Skip to main content

Hacker steals more than $7 million in digital currency by switching a mere link

A render of virtual currency.
Image used with permission by copyright holder
Security firm Tripwire reports that a hacker managed to steal more than $7 million in digital currency by simply replacing a single link. The hack took place on Monday during an event called an Initial Coin Offering (ICO) to reel in investors of a cryptocurrency app called CoinDash. However, early investors quickly discovered that a link for depositing digital currency on the CoinDash website was not legitimate.

According to Tripwire, trading platform CoinDash began its ICO at 1 p.m. (GMT). Three minutes later, investors figured out that the link for sending Ether, a type of digital currency, was taking them to the wrong deposit location. Within those three minutes, the hacker managed to accumulate more than $7 million before CoinDash terminated the ICO and removed the page.

“The moment the token sale went public, the CoinDash website was hacked and a malicious address replaced the CoinDash Token Sale address,” CoinDash said. “As a result, more than 2,000 investors sent ETH to the malicious address. The stolen ETH amounted to a total of 37,000 ETH.”

Ether is the digital currency of the world’s second most popular cryptocurrency network, Ethereum. This platform consists of smart contracts, which are essentially bits of code that will execute when certain requirements are fulfilled. These “apps” are listed on the Ethereum network using what is called a blockchain, which serves as a registry that records all transactions. Ether, abbreviated as ETH, is what’s used to pay for things and services listed on the Ethereum network.

So why not just use real world cash? Because digital currency is decentralized. It’s not managed by banks or the government. Plus, both the merchant and buyer can remain completely anonymous, with a transaction digitally signed and verified by an unknown miner on the associated network. Ether is similar to Bitcoin in purpose although technically they are completely different digital currencies.

Individuals who successfully participated in a private “heads up” for whitelist contributors 15 minutes prior to the public ICO received “tokens” as proof of their CoinDash app investment. However, those who invested Ether using the hacked address are reportedly now demanding a refund. After all, the CoinDash website was not locked down tight, enabling a hacker to insert a simple link that collected millions in stolen digital currency.

However, many Ether users reportedly flocked to social networks and questioned the theft. Was this a genuine hack, or a simple scam using a hack as a cover story? As Tripwire states, there is no evidence to suggest foul play.

CoinDash is currently providing an online form for victims to complete as part of the company’s forensic investigation into the hack. Victims are asked to provide their email address, wallet address, a proven transaction number, and the amount of Ether sent.

“This was a damaging event to both our contributors and our company but it is surely not the end of our project,” CoinDash added. “We are looking into the security breach and will update you all as soon as possible about the findings. We are still under attack. Please do not send any ETH to any address, as the Token Sale has been terminated.”

Despite the hack, CoinDash said that it managed to secure $6.4 million from early contributors and whitelist participants in the 15-minute “heads up” prior to the ICO. Those who sent digital currency to the wrong Ether address during the hack will still receive tokens. Otherwise, investors who sent Ether to the wrong address after CoinDash removed the ICO page will not receive investment tokens.

Update: Added new information provided by CoinDash.

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
The 5 best laptops for accountants in 2024
Samsung Galaxy Book3 Pro 360 top down tablet view with pen.

Accountants tend to have a lot on their shoulders, especially as a lot of folks can rely on them for financial health, which is very important in today's world where the economy isn't at its best. As such, it's important to have the right tools for the job, and while there are a ton of great laptops out there that might work well for accounting, some will excel at it more than others. As such, we've gone out and picked our favorite laptops that can easily handle everything from large and heavy-duty spreadsheets to accounting software. Also, if you haven't quite found what you're looking for here, be sure to check out some of or other favorite laptop deals as well.
The Best Laptops for Accountants in 2024

Buy the  if you want the best overall laptop for accountants
Buy the if you want the best MacBook laptop for accountants
Buy the  if you want the best portable laptop for accountants
Buy the if you want the best 14-inch laptop for accountants
Buy the  if you want the best budget laptop for accountants

Read more
It’s time to stop believing these PC building myths
Hyte's Thicc Q60 all-in-one liquid cooler.

As far as hobbies go, PC hardware is neither the cheapest nor the easiest one to get into. That's precisely why you may often run into various misconceptions and myths.

These myths have been circulating for so long now that many accept them as a universal truth, even though they're anything but. Below, I'll walk you through some PC beliefs that have been debunked over and over, and, yet, are still prevalent.
Liquid cooling is high-maintenance (and scary)

Read more
AMD’s next-gen CPUs are much closer than we thought
AMD Ryzen 7 7800X3D held between fingertips.

We already knew that AMD would launch its Zen 5 CPUs this year, but recent motherboard updates hint that a release is imminent. Both MSI and Asus have released updates for their 600-series motherboards that explicitly add support for "next-generation AMD Ryzen processors," setting the stage for AMD's next-gen CPUs.

This saga started a few days ago when hardware leaker 9550pro spotted an MSI BIOS update, which they shared on X (formerly Twitter). Since then, Asus has followed suit with BIOS updates of its own featuring a new AMD Generic Encapsulated Software Architecture (AGESA) -- the firmware responsible for starting the CPU -- that brings support for next-gen CPUs (spotted by VideoCardz).

Read more