Close Menu
Crypto Chain Post
    Trending

    Canada’s Belgravia Hartford Pulls Another $1M to Stack Bitcoin Treasury 

    June 27, 2025

    Vitalik Drops Two Trillion in Meme Tokens: ETH Market Reacts Instantly

    June 27, 2025

    HashKey’s HSK Soars 90% This Week as Mainland China Brokers Eye Crypto

    June 27, 2025

    Will XRP Shake Off Its Current Price Pattern?

    June 27, 2025

    Ripple to Drop Appeal in SEC Case Over XRP Sales, Ending Case ‘Once and for All’

    June 27, 2025
    Facebook X (Twitter) Instagram TikTok Telegram
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    Friday, June 27
    Crypto Chain Post
    Price Index Newsletter
    • Home
    • News
      • Bitcoin
      • Ethereum
      • Altcoin
    • Blockchain
    • Markets
    • NFTs
    • DeFi
    • Web3
    • Analysis
    • Metaverse
    • Resources
      • Price Index
      • Crypto Heatmap
      • Glossary
      • Exchange
      • Economic Calendar
    • More
      • GameFi
      • ICO
      • Legal
      • Security
    Crypto Chain Post
    Home » Pepe meme creator’s NFT projects hit for $1 million as contract hijackers drain collections
    Ethereum

    Pepe meme creator’s NFT projects hit for $1 million as contract hijackers drain collections

    News RoomBy News RoomJune 27, 2025No Comments3 Mins Read
    Nemo

    Projects tied to Pepe meme creator Matt Furie and the NFT studio ChainSaw lost roughly $1 million to contract takeover exploits last week, according to on-chain investigator ZachXBT.

    On June 27, ZachXBT reported transaction records showing that the attacker seized control of the “Replicandy” contract at 4:25 a.m. UTC on June 18 by transferring ownership to the externally owned address 0x9Fca. 

    Two hours later, the new owner withdrew mint proceeds and, at 5:11 a.m. the next day, reopened the mint, issued fresh NFTs, and dumped them into open bids, pushing the floor price to zero.

    On June 23, the same address took over three additional ChainSaw contracts: Peplicator, Hedz, and Zogz. The bad actor then repeated the mint-and-dump cycle. 

    ZachXBT estimated the combined theft at more than $310,000 and linked the funds to three collector addresses: 0xf6a9, 0x7e58, and 0x58f4. He traced a 2.05 ETH payment from 0x9Fca to an exchange deposit that converted to 5,007.91 USDT and was then moved to MEXC. 

    He subsequently mapped many smaller monthly deposits from unrelated projects into the same exchange wallet.

    Two GitHub accounts, “devmad119” and “sujitb2114,” list wallets that intersect the stolen fund trail. 

    Both accounts share indicators that ZachXBT associated with North Korean IT workers, including Korean language system settings, Astral VPN sessions, and Asia-Russia time zones, despite résumés that claim US residency.

    Favrr exploit follows the same payroll path

    A second incident surfaced on June 25, when the freelance services token project Favrr lost more than $680,000 following its listing on a DEX. On-chain analysis linked the exploit to the consolidation wallet 0x477, which received recurring payments from Favrr payroll addresses 0x1708 and 0x6412. 

    Gate.io deposit address 0xab7 received part of the stolen Favrr tokens, and was previously funded by the suspected developer behind “sujitb2114”.

    Favrr announced that it would refund all initial decentralized offering participants, cancel its MEXC listing, and initiate a thorough audit of its codebase. The project added that it will publish a new launch timeline “in the coming weeks” and advised users to avoid trading impostor tokens in the interim.

    ZachXBT reported that Favrr’s chief technology officer, listed as Alex Hong, deleted his LinkedIn profile after the exploit. Attempts to verify his work history with previous employers were unsuccessful.

    The investigator plans to release aggregate data on payroll flows to wallets tied to the same North Korean cluster, contending that basic due diligence checks would have flagged the hires.

    The stolen funds from the ChainSaw collections remain idle, while most Favrr proceeds have already passed through Gate.io and several nested services. 

    ZachXBT said he has not reached the teams because their direct message channels are closed, and official Telegram or Discord rooms do not provide contact options.

    The incidents bring renewed attention to the risks of “shadow hiring” in crypto projects that outsource development through gig-work platforms. 

    Investigators continue to follow the on-chain trails, and affected communities await formal statements from Furie, ChainSaw, and Favrr.

    Mentioned in this article

    Read the full article here

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related News

    Is ETH Staging a Push Toward $2.8K or Facing a Crash to $2K?

    June 27, 2025

    FATF sounds alarm over rising stablecoin misuse as global crypto rules lag

    June 27, 2025

    ‘The Signal We’ve Been Waiting For’: Analytics Firm Says Bitcoin Laying the Groundwork for the Next Leg Up

    June 27, 2025

    Ethereum Network Fee Skyrockets 130%, What’s Behind It?

    June 27, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top News

    Vitalik Drops Two Trillion in Meme Tokens: ETH Market Reacts Instantly

    June 27, 2025

    HashKey’s HSK Soars 90% This Week as Mainland China Brokers Eye Crypto

    June 27, 2025

    Will XRP Shake Off Its Current Price Pattern?

    June 27, 2025
    Advertisement
    Demo
    Crypto Chain Post
    • Home
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2025 Crypto Chain Post. All Rights Reserved.

    71-75 Shelton Street, Covent Garden, London United Kingdom, WC2H 9JQ

    Type above and press Enter to search. Press Esc to cancel.