Skip to main content

Hacker steals more than $7 million in digital currency by switching a mere link

Security firm Tripwire reports that a hacker managed to steal more than $7 million in digital currency by simply replacing a single link. The hack took place on Monday during an event called an Initial Coin Offering (ICO) to reel in investors of a cryptocurrency app called CoinDash. However, early investors quickly discovered that a link for depositing digital currency on the CoinDash website was not legitimate.

According to Tripwire, trading platform CoinDash began its ICO at 1 p.m. (GMT). Three minutes later, investors figured out that the link for sending Ether, a type of digital currency, was taking them to the wrong deposit location. Within those three minutes, the hacker managed to accumulate more than $7 million before CoinDash terminated the ICO and removed the page.

Recommended Videos

“The moment the token sale went public, the CoinDash website was hacked and a malicious address replaced the CoinDash Token Sale address,” CoinDash said. “As a result, more than 2,000 investors sent ETH to the malicious address. The stolen ETH amounted to a total of 37,000 ETH.”

Please enable Javascript to view this content

Ether is the digital currency of the world’s second most popular cryptocurrency network, Ethereum. This platform consists of smart contracts, which are essentially bits of code that will execute when certain requirements are fulfilled. These “apps” are listed on the Ethereum network using what is called a blockchain, which serves as a registry that records all transactions. Ether, abbreviated as ETH, is what’s used to pay for things and services listed on the Ethereum network.

So why not just use real world cash? Because digital currency is decentralized. It’s not managed by banks or the government. Plus, both the merchant and buyer can remain completely anonymous, with a transaction digitally signed and verified by an unknown miner on the associated network. Ether is similar to Bitcoin in purpose although technically they are completely different digital currencies.

Individuals who successfully participated in a private “heads up” for whitelist contributors 15 minutes prior to the public ICO received “tokens” as proof of their CoinDash app investment. However, those who invested Ether using the hacked address are reportedly now demanding a refund. After all, the CoinDash website was not locked down tight, enabling a hacker to insert a simple link that collected millions in stolen digital currency.

However, many Ether users reportedly flocked to social networks and questioned the theft. Was this a genuine hack, or a simple scam using a hack as a cover story? As Tripwire states, there is no evidence to suggest foul play.

CoinDash is currently providing an online form for victims to complete as part of the company’s forensic investigation into the hack. Victims are asked to provide their email address, wallet address, a proven transaction number, and the amount of Ether sent.

“This was a damaging event to both our contributors and our company but it is surely not the end of our project,” CoinDash added. “We are looking into the security breach and will update you all as soon as possible about the findings. We are still under attack. Please do not send any ETH to any address, as the Token Sale has been terminated.”

Despite the hack, CoinDash said that it managed to secure $6.4 million from early contributors and whitelist participants in the 15-minute “heads up” prior to the ICO. Those who sent digital currency to the wrong Ether address during the hack will still receive tokens. Otherwise, investors who sent Ether to the wrong address after CoinDash removed the ICO page will not receive investment tokens.

Update: Added new information provided by CoinDash.

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
Google’s new satellite network can help spot wildfires
penny machine learning income predictor 30619164  space satellite orbiting the earth

The first FireSat satellite has launched and made a connection with Earth. The FireSat system is a collaborative effort between Google Research, Muon Space, Earth Fire Alliance, Moore Foundation, and numerous other agencies, and it has a single, deceptively simple purpose: to detect wildfires before they become too hard to contain and control.

Wildfires have been a constant problem for agencies. Early detection is vital, but fires can often start in subtle ways; by the time anyone notices the growing blaze, it's too late to stop. Just take the wildfires in Los Angeles earlier this year as an example. Apps have been created to crowdsource fire detection, and the traditional method of watching for wildfires is through satellite imagery.

Read more
Buy this Samsung 49-inch OLED monitor deal and get a free 4TB SSD
The Samsung Odyssey OLED G9 monitor with 990 Pro SSD on a white background.

If you're thinking about making some upgrades to your PC gaming setup, you can take advantage of monitor deals and SSD deals with just one purchase through this interesting offer from Samsung. A bundle that combines the 49-inch Samsung Odyssey OLED G9 gaming monitor and the 4TB Samsung 990 Pro SSD is on sale, dropping the total price from $2,300 to only $1,634. That's $666 in savings that you won't find anywhere else, but you need to hurry if you don't want to miss out because there's no telling when the discount ends.

Why you should buy the 49-inch Samsung Odyssey OLED G9 gaming monitor and 4TB Samsung 990 Pro SSD
The Samsung Odyssey OLED G9 is featured in our roundup of the best gaming monitors as the best 32:9 gaming monitor, as it provides an unmatched immersive experience with OLED technology and a dual QHD resolution for vibrant colors and lifelike images, a 240Hz refresh rate for smooth animations on the screen, and a 0.03ms response time that could give you the edge over the competition. The gaming monitor also supports Nvidia's G-Sync and AMD's FreeSync Premium Pro, which will eliminate screen tearing and stuttering.

Read more
China joins the global push for AI content regulation
AI chatbots.

Many international entities are pushing for better regulation of AI-generated content on the internet– and China’s government is the latest to reign in the use of the quickly developing technology.

According to Bloomberg, several government ministries have joined with the Chinese internet watchdog Cyberspace Administration of China (CAC) to announce a new mandate that will require internet users to identify any AI-generated content as such in a description or metadata encoding.

Read more