Trade Haven Hub - Investing and Stock News
  • Investment Tips
  • Trade Tips
  • Crypto News
  • Economy News
  • Stock Market
  • Investment Tips
  • Trade Tips
  • Crypto News
  • Economy News
  • Stock Market
No Result
View All Result
Trade Haven Hub - Investing and Stock News
No Result
View All Result
Home Crypto News

THORChain Co-Founder’s Wallet Drained $1.35M in DPRK Telegram Scam

by
September 12, 2025
in Crypto News
0
THORChain Co-Founder’s Wallet Drained $1.35M in DPRK Telegram Scam
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

THORChain co-founder JP lost $1.35 million from a personal wallet on Sept. 9 after falling victim to a Telegram phishing scam linked to North Korea. The attack combined a hacked Telegram account, a deepfake Zoom call, and what he believes was a zero-day exploit.

His loss joins the list of recent high-profile losses in the crypto space. Last month, billionaire heiress Taylor Thomson lost over $80 million in crypto after investments tied to a psychic. Similarly, earlier this month, a crypto investor lost $3.05M after signing a malicious transaction.

$1.2M THORChain Wallet Drained in Telegram Deepfake Scam, Investigators Confirm

Blockchain investigator ZachXBT confirmed the incident, stating that JP’s wallet was drained after he joined a fake meeting link shared through Telegram. PeckShieldAlert had earlier reported the breach, reporting that approximately $1.2 million had been stolen from a THORChain user’s wallet.

The wallet likely belongs to @jpthor who had a private wallet compromised due to a fake meeting scam a few days ago.

JP is one of the people whose has greatly benefited financially from the laundering of DPRK hacks/exploits.

So it’s a bit poetic he got rekt here by DPRK. pic.twitter.com/T57RRJ0bbf

— ZachXBT (@zachxbt) September 12, 2025

Unravelling the stolen funds, JP explained in a post on X that the funds were tied to an old MetaMask account he had forgotten. The wallet contained staked assets that did not appear on Etherscan, making it easy to overlook.

Yes, an old metamask (which I had completely forgotten about) was drained. They had access to my encrypted entire iCloud + keychain.

Ironically – only the private keys (radioactive) were vulnerable. Vultisig wallets were untouched, despite also using iCloud.

They’re safe -… pic.twitter.com/TWw7AdCgPw

— JP (@jpthor) September 12, 2025

JP also explained that the scam began when a friend’s Telegram account was hacked. The attackers invited him to a Zoom call, where a deepfake video was used to increase credibility. JP clicked a link during the call but saw no suspicious prompts or requests for credentials.

He believes the attackers may have accessed his encrypted iCloud Keychain or a separate Chrome profile on his Mac, where MetaMask keys were stored. “There was no request for admin passwords or installation,” JP wrote. “It has to be an active or recently patched 0-day.”

Ok so this attack finally manifested itself.

Had an old metamask cleaned out (which I forgot about, it was staking some assets which don’t appear on etherscan unless you use portfolio tracking sites)

Summary
1) friend’s hacked telegram account + deep-fake video on zoom
2)… https://t.co/bjqqFZ5ddB

— JP (@jpthor) September 9, 2025

In a bid to recover the stolen funds, on-chain data flagged by Lookonchain showed a new message sent to the exploiter’s wallet. The message, recorded on Etherscan, offered a bounty if the stolen THOR tokens were returned within 72 hours, promising “no legal action” if the hacker complied and provided contact details for the THORSwap team.

Notably, ZachXBT noted that THORChain and its co-founder had previously profited from the laundering of funds tied to DPRK exploits, including hacks on exchanges like Bybit. “It’s a bit poetic he got rekt here by DPRK,” ZachXBT said.

Highlighting the lessons learned from the experience, JP emphasized that private keys grow riskier the longer they are stored, urging users not to back them up on iCloud, Google Drive, or similar services. He also recommended using two-factor authentication on a separate device, such as a burner phone, to reduce exposure.

He added that threshold signature wallets like Vultisig, which split key shares across multiple devices, represent the next stage of crypto security. “Attacks are going to only get worse,” JP said. “It can be solved; we just need to upgrade our wallets.”

Telegram Scams Surge: $2.2B Lost in 2025 as Malware Attacks Overtake Phishing

By the end of June this year, crypto investors had lost $2.2B, mostly from wallet breaches and scams. Crystal Intelligence confirmed that over 1,000 hacks, scams, and DeFi breaches have stolen $22.7B in crypto across 14 years of tracked incidents.

Specifically, Scam Sniffer reported that crypto scammers are targeting Telegram, where malware scams have surged 2,000% since November and overtaken traditional phishing. Attackers spread malware through bogus verification bots in trading, airdrop, and alpha groups, allowing them to steal passwords, private keys, and wallet data once users execute malicious code.

Noting the abundance of hacks on Telegram, last year, the United Nations estimated scams, money laundering, and stolen data sales on Telegram generated more than $36.5 billion annually, often through USDT.

