Hacker steals $950,000 from crypto vanity address as exploits continue

Partner offers
The Block may may earn a commission if you use our partner offers, at no extra cost to you.

Quick Take

  • Hackers are continuing to steal cryptocurrency through an exploit linked to vanity addresses created by a tool called Profanity.
  • The latest hack comes after Wintermute lost $160 million as a result of this issue.
 
 

A hacker has stolen $950,000 in ether from a crypto wallet via the same vanity address exploit linked to an attack on trading firm Wintermute last week.

The hacker stole 732 ETH on Sept. 25 and sent it directly to the sanctioned cryptocurrency mixing service Tornado Cash, according to PeckShield citing on-chain data. Here it will have been mixed with other cryptocurrency and withdrawn to the hacker’s own wallet.

The exploit was made possible due to the recent vanity address weakness that was picked up on GitHub in January but only made widely known by DEX aggregator 1inch on Sept. 15. A vanity address is a cryptocurrency address designed in a certain way, often to feature a pattern or word in the address, similar to a custom license plate on a car. 

Many vanity addresses were created through a tool called Profanity. Yet 1inch highlighted that its method of creating such addresses made them easier to breach through a brute force attack. While this would require a lot of computing power, it might be offset by the amount of cryptocurrency in the wallet.

A number of smaller hacks have taken place so far. Earlier this month, $3.3 million was drained from multiple Ethereum addresses that had used Profanity.

On Sept. 20, crypto market making firm Wintermute said it had been hacked for $160 million — later acknowledging it was likely due to this exact issue.

 

Disclaimer: Evgeny Gaevoy, the founder and CEO of Wintermute, previously sat on The Block’s board of directors from April 2023 to early November 2023 and remains a minority shareholder.

© 2025 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

AUTHOR

Tim Copeland is the Head of Growth at The Block and host of The Crypto Beat, a live-streaming podcast. He was previously the company's Editor-in-Chief and spent seven years covering the industry as a journalist. Prior to joining The Block, Tim was a news editor at Decrypt. He earned a bachelor's degree in philosophy from the University of York and studied news journalism at Press Association Training. Follow him on X @Timccopeland.

See More
Connect on

WHO WE ARE

The Block is a news provider that strives to be the first and final word on digital assets news, research, and data.

+ Follow us on Google News
Connect with the block on

More by Tim Copeland