Wintermute Hack
What happened
On September 20, 2022, Wintermute suffered an approximately $160 million theft from its DeFi operations. Security researchers linked the compromise of a privileged wallet to Profanity, an Ethereum vanity-address generator with a serious weakness in its private-key generation.
Profanity relied on a 32-bit seed and deterministic generation, leaving far less randomness than a securely generated Ethereum private key requires. A vulnerable wallet's administrator role extended the impact beyond its own balance to assets controlled by the vault. The reviewed analyses support the Profanity explanation but do not directly establish the attacker's exact key-recovery process.
Case & protocol details
How it happened
- Wintermute used Profanity to generate a wallet address beginning with repeated zeroes, according to the security analyses.
- Profanity's limited seed randomness made generated private keys vulnerable to recovery; researchers identified this as the likely route to the wallet compromise.
- The compromised address held administrator permissions on a Wintermute vault. Beosin's analysis identified calls from that address that transferred assets to an attacker-controlled contract.
- The theft caused an estimated $160 million loss across Wintermute's DeFi operations.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Q3 2022 Blockchain Security Report beosin.com
- analysis The Real Cause of the Wintermute Exploit slowmist.medium.com
- analysis Website reference coindesk.com
- analysis Website reference twitter.com
- analysis Website reference certik.com
- analysis How Crypto Trading Firm Wintermute Was Hacked For $160 Million forbes.com
- analysis Explained: The Wintermute Hack (September 2022) halborn.com
- analysis Our short analysis of the Profanity tool vulnerability blocksecteam.medium.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.