The post Jill Gunter has wallet drained via vulnerable ThirdWeb contract appeared on BitcoinEthereumNews.com. On Thursday, Jill Gunter, co-founder of “the base The post Jill Gunter has wallet drained via vulnerable ThirdWeb contract appeared on BitcoinEthereumNews.com. On Thursday, Jill Gunter, co-founder of “the base

Jill Gunter has wallet drained via vulnerable ThirdWeb contract

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

On Thursday, Jill Gunter, co-founder of “the base layer for rollups” Espresso, took to X to inform followers her wallet had been drained due to a vulnerability in a ThirdWeb contract.

The 10-year crypto veteran noted the “deep irony” of her funds being funneled into privacy protocol Railgun while she was “writing a defense of privacy in crypto to present in DC next week.”

In a follow-up thread, Gunter describes the process of investigating how over $30,000 USDC was lost.

Read more: ZachXBT cracks Railgun privacy to expose Bittensor hacker

The transaction, which drained Gunter’s jrg.eth address, occurred on December 9. 

The tokens had been moved into the address the day before the theft “in anticipation of funding an angel investment I planned to make this week.”

Although the tokens had been moved from jrg.eth to another (0xF215), the transaction shows a contract interaction with 0x81d5.

This vulnerable contract that led to the drained wallet, Gunter found, was a Thirdweb bridge contract that she had previously used for “a $5 transfer.”

After contacting Thirdweb, she was informed that a vulnerability was found in the bridge contract in April. It “allowed anyone to access funds from users who had clicked through and accepted unlimited token approvals.”

Indeed, the contract is now labelled on Etherscan as compromised.

Read more: Explained: how crypto’s ‘largest supply chain attack’ stole just $0.05

A Thirdweb blog post, published today, states that the theft “resulted from the legacy contract not being properly decommissioned during our April 2025 vulnerability response.”

Thirdweb “permanently disabled the legacy contract… and no user wallets or funds remain at risk.”

Gunter praised the SEAL Security Alliance for its response, pledging to donate any potential reimbursement, and urged others to do the same.

Thirdweb’s second rodeo

In addition to the vulnerable bridge contract, ThirdWeb had previously disclosed a wide-reaching vulnerability in late 2023.

It informed the crypto community of “a security vulnerability in a commonly used open-source library.”

Security researcher and SEAL member Pascal Caversaccio dubbed Thirdweb’s statement “not responsible disclosure.” He argued that providing a list of vulnerable contracts gave black hats hackers a “head start.”

According to crypto scam tracker ScamSniffer’s analysis, over 500 token contracts were affected and at least 25 exploited.

Got a tip? Send us an email securely via Protos Leaks. For more informed news, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.

Source: https://protos.com/jill-gunter-has-wallet-drained-via-vulnerable-thirdweb-contract/

Market Opportunity
Ambire Wallet Logo
Ambire Wallet Price(WALLET)
$0.00997
$0.00997$0.00997
-0.49%
USD
Ambire Wallet (WALLET) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

UK crypto holders brace for FCA’s expanded regulatory reach

UK crypto holders brace for FCA’s expanded regulatory reach

The post UK crypto holders brace for FCA’s expanded regulatory reach appeared on BitcoinEthereumNews.com. British crypto holders may soon face a very different landscape as the Financial Conduct Authority (FCA) moves to expand its regulatory reach in the industry. A new consultation paper outlines how the watchdog intends to apply its rulebook to crypto firms, shaping everything from asset safeguarding to trading platform operation. According to the financial regulator, these proposals would translate into clearer protections for retail investors and stricter oversight of crypto firms. UK FCA plans Until now, UK crypto users mostly encountered the FCA through rules on promotions and anti-money laundering checks. The consultation paper goes much further. It proposes direct oversight of stablecoin issuers, custodians, and crypto-asset trading platforms (CATPs). For investors, that means the wallets, exchanges, and coins they rely on could soon be subject to the same governance and resilience standards as traditional financial institutions. The regulator has also clarified that firms need official authorization before serving customers. This condition should, in theory, reduce the risk of sudden platform failures or unclear accountability. David Geale, the FCA’s executive director of payments and digital finance, said the proposals are designed to strike a balance between innovation and protection. He explained: “We want to develop a sustainable and competitive crypto sector – balancing innovation, market integrity and trust.” Geale noted that while the rules will not eliminate investment risks, they will create consistent standards, helping consumers understand what to expect from registered firms. Why does this matter for crypto holders? The UK regulatory framework shift would provide safer custody of assets, better disclosure of risks, and clearer recourse if something goes wrong. However, the regulator was also frank in its submission, arguing that no rulebook can eliminate the volatility or inherent risks of holding digital assets. Instead, the focus is on ensuring that when consumers choose to invest, they do…
Share
BitcoinEthereumNews2025/09/17 23:52
Ukrainian Drone Strikes Hit Moscow, St. Petersburg And Russia’s Economy

Ukrainian Drone Strikes Hit Moscow, St. Petersburg And Russia’s Economy

The post Ukrainian Drone Strikes Hit Moscow, St. Petersburg And Russia’s Economy appeared on BitcoinEthereumNews.com. In Kyiv, Ukraine, on December 6, 2024, President of Ukraine Volodymyr Zelenskyy, Commander-in-Chief of the Armed Forces of Ukraine Oleksandr Syrskyi, and Deputy Minister of Strategic Industries of Ukraine Anna Gvozdiar (L to R) attend the handover of the first batch of long-range Peklo (Hell) missile drones to the Defence Forces on the Day of the Armed Forces of Ukraine. Ukraine’s President Volodymyr Zelensky conveys the first batch of advanced Peklo missile drones to the military. During the event, it is reported that there have already been five successful uses. The Peklo missile drone, which has a strike range of 700 km and a speed of 700 km per hour, is launched into serial production. NO USE RUSSIA. NO USE BELARUS. (Photo by Ukrinform/NurPhoto via Getty Images) NurPhoto via Getty Images Kyiv is intensifying its air campaign, aiming not only to destroy Russian oil refineries but also to expose the vulnerabilities of the country’s elites. On September 9, a Ukrainian drone targeted Sochi on the Black Sea, just hours after President Vladimir Putin held meetings there. On September 12, a Ukrainian drone struck Russia’s Leningrad region for the first time, hitting the Primorsk oil terminal near St. Petersburg and forcing a temporary suspension at the country’s largest crude port. The drone threat also shut down St. Petersburg’s Pulkovo Airport. Ukraine’s drone offensive is showing results, intensifying pressure on the Kremlin as strikes deepen Russia’s fuel crisis and accelerate inflation. According to September data from the independent pollster Levada Center, a record 66% of respondents in Russia now say it is time to move toward peace negotiations, while just 27% support continuing military action – the lowest level ever recorded. In June, 58% also cited rising prices as their top concern. While public frustration with the war is rising, elites in…
Share
BitcoinEthereumNews2025/09/18 06:11
Metaplanet raises $1.4B to fuel BTC purchases and U.S. subsidiary launch

Metaplanet raises $1.4B to fuel BTC purchases and U.S. subsidiary launch

Metaplanet Inc. has formalized the subsidiary in Miami, Florida, naming it Metaplanet Income Corp.
Share
Cryptopolitan2025/09/17 23:34