Cashaa Hack

Prayank
3 min readJul 13, 2020

335.9 BTC were moved to address 14RYUUaMW1shoxCav4znEh64xnTtL3a2Ek in this security incident and later in other UTXOs. You can explore the transactions using the above link. Fee rate used in this transaction was 66.46 SAT/VB. I would expect hackers to use a higher fee rate and not RBF transaction but it is possible that hacker planned it differently or it was an insider and whole incident is fake.

Three transactions that look interesting after expanding all the transactions involved:

5849b97dfb910c609d17006cbe3d573ad5b06cec7af3c566bf910e6eb4256b2a

5da7929448f5c8b287464affb8f02921bfa188efce2bf98dfc2e4e2a97e70ec7

054fed059fed07880fea16bdf04f81ee608d3b8403932ae787210b5c5b1cc64f

Not sure but some of the BTC has been sold on some exchange is not labelled on OXT right now or some OTC market in India that works locally.

The screenshot of complaint which mentions few interesting things including two addresses, time, use of blockchain.info wallet and user activity. There was some malware thing mentioned in cointelegraph article which can be true but then you dont expect such stupidity from an exchange. Not sure why they think hacker is from East Delhi.

https://www.reddit.com/r/Bitcoin/comments/hpg9j3/336_btc_hacked_from_cashaa_they_were_using/fxrrbiw/

Greg Maxwell has mentioned important thing that most of the users and exchanges are using shitty wallets and services to manage their BTC holdings. It is irresponsible and unacceptable for an exchange to use blockchain.info wallet for their users funds. They should be using their own full node, cold storage and multi-sig to have a secure setup which can be managed by people who are competent and experienced.

Police will not be able to do much in this case as they couldnt do anything in Coinsecure case. You can read my old posts to know about whole thing and I had also emailed several people including DCP, Delhi Police Cyber Crime Cell but no response yet or any progress.

I will update this post if there is any new information.

Blockonomics “wallet watcher” can be helpful to keep a track of BTC movement in this case: https://www.blockonomics.co/views/wallet-watcher.html

UTXOs that you can keep an eye on:

bc1qtfmgnpye86eycn3vw7vy4wvrxj48c8pr2yd0fj
bc1q5re0ul5jec6ctnspppyewvdn6rs9zezu9mayr5
35BNUe1otLbe2QkMtkPuJnnAgf8LTDn5VN
3A355HNmyw5JcXcnFntNfwFeeNYTypqcma
35tUitBHZtAhec1GnyUxre8zHTAQ8GVaSC
bc1qmg7yueptws2mejrta4u7tcmfgjvhv89t67jtcs
bc1q9pg90pw0xy7gsmt6yrgz4tmaqq3nuy5qqpncvk
bc1q7u56suywgthelxzuhfm99d2nld63de2n0fnyk4
bc1q87u5xzuwwwt8frluj9vw7fddcvhe3xght0h3h0
3EF8qbEt7XTsmbnh7n8YbvVZyQanV8ULof
177AgBzQH5CUuhZQWn9CY4YyHfoZfk3T4c
36m2hguHr5RX5ynvbnGg35MLyvrWNwSjXY
34PM2reZt4n9ymCMc7pZcuBbk7L1gPAQqi
3Lin6M9DeeGGhc4QormH8GZUt2C3Pn2H3R
bc1qa75w4n35qmay7auu0cvvazuq9z6v7e2c6weafa
1EfFzEuQbaeYKdXXuJSXQWdiL6mPJdcrbD
bc1q305jdlk3assjkj28d449mxhw45vxqmns0y7vp5
1QAnBk4oC8CPRUDZBGyEGgjn9VhxhKPmJ4
184b119VjbjxFFSGh2qLSG85gwMusafqkw
bc1qacl0kqht4yzzcq5afu9emwuu93mzwlcx2c59p5
36bA5vY2wooGn4LQGiqATPFjS9Fn1o3ghq

Bitcoin wallets: https://bitcoin-only.com/#wallets

Full node and Hardware: https://bitcoin-only.com/#hardware

Multisig: https://unchained-capital.github.io/caravan/

--

--