Criminals also promote deepfake tools and malware, with the U.S. Treasury linking Huione Group to $98 billion in illicit crypto flows tied partly to North Korea’s Lazarus Group.

Telegram shuts down $27 billion Huione crypto scam marketplace but rivals surge 400% volume as criminal networks quickly migrate to successor platforms like Tudou Guarantee.#Telegram #CryptoScamhttps://t.co/xjpxGw5SSo

— Cryptonews.com (@cryptonews) June 24, 2025

To curb this, Telegram shut down Huione Guarantee in May 2025, but rival Tudou Guarantee quickly absorbed its users and drove a 400% surge in activity.

Similarly, Telegram shut down thousands of channels tied to Xinbi and Huione Guarantee, which processed over $35 billion in illicit USDT transactions, Elliptic reported. The platforms used encrypted groups to sell money laundering, stolen data, and fake IDs, with Huione linked to Cambodia’s ruling elite.

The post THORChain Co-Founder’s Wallet Drained $1.35M in DPRK Telegram Scam appeared first on Cryptonews.

Previous Post

SOL Breaks $230, Touches $240 for First Time Since January – Is Solana Season Finally Here?

Next Post

Ethena Labs Withdraws Bid for Hyperliquid’s USDH Stablecoin Amid Pushback

Next Post
Ethena Labs Withdraws Bid for Hyperliquid’s USDH Stablecoin Amid Pushback

Ethena Labs Withdraws Bid for Hyperliquid’s USDH Stablecoin Amid Pushback

  • Trending
  • Comments
  • Latest
Buy Bitcoin Under $100K Before The Next Bull Run

Buy Bitcoin Under $100K Before The Next Bull Run

April 22, 2025
Quantum Computing: its Evolution and its Potential Future

Quantum Computing: its Evolution and its Potential Future

March 20, 2025
Stock Market News UK Update: FTSE 100 & 250 Rise

Stock Market News UK Update: FTSE 100 & 250 Rise

March 20, 2025
Air Direct Capture – Reducing CO2 from the Atmosphere

Air Direct Capture – Reducing CO2 from the Atmosphere

March 20, 2025
SunnyMining Launches New Cloud Mining Contracts for BTC, ETH, and XRP

SunnyMining Launches New Cloud Mining Contracts for BTC, ETH, and XRP

0
Quantum Computing: its Evolution and its Potential Future

Quantum Computing: its Evolution and its Potential Future

0
Quantum Computing: its Evolution and its Potential Future

Quantum Computing: its Evolution and its Potential Future

0
Air Direct Capture – Reducing CO2 from the Atmosphere

Air Direct Capture – Reducing CO2 from the Atmosphere

0
SunnyMining Launches New Cloud Mining Contracts for BTC, ETH, and XRP

SunnyMining Launches New Cloud Mining Contracts for BTC, ETH, and XRP

September 12, 2025
XRP Investment Strategies Are Becoming More Diverse: Moving Beyond Holding Onto Coins

XRP Investment Strategies Are Becoming More Diverse: Moving Beyond Holding Onto Coins

September 12, 2025
FTX’s Sam Bankman-Fried Files Appeal to U.S Court in a Bid to Reduce 25-Year Sentence

FTX’s Sam Bankman-Fried Files Appeal to U.S Court in a Bid to Reduce 25-Year Sentence

September 12, 2025
105 of 107 Economists Expect Fed to Cut Rates 25 Basis Points on September 17: Reuters

105 of 107 Economists Expect Fed to Cut Rates 25 Basis Points on September 17: Reuters

September 12, 2025

    Stay updated with the latest news, exclusive offers, and special promotions. Sign up now and be the first to know! As a member, you'll receive curated content, insider tips, and invitations to exclusive events. Don't miss out on being part of something special.


    By opting in you agree to receive emails from us and our affiliates. Your information is secure and your privacy is protected.

    Recent News

    SunnyMining Launches New Cloud Mining Contracts for BTC, ETH, and XRP

    SunnyMining Launches New Cloud Mining Contracts for BTC, ETH, and XRP

    September 12, 2025
    XRP Investment Strategies Are Becoming More Diverse: Moving Beyond Holding Onto Coins

    XRP Investment Strategies Are Becoming More Diverse: Moving Beyond Holding Onto Coins

    September 12, 2025
    FTX’s Sam Bankman-Fried Files Appeal to U.S Court in a Bid to Reduce 25-Year Sentence

    FTX’s Sam Bankman-Fried Files Appeal to U.S Court in a Bid to Reduce 25-Year Sentence

    September 12, 2025
    105 of 107 Economists Expect Fed to Cut Rates 25 Basis Points on September 17: Reuters

    105 of 107 Economists Expect Fed to Cut Rates 25 Basis Points on September 17: Reuters

    September 12, 2025
    • About us
    • Contact us
    • Privacy Policy
    • Terms & Conditions

    Copyright © 2025 tradehavenhub.com | All Rights Reserved

    No Result
    View All Result
    • Investment Tips
    • Trade Tips
    • Crypto News
    • Economy News
    • Stock Market

    Copyright © 2025 tradehavenhub.com | All Rights Reserved