Highlights
- SlowMist founder Yu Xian says a mass theft event has drained more than 100 addresses belonging to dozens of real users.
- The cause was leaked private keys, and hackers have profited roughly $200,000 so far.
- Every affected user shares one common factor: they had previously used the iToken wallet.
- iToken has a documented history of private key and mnemonic collection tied to a prior incident that led to arrests.
SlowMist founder Yu Xian, widely known in the industry by his handle Cos, disclosed on X on August 31, 2026 that a group theft incident has affected more than 100 wallet addresses belonging to several dozen real users, according to a report from PANews. The root cause was leaked private keys, and the attackers have profited approximately $200,000 from the drained funds. Every victim identified so far shares the same trait: each had, at some point, used the iToken wallet.
A Wallet With a History
Yu Xian's disclosure singles out iToken specifically because the wallet has a documented prior security scandal. A prior security analysis of an earlier incident involving the wallet, then still operating under an older brand, found that a former employee had planted a Trojan designed to collect users' mnemonics and private keys, funneling stolen funds — roughly $260,000 in that case — through intermediary tokens before cashing out via exchanges. That earlier case resulted in an arrest, but Yu Xian's post indicates it did not fully close the exposure: users who set up or restored wallets during the compromised period may still be carrying keys that were captured at the time, meaning funds can be drained long after the original breach was supposedly resolved.
Why Leaked Keys Resurface Years Later
Private key theft is unusual among crypto exploits in that it doesn't require any new action from the attacker once the data is captured — a wallet whose seed phrase was harvested during a compromised app installation remains vulnerable indefinitely, since moving funds into a new wallet is the only real fix and most victims never realize their keys were exposed until funds actually disappear. That mechanic explains why a mass-theft event can surface years after the underlying vulnerability was first identified and supposedly addressed: the stolen keys sit dormant in an attacker's database until it becomes convenient, or lucrative enough, to use them.
Related: More Markets Loses $9.3M in Flow EVM Exploit Tied to Ankr LST
What Affected Users Should Do
Yu Xian's core recommendation, consistent with SlowMist's standard guidance in cases like this, is that anyone who has ever installed or restored a wallet through iToken should treat those keys as compromised and migrate any remaining funds to a newly generated wallet created on a device and app with no history tied to the flagged software. Watching for further disclosures from SlowMist about the scope of affected addresses will be the clearest signal of whether this is an isolated resurfacing or a larger wave still working through the flagged user base.
FAQ
How much has been stolen in this incident?
SlowMist founder Yu Xian estimates hackers have profited roughly $200,000 so far from more than 100 affected addresses.
What do the victims have in common?
Every affected user identified so far had previously used the iToken wallet, which has a documented history of private key and mnemonic collection.
Has iToken been implicated in wallet theft before?
Yes. An earlier incident found a former employee had planted malware to harvest user private keys, funds were traced through intermediary tokens to exchanges, and someone was arrested in connection with it.
What should affected users do?
Treat any keys generated or restored through iToken as compromised and move remaining funds to a newly created wallet on unrelated software.
