Vanity address exploit Hack
What happened
Hackers have stolen around $950,000 worth of crypto from an Ethereum "vanity address" generated using the Profanity tool in an exploit likely using a "brute force" attack. The funds were transferred to Tornado Cash.
The exploit targeted a vulnerability related to the vanity address generator Profanity, likely using a brute force attack. A vanity address is a type of crypto address that conforms to certain parameters laid out by the creator. The hacker stole 732 Ethereum on September 25 before transferring the funds straight to Tornado Cash.
The exploit leveraged a similar vulnerability related to the recent $160 million attack on market maker Wintermute.
Victim:
https://etherscan.io/address/0x9731f44b…0539b9
Tornado cash deposits:
https://bloxy.info/txs/calls_from/0x9731f44b…0539b9?signature_id=994162&smart_contract_address_bin=0xd90e2f92…24f31b
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report decrypt.co
- report Report twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.