CryptoReal
CASE FILE — Sep 20, 2022

Wintermute's $160M Hot Wallet Breach Traced to a Flawed Vanity Address Tool

Market maker Wintermute has lost more than $160 million in its second major incident this summer.

Back in June, the firm sent 20 million OP tokens to an address it didn't actually control. This time, its hot wallet itself has been compromised — most likely because that wallet's address was generated using Profanity, a vanity-address tool with a known vulnerability.

Wintermute CEO Evgeny Gaevoy disclosed the loss roughly three hours after the theft occurred, writing: "We've been hacked for about $160M in our defi operations. Cefi and OTC operations are not affected," and adding, "We are solvent with twice over that amount in equity left."

Gaevoy has since said the vanity address was created for "gas savings" rather than for aesthetic reasons — a decision that turned out to be extraordinarily costly.

The last time Wintermute suffered a major loss, the exploiter ultimately returned most of the funds. Whether that pattern repeats this time remains to be seen.

Key addresses and transactions:

The breach appears to trace back to a weakness in Profanity, the tool used to generate custom Ethereum vanity addresses. After that vulnerability came to light the previous week, roughly $3.3 million was drained from a range of wallets in the following days by an address identified as 0x6AE09AC63487FCf63117A6D6FAFa894473d47b93.

Both Wintermute's hot wallet and its DeFi vault contract carry vanity addresses featuring multiple leading zeros. It appears the hot wallet's private key was compromised, and that access was then used to drain the vault.

Sums referenced in this case file

Although the security flaw in Profanity-generated addresses only became widely known recently, the issue had actually been flagged on the tool's GitHub repository back in January.

Security researcher Mudit Gupta explained the mechanics: the vault's design only permits admin-designated addresses to move funds, and Wintermute's hot wallet held that admin role, exactly as intended. In that sense, the contracts behaved correctly — the actual failure was that the admin address itself had been compromised. Gupta also noted that around the time the Profanity vulnerability was disclosed, Wintermute withdrew all ether from that admin address, suggesting the team recognized some level of risk — but neglected to also revoke its admin permissions on the vault.

Most of the stolen assets were stablecoins, amounting to $118.4 million in total. The bulk of that was funneled into Curve's 3pool, likely as an attempt to dodge blacklisting efforts. As a result, the exploiter is now the third-largest holder of 3CRV, controlling over 13% of its total supply — raising the question of whether 3pool is becoming a de facto replacement for Tornado Cash as a mixing venue.

The remainder of the stolen funds includes 671 WBTC (worth roughly $13 million), 6,928 ETH (worth $9.4 million), and a range of other tokens. At the time of reporting, the attacker's wallet held assets worth approximately $162.3 million.

Wintermute has stated that it doesn't expect "a major selloff of any sort," but several smaller-cap tokens remain vulnerable to price impact given how much of their circulating supply was caught up in the theft — reportedly as high as 21% for one token:

  1. $PRIMATE — 21%
  2. $CUBE — 12%
  3. $NYM — 2.44%
  4. $eXRD — 1.93%
  5. $YGG — 1.17%

As of this writing, most of the stolen assets hadn't been swapped or moved further, raising the possibility that the attacker might be angling to negotiate a whitehat bounty instead of cashing out.

Shortly after news of the hack spread, a scammer exploited the attention by spoofing a fake honeypot token called WinterMuteInu to appear as though it originated from the exploiter's own address. The scam's operator seeded a Uniswap pool with 35 ETH in liquidity, which has since grown to roughly 166 ETH (about $225,000).

This is the first major hack since last month's sanctioning of Tornado Cash, and — assuming Wintermute can't recover the stolen funds — it will be worth watching closely how the attacker attempts to launder them, particularly given the concerns raised about Curve's 3pool potentially serving as an alternative mixing route for Curve users generally.

For now, Wintermute's Gaevoy has simply urged the industry to "stay humble."

ProfanityWintermute
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.