Today, the founder of the ToAus Lion community, BroLeon, once again stirred up a storm on Twitter with a bombshell revelation. He claimed to have received information from a friend that a hacker used purchased social engineering data to create a fake identity card, then generated a fake avatar video using AI. This deceitful tactic reportedly tricked Okx's manual review process, resulting in the theft of over 3 million USD.
The theft occurred in the early hours of May 3rd. After active communication with the platform, the victim learned that it was not a widespread data breach but rather a targeted attack. The breach didn't occur due to leaked email passwords, phone numbers, or Google authentication codes. Instead, the hacker accessed the victim's email, clicked on the "forgot password" option, and bypassed all security measures using an AI-generated video. Without the victim's knowledge, the hacker changed their phone number, email, and Google Authenticator, resulting in the complete loss of assets within 24 hours.
The victim was devastated upon seeing the AI-generated "self" holding a fake ID card and reciting personal information. Despite the obvious fakeness, this tactic somehow bypassed the platform's extensive security measures, leaving the victim in disbelief.
The victim had entrusted all their assets to the platform due to their trust in its compliance processes. However, the loss of all assets due to the platform's purported security measures was a bitter irony.
Law enforcement is now involved, having gathered some leads and identifying two individuals involved in the forgery. However, the victim suspects there may be additional perpetrators yet to be uncovered. Due to limitations in law enforcement technology, this process will take time.
Regarding compensation, the victim hopes Okx will fully reimburse their losses, emphasizing that while 2 million USD may seem insignificant to the platform, it's a significant loss for them.
This incident has garnered widespread attention, highlighting the significant challenges cryptocurrency trading platforms face regarding security and user protection. The victim hopes Okx will take responsibility and compensate for their substantial loss. They also urge other users to remain vigilant against similar scams. Meanwhile, law enforcement's involvement offers a glimmer of hope for victims, aiming to apprehend the perpetrators and recover stolen assets. This incident serves as a stern warning for the cryptocurrency industry, emphasizing the necessity for platforms to continuously enhance security measures, protect user assets, and establish more robust risk control systems to prevent such tragedies from recurring.