Last night, the GUA crypto project suffered a significant security breach that resulted in the theft of 14.98 million GUA tokens, which were valued at around $15.2 million at the time of the incident.

The hacker dumped the entire 15 million GUA tokens instantly on-chain, causing a sharp and sudden plunge in its market value. They then swapped the stolen tokens for 2,784 Ethereum and stored them in three different wallets.

The hacker executed this operation by exploiting a software vulnerability in the UI Tampering to modify the smart contract content, along with leveraging human error based on quick visual inspection.

The hacker used advanced computers to generate millions of random addresses until he found a wallet address that matched the first four and last four characters of the legitimate Airdrop contract address.

He successfully deceived the auditors by having the rest of the team members responsible for signing only visually inspect the first and last characters of the address before approving the transaction.

Once the required signatures from partners were completed, the transaction was broadcasted on the blockchain, automatically and irreversibly sending the funds to the hacker instead of the legitimate Airdrop contract.

The team behind the SUPERFORTUNE AI project (developer of GUA coin) announced that preliminary investigations indicate manipulation or a breach in the wallet address during the execution of a multi-signature transaction.

The GUA coin project operates as a "Smart Fortune Telling" platform dedicated to the crypto market. It employs Eastern metaphysical systems like astrology and Chinese fortune-telling "Ba Zi" along with the five elements (Wu Xing) to analyze the energy of digital wallets and predict market trends.

Target legal address (Airdrop contract):

0x70ae7D3DECfB4C3aE996fb1c07092566F73D5c15

Initial wallet address of the hacker that received the tokens:

0x70AE678b457C5E1b3fD7AD9537F234dFc1795C-2515

#HackerNews