Not your keys, not your crypto: Negligence allows attacker to steal 1.1 billion VET tokens from the VeChain Foundation

The VeChain Foundation announced that last Friday, an attacker gained access to the Foundation’s wallet and ran off with 1.1 billion VET tokens (~1.3% of VET’s liquid supply). After an internal investigation, VeChain attributed the hack to “the negligence of the staff member,” citing an improper wallet creation process that exposed the Foundation’s private key. The project has since tagged the stolen funds and notified exchanges to blacklist any transfers connected to the attacker’s address.

Why it matters:

  • These events always display an irony of crypto today: transfers are permissionless until you want to cash out. The fact that any entity, no matter how right they may be, can dictate which coins or accounts are acceptable is antithetical to the original crypto-anarchist ideals. Exchanges provide easy to use on/off ramps for crypto but still maintain outsized power in the space.
  • The Vechain Foundation is not alone. Back in Oct., Algo Capital lost $3 million after attackers seized control of a mobile hot wallet controlled by its CTO. In similar recent news, Kraken reported a security flaw in the KeepKey crypto hardware wallet could allow a hacker to extract a user’s seed phrase with minimal effort (a claim that KeepKey’s creator, ShapeShift, later denied). The lesson is secure crypto storage practices are still misunderstood and easy to overlook but need to remain a top priority.
Let us know what you loved about the report, what may be missing, or share any other feedback by filling out this short form. All responses are subject to our Privacy Policy and Terms of Service.
Mentioned Assets

Suggested Research Based on your Watchlists

Create a new watchlist
Mentioned Assets