{"id":18401,"date":"2026-03-18T02:57:22","date_gmt":"2026-03-18T02:57:22","guid":{"rendered":"https:\/\/cryptoted.net\/index.php\/2026\/03\/18\/china-hacker-group-leaks-7m-crypto-theft-operation-targeting-wallet-supply-chains\/"},"modified":"2026-03-18T02:57:22","modified_gmt":"2026-03-18T02:57:22","slug":"china-hacker-group-leaks-7m-crypto-theft-operation-targeting-wallet-supply-chains","status":"publish","type":"post","link":"https:\/\/cryptoted.net\/index.php\/2026\/03\/18\/china-hacker-group-leaks-7m-crypto-theft-operation-targeting-wallet-supply-chains\/","title":{"rendered":"China hacker group leaks $7M crypto theft operation targeting wallet supply chains\u200b"},"content":{"rendered":"<p> <br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/crypto.news\/app\/uploads\/2025\/04\/crypto-news-DeepSeek-China-and-Russia-AI-partnership-option02.webp\" \/><\/p>\n<div>\n<p class=\"is-style-lead\">A hacker group from China posing as a cybersecurity firm has allegedly stolen 7 million dollars via wallet supply\u2011chain attacks, targeting Trust Wallet and other clients before an internal dispute triggered a whistleblower leak.<\/p>\n<div id=\"cn-block-summary-block_2eac3fdeb2ec4db84b98820baf907f4d\" class=\"cn-block-summary\">\n<p>\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/p>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>Operating under Wuhan Anshun Technology, the group presented itself as a security outfit while allegedly using Electron apps, browser plugins, and remote\u2011control tools to exfiltrate mnemonics and drain wallets across Ethereum, BNB Chain, Arbitrum and more.<a href=\"https:\/\/crypto.news\/wp\/wp-admin\/post-new.php\" target=\"_blank\"\/>\u200b<\/li>\n<li>A disgruntled member claims the crew stole about 7 million dollars across 37 token types, then leaked internal details after a fight over profit splits and unpaid \u201cseverance,\u201d saying they now plan to turn themselves in.<a href=\"https:\/\/crypto.news\/wp\/wp-admin\/post-new.php\" target=\"_blank\"\/>\u200b<\/li>\n<li>Even as authorities stay quiet, the episode echoes recent supply\u2011chain and extension incidents involving Trust Wallet and others, underscoring that every update, plugin, and wrapper around self\u2011custody wallets is part of the real attack surface.<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>A Chinese hacker group posing as a cybersecurity firm has been <a href=\"https:\/\/mp.weixin.qq.com\/s\/hskfopX7w2fjuKcU8a_R_g\" target=\"_blank\" rel=\"nofollow\">exposed<\/a> after an internal dispute led members to leak details of a multimillion\u2011dollar crypto theft operation. According to market reports, the group claims to have stolen around 7 million dollars in digital assets through supply chain attacks, with targets including popular wallet provider Trust Wallet.<a href=\"https:\/\/www.chaincatcher.com\/en\/news\" target=\"_blank\" rel=\"nofollow\"\/>\u200b<\/p>\n<p>Operating under the corporate front Wuhan Anshun Technology, the group presented itself publicly as a security company focused on vulnerability research, network offense-and-defense exercises, and security services. Internally, however, members were allegedly conducting \u201cgray market\u201d activity, systematically stealing mnemonic phrases and raiding user wallets across multiple chains. The whistleblower says the team built automated tooling to bulk-scan mnemonic phrase assets and to identify high\u2011value portfolios across Ethereum, BNB Chain, Arbitrum and other networks.<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.chaincatcher.com\/en\/news\"\/>\u200b<\/p>\n<p>Per the leaked account, the group exploited supply chain vulnerabilities in Electron-based clients and browser plugins, combined with reverse engineering and remote-control programs, to exfiltrate wallet data and drain funds. The operation allegedly touched 37 different token types across several blockchains, with funds laundered via splitting and transfers to obscure the trail. The immediate trigger for the exposure was an internal fight over profit distribution and unpaid \u201cseverance\u201d to one of the operators.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<p>The whistleblower claims they clashed with the team leader over what they saw as unfair profit splits, then decided to publicly dump evidence after promised compensation was not delivered, stating they intend to turn themselves in to law enforcement. So far, the allegations have not been officially confirmed, and authorities have not publicly detailed any investigation progress. Industry commentators note that, confirmed or not, the episode again underscores the <a href=\"https:\/\/crypto.news\/react-bug-triggers-wallet-draining-attacks-as-hackers-hit-crypto-websites\/\">structural attack<\/a> surface in wallet <a href=\"https:\/\/crypto.news\/the-crypto-trust-crisis-nobody-wants-to-admit-opinion\/\">supply chains<\/a>, plugin ecosystems, and desktop clients\u2014especially for high\u2011value users who treat self\u2011custody software as \u201cset and forget.\u201d<a href=\"https:\/\/www.chaincatcher.com\/en\/news\" target=\"_blank\" rel=\"nofollow\"\/>\u200b<\/p>\n<p>For retail and institutional users, the lesson is blunt: security risk is not just in private key handling, but in every update, extension, and client wrapper sitting between you and your keys. In a market where <a href=\"https:\/\/crypto.news\/trust-wallet-extension-exploit-a-possible-insider-job-victims-to-be-compensated\/\">attackers<\/a> are willing to build fake \u201csecurity companies\u201d as covers, rigorous supply\u2011chain auditing, minimal plugin use, and strict device\u2011level hygiene are no longer best practices\u2014they are baseline survival requirements.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/crypto.news\/china-hacker-group-leaks-7m-crypto-theft-operation-targeting-wallet-supply-chains\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A hacker group from China posing as a cybersecurity firm has allegedly stolen 7 million dollars via wallet supply\u2011chain attacks, targeting Trust Wallet and other clients before an internal dispute triggered a whistleblower leak. Summary Operating under Wuhan Anshun Technology, the group presented itself as a security outfit while allegedly using Electron apps, browser plugins, [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":18402,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"tdm_status":"","tdm_grid_status":"","footnotes":""},"categories":[23],"tags":[],"kronos_expire_date":[],"class_list":["post-18401","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto"],"_links":{"self":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts\/18401","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/comments?post=18401"}],"version-history":[{"count":0,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts\/18401\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/media\/18402"}],"wp:attachment":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/media?parent=18401"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/categories?post=18401"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/tags?post=18401"},{"taxonomy":"kronos_expire_date","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/kronos_expire_date?post=18401"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}