Vanity address exploit Hack

TOTAL LOST $950K
Low Other

What happened

Hackers have stolen around $950,000 worth of crypto from an Ethereum "vanity address" generated using the Profanity tool in an exploit likely using a "brute force" attack. The funds were transferred to Tornado Cash.

The exploit targeted a vulnerability related to the vanity address generator Profanity, likely using a brute force attack. A vanity address is a type of crypto address that conforms to certain parameters laid out by the creator. The hacker stole 732 Ethereum on September 25 before transferring the funds straight to Tornado Cash.

The exploit leveraged a similar vulnerability related to the recent $160 million attack on market maker Wintermute.

Victim:

https://etherscan.io/address/0x9731f44b…0539b9

Tornado cash deposits:

https://bloxy.info/txs/calls_from/0x9731f44b…0539b9?signature_id=994162&smart_contract_address_bin=0xd90e2f92…24f31b

Case & protocol details

Classification Other
Protocol Type Exploit/Other

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.