Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert & block trade
Convert crypto with one click and zero fees
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Hackers steal $3.05m XRP from cold wallet, ZachXBT traces funds

Hackers steal $3.05m XRP from cold wallet, ZachXBT traces funds

Crypto.NewsCrypto.News2025/10/19 16:00
By:By David MarsanicEdited by Jayson Derrick

Crypto investigator ZachXBT traced the funds of a victim who lost their life savings of $3.05 million in XRP.

Summary
  • A victim lost their life savings of $3.05M worth of XRP from an Ellipal cold wallet
  • The hack happened after the victim imported their seed phrase into Ellipal’s mobile app
  • ZachXBT traced the funds to a Southeast Asian laundering ring

Self-custody is a powerful tool for security, but only if users know what they are doing. On Sunday, Oct. 19, crypto investigator ZachXBT revealed a case of a victim losing $3.05 million in XRP from a cold wallet. The investigator ultimately traced the funds to a Southeast Asian crypto laundering ring.

The initial theft happened on Oct. 12, when attackers drained the victim’s (XRP) wallet. The victim used an Ellipal hardware wallet, which markets itself as a cold wallet. However, the victim made the mistake of importing their seed phrase into the Ellipal mobile app.

This effectively made it into a hot wallet, meaning it became connected to the internet. ZachXBT explained that importing a seed phrase into a mobile app completely defeats the purpose of cold storage and exposes users to hacks.

How hackers laundered $3.05 in XRP

Following the breach, hackers used the cross-chain bridge Bridgers to swap the XRP into Tron (TRX) in over 120 transactions. The transactions appeared to go to Binance, but this was actually part of Bridgers’ liquidity path.

After the laundering steps, the attackers moved all tokens into a single Tron wallet, making it easier to move the funds off-chain. For that purpose, they used OTC desks adjacent to Huione, a Southeast Asia–based illicit online marketplace.

According to ZachXBT, Huione has connections to hacks, pig-butchering scams, money laundering, and more. The exchange has also been sanctioned by the U.S. government for facilitating massive illicit crypto flows.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Algo +1.57% Propelled by Robust 7-Day Surge

- Algo (ALGO) rose 1.57% in 24 hours on Nov 9, 2025, with a 17.27% surge over seven days. - The 7-day rally signals short-term bullish momentum, though a 46.01% annual decline remains unresolved. - Technical indicators like RSI and MACD suggest continued upward trends, but analysts caution against long-term optimism. - Traders are advised to monitor volume and market conditions amid ALGO's distinct performance versus broader crypto trends.

Bitget-RWA2025/11/09 14:44

YFI has surged by 13.08% over the past week as it experiences a robust short-term upward trend

- Yearn.finance's YFI token rose 0.47% in 24 hours, marking a 13.08% surge over seven days despite a 38.81% annual decline. - Analysts attribute the rally to accumulated buying pressure or improved trader sentiment, typical of DeFi's short-term volatility patterns. - Technical indicators suggest potential corrections post-rally, while backtesting historical 13.08% gains could reveal sustainability of the recent momentum.

Bitget-RWA2025/11/09 14:44

AAVE Rises 8.63% Over the Past Week: DeFi Buyback Momentum and Treasury Advancements

- Aave's $50M annual buyback program shifts DeFi tokenomics toward deflation, redirecting protocol earnings to reduce $AAVE supply. - The 7-day 8.63% price surge reflects growing adoption of buyback strategies by DeFi platforms like EtherFi and Maple Finance. - BTCS Inc. leverages Aave's 24/7 automated lending to cut borrowing costs by 5-6% while expanding Ethereum holdings through DAT strategy. - Analysts predict deflationary models will enhance price resilience, with metrics like protocol revenue replaci

Bitget-RWA2025/11/09 14:10