Wintermute hack — September 2022
Incident facts
| Date of incident | |
|---|---|
| Target type | Other |
| Loss | $160,000,000Price at time of incident |
| Method | Private key compromiseprivate key of a Profanity-generated vanity admin address recovered by brute force against a 32-bit RNG seed |
| Chains | Ethereum |
| Outcome | Unresolved |
What happened
Wintermute, a London-based algorithmic market maker, disclosed on 20 September 2022 that its decentralised finance operation had been drained. Founder and chief executive Evgeny Gaevoy said the firm had 'been hacked for about $160M in our defi operations' and that 'cefi and OTC operations are not affected'. He said Wintermute remained solvent with roughly twice the stolen amount left in equity, and separately put remaining equity at more than $350 million.
The vault was controlled by an administrator address beginning 0x0000000, a vanity address generated with the open-source tool Profanity. Wintermute used such addresses to cut gas costs on high-frequency transactions. Profanity seeded its random number generator with a 32-bit value, which made the set of possible private keys behind any Profanity address small enough to search exhaustively with enough GPU time. 1inch had published a disclosure of the flaw five days earlier, on 15 September. Gaevoy said the firm had begun retiring its Profanity addresses but had missed one of ten, which he described as the firm's own human error.
Reported composition of the loss was roughly $120 million in USDC and USDT, about $20 million in bitcoin and ether, and about $20 million in smaller tokens. The link to Profanity came from outside analysts, among them Polygon's Mudit Gupta and the security firm SlowMist, rather than from Wintermute.
Wintermute offered a 10 per cent bounty for return of the remainder and asked the attacker to make contact. Nothing was returned. About $114 million of the stablecoins was instead deposited into Curve's 3pool, commingling it with other liquidity; by April 2023 that position was still the pool's largest, at 28 per cent of $409 million.
Sources
- 1inch NetworkPrimary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- ForbesSecondary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- DL NewsSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Wintermute hack — September 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/wintermutehttps://itokenly.com/hacks/wintermutePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.