================================================================================================
CASE 409  |  NFT collector and crypto trader "Sillytuna"  |  March 4, 2026  |  Hong Kong
================================================================================================

DATABASE RECORD
  id                  409
  date                March 4, 2026
  original_date       March 4, 2026
  year                2026
  month               3
  quarter             2026-Q1
  victim              NFT collector and crypto trader "Sillytuna"
  location            Hun Hom
  country             Hong Kong
  scenario            Home Invasion
  description         "Sillytuna" claimed violent attack with axes over hands/feet resulting in forced transfer of $24 million in aEthUSDC. Victim posted on X about bruises, weapons, kidnapping/sexual assault threats, stated police involved and "definitely out of crypto," offered 10% bounty. 
  kidnappings         1
  violence_torture    1
  drugs_alcohol       (null)
  weapons             1
  theft               1
  life_taken          0
  money_wanted        $24 million
  coin_type           $24 million in aEthUSDC
  reports             The Block
  notes               Blockchain confirmed $24M transfer and rapid laundering to DAI/Monero via Arbitrum/Hyperliquid
  has_processed_date  0
  created_at          2026-03-05 16:40:45
  (flag legend: 'kidnappings' is the DETENTION flag — 1 when the victim was held against
   their will at any point, tied, locked in, held at gunpoint or taken away; it is NOT the
   same as the 'Kidnapping' scenario, which means taken away and held. See README, Definitions.)

AI SUMMARY  [generated at bulk import, NOT verified against sources]
  **Victim:** "Sillytuna" (pseudonym), X account active since June 2008. Longtime NFT collector (formerly owned CryptoPunk #9839, BAYC, CloneX, Meebits, Eufloria). Gaming entrepreneur associated with Soulcast NFT and Clodhoppers/Claymatic Games. Active DeFi participant, primarily used Aave protocol. Real identity not publicly confirmed.
  
  **Attackers:** Unknown. No number, descriptions, names, or identifying details provided by victim.
  
  **Attack Method:** Per victim's X posts March 4, 2026: violent physical assault using weapons. Victim wrote "Bruised, held off while I could, but can't do that much with axes over your hands and feet." Claimed threats of kidnapping and sexual assault. Forced to transfer cryptocurrency under duress. No location disclosed. Victim stated police involved but did not identify agency.
  
  **Violence Used:** Claimed: axes held over/against hands and feet, physical assault leaving bruises, death/kidnapping threats, sexual assault threats. Victim indicated resistance but overcome by force.
  
  **Crypto Demanded/Stolen:** ~$24 million in aEthUSDC (Aave interest-bearing USDC on Avalanche network). Single on-chain transaction March 5, 2026 from victim wallet 0xd2e8…ca41 to attacker wallet 0x6fef…a246032. Blockchain-verified theft.
  
  Attacker laundered rapidly: converted $20.34M to DAI split across 2 wallets (0xd0c…9dd3E: ~$10M; 0xcdCA…eC9C4: ~$9.979M). Bridged ~$2.48M to USDC on Arbitrum. Moved $2.47M to Hyperliquid via 19 Wagyu-linked accounts to purchase Monero (XMR privacy coin). Bridged ~$1.1M to Bitcoin via LiFi. Possibly deposited 0.5 BTC into mixing service. Destination addresses linked to known scammer wallet (0xbeef prefix, history of exploits/rug pulls).
  
  **Status:** Victim offered 10% bounty "even if you were involved." Posted "definitely out of crypto" indicating retirement. No arrests, no police statements, no media investigations, no independent corroboration of physical attack. Blockchain security firms (PeckShield, Arkham Intelligence) tracked funds. Wagyu bridge blacklisted wallets but didn't freeze funds.

