The tokens were stolen by someone who compiled vanity addresses eligible for ARB airdrops.
It is reported that the hacked Vanity address was used to steal $500000 worth of tokens in the airdrop of layer 2 extension solution Arirum on March 23.
Vanity address is a customized digital currency address, including special English words or sentences selected by the user, which is committed to making it more personalized and easier to identify. However, the security of vanity addresses is also questionable.
The article explained that the token was stolen by someone, who compiled the program to accept the vanity address of the ARB token, then used the vanity address maker to form a similar address, and then assigned the token of the airdropped material to this address. The hacking of this vain address makes it impossible for the initial user to claim his ARB token.
Many login password users expressed the sadness of their stolen ARB tokens on Twitter. Most of the affected I do not know the underlying cause of the damage, nor do I know how to treat it.
The establishment of a virtual address requires special software or service, which may seriously endanger the security of the user's public key. The hack that obtains the public key can steal all encryption assets related to this address.
Abilem's token gift caused a lot of excitement and engulfed many web sites. However, according to the information of blockchain technology data analysis platform Nansen, there are still 428 million ARB tokens that can be claimed. As of the late Thursday, March 22nd, about 240000 addresses had not claimed regulation tokens, although 61 per cent of qualified data encryption wallets had already claimed regulation tokens. By the time of publication, the 428 million unclaimed tokens were worth nearly US $596 million, accounting for 37 per cent of the total amount of 1.1 billion ARB allocated to Arirum airdrop materials.
Taking these numbers into account, some qualified addresses that do not declare their tokens are likely to belong to the type of network hacker address.
This is not the first time the fraudster has leaked the fake address in the login password scenario. In January of this year, MetaMASK warned that the login password user address was poisoned.
Magazines and periodicalsAccount abstraction accessibility Ethernet Square wallet: virtual character Handbook