DogWifTools Hack
What happened
DogWifTools' Windows releases were compromised in January 2025, exposing users' wallet keys. Developers reported tampering with versions 1.6.3-1.6.6. A community estimate exceeded $10 million, but the final loss was disputed and not independently established.
The reported failure was compromise of the software distribution process. The available evidence does not establish that the altered binaries were cryptographically signed, or a final verified loss or recovery amount.
Case & protocol details
How it happened
- The developers said an attacker extracted a GitHub token by reverse-engineering the software.
- Access to the private repository allowed replacement of legitimate Windows releases with trojanized builds.
- Running an affected build downloaded
updater.exeinto AppData, targeting locally stored wallet keys. - Users reported drained wallets; the team announced an investigation and additional security measures.
Evidence & learning
Sources and on-chain records
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.