Victim of on-chain exploit publicly messages attacker with recovery ultimatum, reveals law enforcement involvement and exchange coordination to freeze stolen funds.
Security & Exploits ·
A victim of an on-chain exploit published a message to the attacker's wallet address, escalating pressure after 48 hours without fund recovery or contact. The message warns that the stolen funds have been flagged across exchanges and cannot be off-ramped, with any transfers to new addresses automatically flagged as "poison" due to their compromised origin. The victim claims to have engaged security firms to coordinate with exchanges on freezing attempts and states that cross-chain bridging and asset swaps will not obscure the stolen value.
The message reveals that investigators traced the attacker's funding back through a ChangeNow account, obtaining the attacker's source wallet address (0xba1b0E433EE9C849Ec4aeBAf6e739E14881D8bA3), IP address, and user data. According to the victim, this information has been reported to law enforcement via ic3.gov. The victim explicitly warns that blockchain traceability makes hiding impossible and that upstream and downstream wallets connected to the attacker's holdings face ongoing flagging.
It remains unclear whether the attacker has responded, what the actual exploit vector was, or the total amount stolen. The effectiveness of exchange-level freezing and law enforcement coordination in recovering the funds is not yet determined. The message appears to have been drafted for delivery the following day, and no public confirmation of the attacker's reply or fund recovery has been stated.