$282M Stolen in Crypto Scam via THORChain and XMR Swap

iconCoinomedia
Share
Share IconShare IconShare IconShare IconShare IconShare IconCopy
AI summary iconSummary

expand icon
A crypto scam alert has been issued after $282 million was stolen through a hardware wallet phishing attack. The thief stole BTC and LTC, converted them into XMR, and used THORChain to swap into ETH, XRP, and LTC. The move made tracking harder. The incident shows risks in wallet security and cross-chain laundering. Crypto news reports the theft via Coinomedia.
$282M Lost in Crypto Scam Using THORChain & XMR Swap
  • $282M in BTC and LTC stolen via hardware wallet phishing.
  • Funds were swapped into XMR, ETH, XRP, and LTC.
  • THORChain used to obfuscate and reroute assets.

Massive $282M Scam Exposes Crypto Security Risks

According to blockchain investigator @zachxbt, a devastating $282 million crypto theft has rocked the community. The victim reportedly lost a massive amount of Bitcoin (BTC) and Litecoin (LTC) through a sophisticated social engineering attack tied to a hardware wallet scam.

This incident is one of the largest personal crypto thefts to date, and it raises fresh concerns about wallet safety, phishing tactics, and asset laundering across decentralized networks.

The attacker cleverly avoided detection by moving the stolen funds through privacy-centric and cross-chain platforms — making recovery and traceability difficult.

How the Attacker Laundered the Crypto

After draining the funds, the attacker began converting the assets to avoid tracking. A significant portion of the stolen BTC and LTC was converted into Monero (XMR) — a privacy-focused cryptocurrency. This triggered a sharp spike in XMR’s price, likely due to the large volume of buys.

The laundering didn’t stop there. The attacker leveraged THORChain, a decentralized cross-chain liquidity protocol, to execute the following swaps:

  • 818 BTC (~$78 million) converted into:
    • 19,631 ETH (~$64.5 million)
    • 3.15 million XRP (~$6.5 million)
    • 77,285 LTC (~$5.8 million)

By using THORChain, which allows asset swaps without centralized exchanges, the attacker avoided traditional Know-Your-Customer (KYC) processes and increased the complexity of tracing the funds.

According to @zachxbt, a victim lost over $282M worth of $LTC and $BTC in a hardware-wallet social engineering scam.

The attacker swapped part of the $LTC and $BTC into $XMR, triggering a sharp spike in $XMR's price.

The attacker also used #THORChain to swap 818 $BTC($78M) into… pic.twitter.com/7PExjntkbT

— Lookonchain (@lookonchain) January 17, 2026

Security Takeaways for Crypto Holders

This incident highlights a chilling truth: even hardware wallets are not foolproof if users fall for phishing or social engineering attacks.

Key takeaways include:

  • Never share seed phrases or recovery information, even with “support staff.”
  • Double-check domain names and verify sources before interacting.
  • Enable passphrases and secure backups for added protection.
  • Be cautious of unsolicited wallet firmware updates or requests.

As attackers become more sophisticated, the community must stay vigilant. This case also demonstrates how privacy coins and decentralized swapping protocols can be double-edged swords — empowering users, but also shielding bad actors.

Read Also:

The post $282M Lost in Crypto Scam Using THORChain & XMR Swap appeared first on CoinoMedia.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.