TechFlow, Dec 5 — According to a post by SlowMist's Yu Xian (@evilcos), user Babur suffered a theft of approximately $27 million in crypto assets.
Analysis shows the stolen assets mainly involved two addresses: Solana address 91xu and Ethereum Safe multisig address 0xD2. The two largest stolen amounts totaled over $18 million. The hacker's addresses are 71fM (Solana) and 0x4f (Ethereum), with部分 funds already bridged to the Ethereum network.
According to Yu Xian's analysis, the incident appears to have been caused by malware infection. After the user double-clicked and executed a malicious file, private keys were leaked. Both signing private keys for the Safe multisig may have been stored on the infected computer.




