Overview
- The theft occurred on Oct. 12 and was discovered on Oct. 15 after two 10-XRP test pulls were followed by a sweep of roughly 1.2 million XRP to new addresses.
- Ellipal says the loss stemmed from importing the hardware wallet’s seed into its mobile app, which stored keys on an internet-connected device and removed cold-storage protection.
- Investigator ZachXBT reports the attacker executed 120+ Ripple-to-Tron swaps via Bridgers, consolidated funds on Tron, and then routed them to OTC venues linked to Huione.
- The U.S. Treasury designated Huione a primary money-laundering concern on Oct. 14, providing regulatory context for the traced endpoints.
- The victim filed an IC3 report and contacted local police, but experts say recovery is unlikely and warn that many private 'recovery' firms are predatory; users are urged to keep seeds offline and segregate hot and cold wallets.