$4.8M in crypto stolen after Korean tax agency exposes wallet seed
好的,我现在需要帮用户总结这篇文章的内容。用户的要求是用中文,控制在100个字以内,不需要特定的开头,直接写描述。 首先,我通读文章,了解主要内容。文章讲的是韩国国家税务局在执法行动中没收了价值81亿韩元的加密资产,并展示了一个Ledger冷钱包的照片。然而,他们不小心公开了钱包的助记词恢复短语,导致440万美元的加密货币被盗。 接下来,我需要提取关键信息:韩国税务局、没收加密资产、公开助记词、资金被盗、损失金额等。 然后,我要把这些信息浓缩到100字以内。要注意用简洁的语言表达清楚事件的过程和结果。 最后,检查是否有遗漏的重要细节,并确保语言流畅自然。 </think> 韩国国家税务局在执法行动中没收了价值8.1亿韩元的加密资产,并展示了一个Ledger冷钱包的照片。然而,他们不小心公开了钱包的助记词恢复短语,导致440万美元的加密货币被盗。 2026-2-28 15:30:34 Author: www.bleepingcomputer.com(查看原文) 阅读量:1 收藏

$4.8M in crypto stolen after Korean tax agency exposes wallet seed

Someone jumped at the opportunity to steal $4.4 million in crypto assets after South Korea’s National Tax Service exposed publicly the mnemonic recovery phrase of a seized cryptocurrency wallet.

The funds were stored in a Ledger cold wallet seized in law enforcement raids at 124 high-value tax evaders that resulted in confiscating digital assets worth 8.1 billion won (currently approximately $5.6 million).

When announcing the success of the operation, the agency released photos of a Ledger device, a popular hardware wallet for crypto storage and management. 

Wiz

However, the images also showed a handwritten note of the wallet recovery phrase, which serves as the master key that allows restoring the assets to another device.

Images released by the South Korean tax authority
Images released by the South Korean tax authority
Source: mk.co.kr

The authorities failed to redact that info, allowing anyone to transfer into their account the assets in the cold wallet.

Reportedly, shortly after the press release was published, 4 million Pre-Retogeum (PRTG) tokens, worth approximately $4.8 million at the time, were transferred out of the confiscated wallet to a new address.

“On-chain data (Etherscan) analysis shows that the attacker first deposited a small amount of Ethereum (ETH) into the wallet to pay transaction fees (gas fees), and then meticulously transferred the 4 million PRTG tokens to their own wallet in three separate transactions,” reports Korean media.

Blockchain data analysis expert Cho Jae-woo, a professor at Hansung University in Seoul who observed the transfer, commented on the authorities’ blunder by comparing it to leaving a wallet open and advertising it to the entire nation for people to take the money.

The professor attributed the mistake to the tax authorities’ “lack of basic understanding of virtual assets,” which effectively cost the national treasury tens of billions of won that had been successfully confiscated.

The press release has now been removed from the NTS website, and it is unclear if authorities started an investigation to determine where the stolen funds ended.

The case is a reminder for hardware wallet owners that their seed phrase gives complete access to their wallet without any additional protections. Anyone who has it can recreate the wallet anywhere without their device, PIN, or permission.

It is recommended to avoid digitizing seed phrases, store them in electronic notes, photos, in email messages, cloud storage, or send them over messaging apps. If a seed is exposed, all funds should be moved to a new wallet as soon as possible.

tines

The future of IT infrastructure is here

Modern IT infrastructure moves faster than manual workflows can handle.

In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.


文章来源: https://www.bleepingcomputer.com/news/security/48m-in-crypto-stolen-after-korean-tax-agency-exposes-wallet-seed/
如有侵权请联系:admin#unsafe.sh