A sophisticated scheme involving individuals posing as IT insiders has led to approximately $1 million in cryptocurrency losses across various NFT protocols and Web3 projects. On-chain investigator ZackXBT exposed the widespread exploitation, which primarily targeted minting mechanisms, causing significant financial damage and undermining trust within the affected communities.
Fake IT Insiders Exploit Web3 Projects
Over the past week, a group of malicious actors, masquerading as legitimate IT professionals, infiltrated several Web3 projects, resulting in an estimated $1 million in crypto theft. The on-chain sleuth ZackXBT brought these exploits to light, detailing how the perpetrators manipulated project infrastructure for their illicit gains.
Key Targets and Exploitation Methods
-
Favrr: A Web3 fan-token marketplace.
-
Replicandy: An NFT project.
-
ChainSaw: Another NFT project.
-
Unnamed Teams: Several other projects were also impacted but not publicly identified by ZackXBT.
The primary method of exploitation involved the manipulation of NFT minting mechanisms. The attackers minted large quantities of NFTs, subsequently selling them off. This influx of supply caused the floor price of the affected NFTs to plummet to zero, allowing the perpetrators to extract substantial profits.
Tracing the Stolen Funds
Following the exploits, the stolen funds were moved through various channels, including exchanges and multiple wallets, in an attempt to obscure their origin. While the funds from the ChainSaw hack largely remain dormant, the crypto stolen from Favrr was transferred to nested services, making tracing more complex.
Broader Implications for Web3 Security
The infiltration of crypto and blockchain projects by malicious software developers continues to pose a significant threat to the industry. These incidents not only lead to substantial financial losses for users but also undermine the credibility and efforts of legitimate software development teams globally. The ongoing challenge highlights the critical need for enhanced security protocols and vigilance within the Web3 ecosystem.
A Growing Trend of Insider Threats
This incident is part of a broader trend of insider threats and sophisticated cyberattacks targeting various industries. For instance, in November 2024, the North Korean government-linked hacking group "Ruby Sleet" was identified infiltrating aerospace and defense contractors, and later, IT firms through fake recruitment initiatives and social engineering scams. Similarly, Coinbase experienced a data leak and extortion attempt in May 2025, where external threat actors bribed customer service contractors to steal user data, impacting approximately 69,461 users.
These events underscore the evolving landscape of cyber threats, where internal vulnerabilities and social engineering tactics are increasingly leveraged to compromise sensitive systems and data.
Sources
-
IT hackers infiltrate crypto projects, steal $1 million, Cointelegraph.
-
This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.
-