Crypto Heist Blunder: Authorities Arrest Wrong Man in $1M BAYC NFT Theft

Key Insights

  • Law enforcement might have arrested the wrong suspect in a high-profile theft of Bored Ape Yacht Club (BAYC) NFTs from 2022, according to Zach XBT.
  • Sam Curry, a former security researcher at Yuga Labs (the creators of BAYC) was mistakenly detained in 2023 while at an airport.
  • Curry had been working to catch the hacker behind the theft and had even accessed part of the code used in the scam in a bid to do so.
  • However, logs from the NFT platform OpenSea ended up showing Curry’s IP address as the hacker’s.
  • Around 143 Bored Ape NFTs (worth more than $13.5 million) have been stolen since the collection’s launch in June 2021

Mistakes tend to be costly in the crypto and NFT spaces, not just financially but in terms of reputation.

A recent revelation from independent investigator ZachXBT has just reopened the conversation on an interesting case.

In this case, law enforcement might have arrested the wrong suspect in a high-profile theft of Bored Ape Yacht Club (BAYC) NFTs from 2022.

These NFTs were worth over $1 million at the time, and here is the full story.

A Costly Mistake

ZachXBT claimed that law enforcement arrested the wrong person in connection with a 2022 scam.

The scam in question led to the theft of 14 Bored Ape NFTs, which were worth roughly $86,000 each at the time.

In total, the amount of assets stolen raked up a staggering $1.2 million, if not more.

According to ZachXBT, Sam Curry, a former security researcher at Yuga Labs (the creators of BAYC) was mistakenly detained in 2023 while at an airport.

Curry had been working to catch the hacker behind the theft and had even accessed part of the infected code used in the scam in a bid to do so.

However unfortunately, logs from the NFT platform OpenSea ended up showing Curry’s IP address as the hacker’s, which investigators used to wrongly connect him to the crime.

“It’s unfortunate to see how a security researcher was detained when stronger leads on a threat actor potentially responsible exist,” ZachXBT posted.

How the Theft Happened

The attack in question happened in December 2022, when an unauthorized individual stole 14 Bored Ape NFTs from multiple investors.

They did this by hijacking a script embedded in a fake website and then luring victims in through phishing tactics.

The victims unknowingly exposed their private-keys and granted the attacker access to their Ethereum wallets, leading to the thefts.

ZachXBT explained that Curry had actually accessed the same script that was used to steal the NFTs as part of his investigation.

Interestingly, he also did so using a private-key embedded in the same JavaScript code that the attacker had left behind.

This little bit of data was likely used by multiple individuals or systems as part of the hacker’s getaway strategy.

ZachXBT then went ahead to trace the attacker by using blockchain forensics to track the movement of funds through Tornado Cash.

His findings turned up a separate wallet and a deleted X account that may have belonged to the true hacker, proving that Curry might have been innocent.

The Bigger Problem

This incident isn’t isolated. Another separate investigation from Immunefi showed that around 143 Bored Ape NFTs (worth more than $13.5 million) have been stolen since the collection’s launch in June 2021.

The majority of these thefts happened during two major hacks in 2022, with one of them happening in April of the same year.

Hackers took over BAYC’s official Instagram account and posted a link to a fake website, luring victims in and stealing their assets.

Two months after this, in June, another attack hit the BAYC and Otherside Discord channels, where the hackers, posing as a BAYC moderator, used a phishing link to steal even more funds.

Another separate report by blockchain analytics firm Elliptic showed that over $100 million worth of NFTs were stolen between January and July 2022 alone.

This shows that there are many issues still present in the NFT space, especially in high-value collections like BAYC.

Disclaimer: Voice of Crypto aims to deliver accurate and up-to-date information, but it will not be responsible for any missing facts or inaccurate information. Cryptocurrencies are highly volatile financial assets, so research and make your own financial decisions.

The content is for reference only, not a solicitation or offer. No investment, tax, or legal advice provided. See Disclaimer for more risks disclosure.
  • Reward
  • 2
  • Share
Comment
0/400
GateUser-9184ee56vip
· 05-11 09:50
Bull Run 🐂
Reply0
GateUser-9184ee56vip
· 05-11 09:50
HODL Tight 💪
Reply0