Author: zachxbt, On-chain Detective
Original Translation: zhouzhou, BlockBeats
Editor’s Note: This article analyzes how the hacker Serpent controlled 9 accounts, including McDonald's, Kabosu, and others, on X and Instagram, launching a meme coin scam that stole approximately $3.5 million, which was then used for gambling at casinos. Serpent was a professional player in "Fortnite" but was terminated for cheating. In 2022, the NFT project DAPE, which he co-founded, experienced a rug pull, and the ERROR project launched in 2024 also faced a rug pull, ultimately leading to his ban on X.
The following is the original content (reorganized for readability):
Over the past few months, I have been tracking a series of related leak events involving McDonald's, Usher, Kabosu's owner, Andy Ayrey, Wiz Khalifa, SPX 6900, and others, which resulted in approximately $3.5 million being stolen through the release of Pump Funmeme coins.
On August 21, 2024, McDonald's Instagram account was hacked, and a post promoting the bundled meme coin GRIMACE was published, after which the hacker began to prank. From this pump and dump, over $690,000 was funneled into two wallets.
4RiNhTwBxYWgb4MSCtt9vXgVk2yuPhoQR3DR9pMVPU1W
2vjnmxwTYNJvTmFhtqxZkPiuCHkaKZK5rcxTLuoC2dPB
On September 3, 2024, the McDonald's attacker transferred 101.5 SOL to two addresses, which were deployed and targeted SCHRADER after actor Dean Norris's X account was hacked.
4s9Uz9pTBXcEaEtcjs8eg98r2TVte3rq3JUm3rVTFMudfewGbNKmqNyYs9bSAMDUaTbTcuA1v39sWr7GRqkDJ6EM
1gxo1pjTqjbee7rHW4cGvuNffX1qP4F8fP17g6SSC5EYbQrnktDrKSFB1uh4ju7PxQjprWFin37WUsAe225b9c6
On September 6, 2024, the funds obtained from the McDonald's APT (Account Takeover) were transferred to a casino deposit address.
CuNzegC9DE4CxCMn31ZcYLvtDaYsLD9RX8eRvmtZQrnB
By conducting a time analysis, subsequent withdrawals shortly after the deposit can be identified.
B2fwZt5nTbdrnJ2CPsgrYMPuB4UnhN82EAM34dXDARLh
On September 12, 2024, B2fw transferred 110 SOL to two addresses that participated in the meme coin rush promoted during the Usher leak event.
4FUrwoHz1fuUf4eR6YEAYSG9d9rN5fzbowMXtbjwJAhTDtHXjpnTb1sz6aeF6T79JaiMFyT2xX2EuTxqT5UhFfKD
427zpHF1WWgYgKxcSiUzwXLg2UqsF6xq7K13PU3mh6Wr99mipiVA6GcDTwi7EY93RJeRuEUDZAK9BnoMeki7sU6C
Subsequently, B2fw transferred 4868 SOL to the casino deposit address ECb5v, which is also directly related to other APT (Account Takeover) events, including the leaks of Andy Ayrey and Enoshima Aquarium.
Ecb5vsomUG3MEnLCgiFvkdnnqpggTEXtN17z62iDPuU3
On October 15, 2024, the X account of Enoshima Aquarium was hacked and promoted a bundled meme coin. On the same day, 84 SOL obtained from the scam was transferred to ECb5v.
5PDjh74JTLMPW4dXr6fKm3Yue2j3vhbxLSK5dPbQ3oEGK4axE7fua1ngBMas4xpRY6dBr92Ccps7b1WwcLdnxXWL
On October 29, 2024, Andy Ayrey (founder of Truth Terminal) had his X account hacked, which lasted for several days and promoted 6 meme coin scams. 3GVUs was one of the addresses involved in the token rush.
3GVUs2gNr161ohqnVXjUeoNQmf3cELxKSiPrxyQu6pjd
On October 30, 2024, 3GVUs transferred 169 SOL to Ecb5vs.
67nwsLLE3aGua4VeH8p6qHc3SL3rpxi9omMxRnfpeyZVsBpZawnUHo4Pt4tdT5Vxny2uRNRDH3vSZ1fzvKkNCML4
From the $2.178 million obtained from the Andy Ayrey ATO, $750,000 was deposited into the casino deposit address Apc3e.
