A man in southern Florida, United States, was alleged to have stolen approximately $222 million of encrypted assets by embedding malicious software in game documents. The case shows that the attackers did not aim directly at the chain agreement, but instead began with user equipment and obtained control of the wallet and account from a common download scene.
Spreading malware through games
The suspect was reportedly charged with embedding malicious software into games-related documents and disseminating it through download channels. Once the victim has installed or operated the document, sensitive information in the equipment may be extracted, including log-in certificates, wallet data or other information that can be used to transfer assets.
Such attacks often do not rely on smart contract loopholes, but rather use the trust of users in games, models or deciphering documents. Once the equipment is infected, the attackers may take over further accounts and transfer encrypted assets.
About $220 million.
The reported cases involved the transfer of encrypted assets totalling approximately $220,000. At this stage, the focus of the public information is on the way in which the suspect is operating and the amount involved, rather than on a technical malfunction in a particular public chain or in a particular DeFi agreement itself.
In terms of the nature of the incidents, this is closer to the end-of-pipe security issue. For encrypted users, the security of wallets depends not only on private key custody, but also on whether the equipment environment is controlled by malicious programs.
Attack route to terminal.
In recent years, many incidents of encrypted theft have shown that the attackers are increasingly entering user equipment through browser plugs, disguised kits, game files and social engineering. The threshold for such an approach is lower than that for direct attacks on large agreements, and it is easier to circumvent general user protection.
Once again, this case reflects the fact that the risk of encrypted assets does not come from the chain alone. As long as terminals are controlled, wallets, exchange accounts and even dual authentication information can be exposed, leading to the transfer of assets.
