CryptoReal
CASE FILE — Jan 31, 2025

Solana Rug-Pull Toolkit DogWifTools Hacked, Over $10M Stolen From Its Own Users

DogWifTools, a widely used piece of software in Solana's meme coin ecosystem, was compromised in a supply-chain attack that drained more than $10 million from the wallets of its own users — a user base largely made up of people who relied on the tool to fabricate trading volume and stage rug pulls against retail traders.

The application, marketed as a bundling solution, was built to help token operators mask supply concentration and simulate the appearance of organic liquidity and trading activity, effectively letting bad actors dress up thinly traded, pre-planned tokens as legitimate markets.

Security researchers had raised concerns about the software for months before the breach. A GitHub security advisory flagged that its permission requests granted unusually deep access to users' systems, access that left little margin for error if the software itself were ever compromised.

According to reporting from SC World and Bleeping Computer, attackers reverse-engineered the DogWifTools codebase and obtained a GitHub token, which they used to gain persistent access to the project's private repository. Rather than pushing malicious code right away, the intruders waited for the development team to release legitimate updates, then modified those builds within hours to insert a Remote Access Trojan.

The tampering affected versions 1.6.3 through 1.6.6. Once an infected build was launched, the malware fetched a file named updater.exe into the AppData directory, which then quietly scanned the host machine for private keys, exchange login credentials, and stored identification photos. The compromise was confined to Windows installations; macOS users were not affected.

Beyond the direct wallet drains, attackers are reported to have used harvested KYC documents to register Binance accounts in the names of the compromised users — meaning victims' own identification records were allegedly repurposed to open new exchange accounts under their names without their knowledge, according to a claim shared by KookCapitalLLC.

In response, the DogWifTools team posted in its Discord server, promising enhanced security measures and a renewed commitment to rebuilding user trust.

One of the alleged perpetrators, operating under the name Jizzy Group, avoided mainstream social platforms entirely. Instead, the group published a manifesto on a Tor onion site, stating: "We specifically targeted scammers... It was morally correct to confiscate money that wasn't rightfully theirs."

That framing of vigilante justice sat awkwardly alongside a separate, more hostile message the group reportedly sent to victims, which described Solana as "a fucking joke designed by criminals for criminals" and singled out an individual referred to as "Malone" as "a script kiddie idiot piggybacking off of others['] work."

On-chain investigator ZachXBT weighed in publicly, saying he hoped the attackers would "leak an entire db with info of the users (scammers)."

Commentators have framed the episode as a case of scammers being turned on by more technically capable actors: the same operators who used DogWifTools to extract money from retail investors ultimately lost their own funds to a supply-chain compromise of the very tool they depended on.

DogwiftoolsMalwareMemes
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.