of Ether was stolen from a crypto wallet using the vanity address exploit again. On-chain data shows that the hacker then transferred the funds to the Tornado Cash service, where it was mixed with other crypto funds and sent to the hacker’s wallet.

Hackers Continue Exploiting Bugs in Profanity-generated Vanity Addresses

Blockchain security company PeckShield reported that a hacker has stolen $950,000 worth of Ether (ETH) from a crypto wallet. The funds were looted using the same vanity address exploit that was used in the $160 million hack on Wintermute last week.

According to PeckShield, the hacker stole 732 ETH on Sunday from a crypto wallet and used the sanctioned Tornado Cash to mix it with other funds. The funds were then withdrawn to the hacker’s own crypto wallet.

It appears that the hacker has exploited the vanity address generated with a tool known as Profanity. A vanity address refers to a crypto address that contains certain patterns or words, making them more personal and identifiable.

“Seems like $950k worth of crypto has been stolen by 0x9731F from Ethereum “vanity address” generated with a tool called Profanity. The exploiter already transferred ~732 $ETH into Mixer”

– @PeckShieldAlert said in a tweet

A large number of vanity addresses were generated via Profanity, and those created that way are easier to breach through a brute force attack, according to decentralized exchange (DEX) 1inch. Such an attempt would require significant computing power, however, it depends on the number of crypto funds kept in the wallet, says 1inch.

Join our Telegram group and never miss a breaking digital asset story.

Crypto Woes Worsen as DeFi Exploits Persist

The new vanity address exploit comes just a week after hackers stole $160 million from the crypto asset algorithmic market maker Wintermute. The attack was aimed at Wintermute’s decentralized finance (DeFi) operations, the firm’s CEO Evgeny Gaevoy said in a tweet.

The Wintermute hack was also made possible due to a bug in Profanity. In this case, the attacker exploited a Profanity-generated address that started with several zeroes.

Just like in 2021, the crypto space has witnessed numerous hacks and exploits this year as hackers continue to exploit DeFi weaknesses. However, this time the timing is much worse as the ongoing ‘crypto winter’ continues to take its toll on prices, pushing investors away from risk assets.

<strong>Finance is changing.</strong>
Learn how, with Five Minute Finance.
A weekly newsletter that covers the big trends in FinTech and Decentralized Finance.

Do you think the number of DeFi attacks will drop in the following years? Let us know in the comments below.

Tim Fries

Tim Fries

Author · Tokenist

Tim Fries is the cofounder of The Tokenist. He has a B. Sc. in Mechanical Engineering from the University of Michigan, and an MBA from the University of Chicago Booth School of Business. Tim served as a Senior Associate on the investment team at RW Baird's US Private Equity division, and is also the co-founder of Protective Technologies Capital, an investment firm specializing in sensing, protection and control solutions.

Related Stories