A crypto investor lost RMB 50 million after buying a “backdoor cold wallet” on Douyin

👤 transfer-top@Igor 📅 2026-04-04 14:59:18

The "cold wallet" purchased by a crypto investor through Douyin had a pre-embedded backdoor, and 50 million yuan in assets were stolen instantly. SlowMist Information Security Chang 23pds repeatedly reminded: Only official purchase and self-initialization can minimize the risk.
(Preliminary information: Attention cold wallet users! The ESP32 chip has a vulnerability that can steal Bitcoin private keys. How to check whether the device is risky?)
(Background supplement: New regulations of the Financial Supervisory Commission: 70~80% of Taiwan VASP customer assets must be stored in cold wallets)

Heartbreaking! Cryptocurrency worth 50 million yuan disappeared from the cold wallet overnight. According to a post on X by SlowMist Information Security Manager 23pds on the 6th, a crypto investor came to him for help, saying that he purchased an uncertified hardware wallet through Douyin, and his assets were devoured by a wallet that was "tampered with before leaving the factory."

The police have not disclosed the details yet, but they have re-awakened investors in the currency circle that the cold wallet purchase method is very important!

⚠️Attention! Someone asked for urgent help in the middle of last night
Nearly 50 million in assets disappeared overnight, all because of buying a "cold wallet" on Douyin! 💥
🚨 Remember:
Purchasing cold wallets must go through official formal channels!
99% of the so-called "new and unopened" and "special price flash sale" cold wallets on the Internet are fake and may have been manipulated!

Don’t gamble your entire fortune on a “wallet” that’s hundreds of dollars cheaper—this is not saving, it’s costing your life! 💸… https://t.co/785t52A0SE

— 23pds (山哥) (@im23pds) June 14, 2025

Be careful when purchasing cold wallets online

Unofficial channel sellers There are three common hidden traps in hardware wallets for sale: first, the device is physically unpacked, allowing attackers to preload malicious firmware; second, the recovery seed phrase is transcribed in advance, and once the buyer activates it, it is equivalent to handing over the private key; third, the lack of original firmware updates allows hackers to penetrate known vulnerabilities.

23pds Warning:

"99% of the so-called "new and unopened" and "special price flash sale" cold wallets on the Internet are fake and may have been manipulated."

Even if the device is intact, if the user accidentally leaks the seed phrase, the assets will also evaporate. Offline storage can isolate cyber attacks, but it cannot prevent physical theft and social engineering.

Official purchase and initialization by yourself are the bottom line

Dongzhi recommends that you only purchase from official websites or authorized channels of brands such as Ledger, Trezor, CoolWallet, etc., and immediately initialize and upgrade the firmware by yourself after receiving it to ensure that the private key is generated locally. Official channels can also enjoy warranty and updates, reducing the risk of software and hardware being "abandoned".

Safety habits are equally important: avoid buying second-hand wallets; handwrite seed phrases offline and store them in two or more safe locations; check firmware versions regularly; spread large assets across multiple wallets. Although these basic actions are not enough to guarantee absolute safety, they at least prevent the attacker from winning at the starting point.

Although it is less popular for Taiwanese users to use Taobao and Douyin e-commerce to purchase cold wallets, Taiwan is still a common shopping website selling "second-hand unopened", "30% off the original price" and "limited time flash sale" hardware wallets. Compared with the official price, it is only a few hundred yuan cheaper, but it may result in the loss of all your wealth. You should be careful before buying.

Этикетка:
делиться:
FB X YT IG
transfer-top@Igor

transfer-top@Igor

Редактор блокчейна и криптоактивов, специализирующийся наполитикаАнализ и аналитика контента домена

Комментарий (10)

파멜라 76дней назад
미래는 신뢰할 수 있는 네트워크의 시대입니다.
메건 76дней назад
킬러 애플리케이션이 없다는 점은 업계에서 가장 큰 난처함입니다.
아이리스 76дней назад
진정한 탈중앙화는 결코 달성될 수 없습니다.
엷은 갈색 76дней назад
미래의 이야기는 여전히 존재하지만 구현이 더 중요합니다.
알리스테어 76дней назад
현재 산업 인프라 경쟁이 치열하다.
마커스 76дней назад
기술 구현이 미래를 결정한다는 데 동의합니다.
걸어 건너기 80дней назад
현재 블록체인은 주류 비전을 향해 나아가고 있습니다.
프랜시스 83дней назад
크로스체인 기술의 이 부분은 특히 잘 작성되었습니다.
조앤 89дней назад
현재 산업 경쟁은 생태적 경쟁으로 바뀌었습니다.
파라 93дней назад
Web3의 비전에는 이러한 견고한 구성이 필요합니다.

Добавить комментарий

Популярный контент