Apc3eA9ScQksuZvfURQswZwVkusEYRaqeKEv4eXXbRZm
The 0.1 SOL from the Kabosu ATO funded an address that participated in the Andy Ayrey ATO.
On October 17, 2024, Kabosu's owner's Instagram account was hacked and promoted a meme coin scam.
On the same day, 191 SOL obtained from the scam was transferred to the casino deposit address:
6kwZ7tz8Xs7jaVqVJXZSRrZ2FtS2PPChEVuLXKrmMgCm
The APT (Account Takeover) events of Kabosu and Andy Ayrey are directly related to the APT event of Wiz Khalifa.
On November 3, 2023, the attacker posted a wallet address on Wiz Khalifa's account. 29 SOL was transferred to 6kwZ7, just as it happened in the Kabosu ATO.
NFCs23ddXQc9Zff2VJotEn2zaSAh4tvw6U6kb7fdXovZ8YPQgJMGQkXmtWiTutqnoBf6wR2khaKvFpyEKNhHfjJ
The funds for WIZ's deployer came from the Andy Ayrey ATO. Other addresses involved in the rush transferred all profits obtained through instant exchanges to the casino deposit address 0x83ee.
0x83ee6b53a0ae76b71bed0c32721a451776dbdb3a
On October 16, 2024, 0x83ee received 0.54 ETH from the deployer of the scam, while SPX 6900 was hacked on October 11, 2024.
On Solana, another scam promoted by the hacked SPX 6900 account was funded by the Ken Carson attacker.
To further demonstrate the relationship between the Kabosu owner, SPX 6900, Ken Carson, and Enoshima ATO, each meme coin deployer provided funding to the previous deployer address through instant exchange funds, attempting to obscure the source of the funds.
Investigate how the threat actor Serpent transitioned from a professional Fortnite player to helping steal $3.5M through meme coin scams initiated from leaks of 9+ accounts on X and IG, using the proceeds for online casino gambling.
Serpent (SerpentAU) is a former professional Fortnite player from Australia who was released by the esports organization "Overtime" in June 2020 after being found guilty of cheating. He then co-founded the NFT project DAPE in March 2022, which later rug pulled.
In March 2024, Serpent launched another project called ERROR, but this project also rug pulled, leading to his ban on the X platform.
Deployer address:
0x8233873ee35547097ccb9098adbab955d7120ee8
On October 23, 2024, the ERROR deployer transferred a total of 29 ETH to two instant exchanges.
By conducting a time analysis, it can be seen that these funds were received in Solana and transferred to the same casino deposit address.
Ecb5vsomUG3MEnLCgiFvkdnnqpggTEXtN17z62iDPuU3
Multiple ATOs (Account Takeover) directly connected to the deposit address Ecb5vs include: McDonald's, Usher, Andy Ayrey, Dean Norris, and Enoshima Aquarium. (For detailed tracking content, please refer to the beginning section)
Serpent gambles millions of dollars monthly on Roobet, Stake, BC Game, and Shuffle, often sharing his screen with friends on Discord.
I obtained recordings of him while gambling, during which he inadvertently leaked multiple deposit and withdrawal addresses.
Discord ID: 1269557350486904945
In a screen share on November 1, 2024, Serpent shared a $100K deposit and a $200K withdrawal, transferring to the following address.
When mapping the transaction graph, it was found that this address had a high exposure to addresses related to McDonald's, Andy Ayrey, and Usher ATO.
0xb8c9c8a5756a7992df65f949b7c1423eeb435aa5
In the Andy Ayrey security breach incident, another threat actor participated in seizing these scam projects, using the alias "Dex" (from Massachusetts, USA).
He began to panic after I mentioned him in my Telegram channel last week and fabricated a story about being extorted, claiming he lost $700K.
Currently, the funds related to these breaches are stored at the following addresses:
0xeb60a5242c1c97eb54195ec83de43bb26813c0d1
0x2355ac2929bb7051814de3c48670fccbb515d8be
4jjWZ8RaXZBqntnhu2JFidXEQWXgfKRbJQZdTHrdaqbv
Today, after the release of the first part of my investigation, Serpent began deleting all his posts on his new X account. I suspect there are still some related ATOs (Account Takeover) that I have not been able to directly trace on-chain. Regarding one of the account breach incidents, I have shared a detailed investigation report with a victim I am collaborating with.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。