Crypto Theft Exceeds $4.3 Million Following Private Key Leak
British security firm Specter reports over $4.3 million in crypto assets stolen across Ethereum, Tron, and Bitcoin networks following a suspected private key leak.

Cryptocurrency assets exceeding $4.3 million were stolen in an attack originating from a private key leak belonging to an unidentified victim, according to British security firm Specter. In an alert published by the company, the attacker successfully drained at least 145 addresses on the Ethereum network, alongside assets stolen from other blockchain networks, including Tron and Bitcoin. Specter warns that the final amount may still increase as the attacker's activity continues.
Cross-Chain Asset Laundering
Most of the affected addresses held USDC stablecoins. After withdrawing the funds from the wallets, the attacker converted a large portion of them into Ethereum and transferred the assets across various networks. Simultaneously, Specter identified Bitcoin stolen from at least five wallets that was transferred to the same infrastructure. The concentration of funds from numerous addresses into shared destinations allowed blockchain investigators to track the money trail and identify a connection between the events.
A private key serves as the cryptographic password enabling a wallet owner to authorize asset transfers. Unlike a bank account, there is generally no central authority capable of reversing a transaction once approved on the blockchain. Consequently, if a private key is exposed to an unauthorized party, they may gain direct control over the assets without needing to breach an exchange's system or crack the network's security mechanism.
Ongoing Investigation and Risks
In this case, Specter did not disclose how the private key was exposed or who stands behind the attack. The identity of the victim or victims was also not published. The alert describes the incident as a suspected key leak and does not determine how the leak occurred. Therefore, at this stage, it remains impossible to ascertain whether the source was insecure key storage, malware, a phishing attack, or another method.
"The incident demonstrates the inherent risk of private control over digital assets: when a private key falls into the wrong hands, funds can be rapidly transferred across networks and converted into other assets," Specter reported.
The ongoing nature of the attack renders the case highly dynamic, with any additional address linked to the compromised key remaining a potential target. As of the alert's publication, Specter estimated the damages at over $4.3 million, though figures are expected to rise.





