HELP: 55k ADA stolen from my Eternl Wallet

Hello Cardano Fam,

55k ADA has been stolen from my account.

I have been holding ADA since Jan 2021 (DCAing slowly). Originally all of this was in Daedalus.

For convenience I started using Eternl available from iPhone App Store, from last year.

I connected my public addresses to crypto tax calculation websites - koinly, coinledger.

Here’s the transaction: Transaction c7e316a3334c10a4bbe9b763fc4c2f6c7450f87fb003861f28b6ab6cf52156c6 - Cardanoscan

What do I do next?

This is a lot of money for me, I would appreciate any help I can get in this matter.

2 Likes

You cant really do anything once the transaction has been confirmed by the network.

Id recommand to report it to your local authorities and hope for the best.

1 Like

Thank you Zyroxa!

It looks like the ADAs were first sent to Address addr1v8x0wa3mxflejvnhrwas6jq0vmpamv0t2m6au3zez9hpplqejfefl - Cardanoscan

and then eventually to $credit.pay handle? Address addr1v83gkkw3nqzakg5xynlurqcfqhgd65vkfvf5xv8tx25ufds2yvy2h - Cardanoscan

  1. Are the above observations correct?

  2. Is my money lost for sure? :frowning:

  3. Can someone please tell me how this was possible? I didn’t initiate or approve this transaction.

The first address is very typical for the deposit address of a centralised exchange (CEX): only used once, ADA arrives and is completely sent further, where the second transaction also collects deposits from other addresses and forwards them all together to one central address with lots of transactions.

The centralised exchange is not the scammer. It was just used by the scammer to cash out. (One could see some responsibility/liability of them for lax KYC processes etc., but they have lots of money for good lawyers.)

They probably did not buy the $credit.pay handle deliberately, but just got it accidentally by one of their customers (or that customer wanted to get rid of it).

The address addr1v…2yvy2h got the handle from the address addr1v…77jc7x in transaction ffdfd3f4ec1f0a42c55feb770e512d95f06ad664298606b42e8c293877c0fd9d a couple of months ago. So, that was probably an earlier address of that CEX. That address was used as an example in blockfrost - How to get balance of enterprise address - Cardano Stack Exchange years ago. I asked Marek where he got it and he is not 100% sure, but thinks that it was Kraken.

So, you could try if Kraken is willing to help you track down the attacker. You’d maybe want a lawyer or your local law enforcement authorities to help you with that.

How can this happen?

  • Maybe you gave away or leaked your seed phrase somewhere.
  • Maybe some malware grabbed the encrypted keys from your computer and brute-forced or also grabbed the spending password for it.
  • In the last days, we had some users who had their seed phrases in LastPass which was famously hacked back in December 2022. Quite possible that someone has broken the passwords from that hack and targets Cardano users now.
2 Likes

@buvrgm i am sorry for your loss, @HeptaSean might be right with the leaks.

just our of curiousity, can i ask you: “with crypto holdings of around $35000, why have you not stored your ada on a hardware wallet? which costs less than $100.”

Thanks.

I am sorry about your stolen ADA. This forum post provides links to web forms that display the Cardanoscan API end point responses in list format: Cardanoscan API (Free) - #6 by BUDDYM They might help you with documenting the trail of transactions. Good luck with the recovery. Hopefully, something good will come out of this. Cheers!