LINKED SOURCES
  [url]  https://www.theblock.co/post/392363/sillytuna-x-account-claims-crypto-stolen
  [url_2]  https://x.com/sillytuna/status/2029311564633809279
  [url_3]  https://coinpedia.org/crypto-live-news/crypto-trader-loses-24m-in-violent-attack/
  [url_4]  https://www.tradingview.com/news/coinpedia:e26a909d6094b:0-crypto-og-loses-24m-in-suspected-address-poisoning-attack-peckshield/
  [url_5]  https://beincrypto.com/crypto-attack-sillytuna-violent-threats/

OTHER LINKED SOURCES
  [NOT AN ARTICLE]  url_2  None — video or social post; recorded as a source reference, not transcribed
      https://x.com/sillytuna/status/2029311564633809279

------------------------------------------------------------------------------------------------
FETCHED ARTICLE 1
  Source     theblock.co
  URL        https://www.theblock.co/post/392363/sillytuna-x-account-claims-crypto-stolen
  Field      url
  Retrieved  2026-08-06T13:42:23+00:00 via raw HTTP retrieval, deterministic extraction (HTTP 200)
  Language   unknown
  Kept       paragraphs headline [0] + 7-23 of 29
  Length     2,811 chars
  Integrity  sha256 41ae939a5366857bd417dc707c0e6480380d92118bef04029f1a87baea2b723a
  Trimmed    trimmed on read-through
  Caveat     retrieved from a live page on the date above. Unlike text copied
             from the spreadsheet, there is no second copy to hash it against.
------------------------------------------------------------------------------------------------

ORIGINAL (unknown, verbatim as retrieved)

Discover the institutional crypto exchange LMAX Digital through high-level info and live data here.

The X account of crypto trader “Sillytuna” claimed that roughly $24 million in aEthUSDC was stolen in a violent attack.

Arkham Intelligence said the attacker moved the funds across Layer 2 networks, Bitcoin, and Monero in an apparent attempt to obscure the trail.

We'd love your feedback.

Take a 30-second survey to help improve The Block.

Across several X posts shared on Wednesday, Sillytuna said that the attack included violence, weapons, kidnapping, and threats of sexual assault. Although the X user stated that law enforcement is involved, authorities have yet to confirm the details of the alleged incident.

"Bruised, held off while I could, but can't do that much with axes over your hands and feet," the X user wrote, adding that he is now "definitely out of crypto."

The posts quickly circulated across the crypto community, drawing attention to the scale of the alleged theft and the disturbing circumstances surrounding it.

Sillytuna also offered a 10% bounty for recovering the funds. "Reminder: 10% bounty of any funds individuals or platforms can recover for me. Even if you were involved," the account said.

"I had to fight off 4 armed attackers but couldn't keep that up for long," Sillytuna later told The Block. "There is now a large movement both from law enforcement and white hats to recover funds and find the culprits."

Moved across Layer 2s, Bitcoin and Monero

Blockchain analytics platform Arkham Intelligence said that the attacker moved the funds across Layer 2 networks, Bitcoin, and Monero in what appeared to be an effort to obscure the trail.

According to Arkham's analysis, roughly $20 million of the stolen funds were stored in two Ethereum addresses in the form of DAI, while other portions were bridged to different networks.

About $2.48 million was bridged to USDC on Arbitrum, while $2.47 million was sent to Hyperliquid across 19 separate Wagyu-linked accounts, which were then used to purchase the privacy-focused cryptocurrency Monero (XMR).

The attacker also bridged about $1.1 million to the Bitcoin network via LiFi, Arkham added, noting that the thieves may have deposited 0.5 BTC into a mixing service.

Blockchain security firm PeckShield also flagged the wallet activity shortly after the claims surfaced, echoing that roughly $24 million in assets linked to the trader's account had been drained and transferred to another address.

Violent attempts to steal crypto from social media influencers or key opinion leaders have been on the rise in recent months.

The Sillytuna X account, which has been active since June 2008, appears connected to a longtime non-fungible token and gaming entrepreneur who has used the alias across several platforms.

------------------------------------------------------------------------------------------------
FETCHED ARTICLE 2
  Source     coinpedia.org
  URL        https://coinpedia.org/crypto-live-news/crypto-trader-loses-24m-in-violent-attack/
  Field      url_3
  Retrieved  2026-08-06T13:42:23+00:00 via raw HTTP retrieval, deterministic extraction (HTTP 200)
  Language   unknown
  Kept       paragraphs headline [0] + 1-1 of 12
  Length     520 chars
  Integrity  sha256 9d739165e15949b8d3a1ede85b8922d48b4d2d26c7e9d9389faa48f2810a1c56
  Trimmed    trimmed on read-through
  Caveat     retrieved from a live page on the date above. Unlike text copied
             from the spreadsheet, there is no second copy to hash it against.
------------------------------------------------------------------------------------------------

ORIGINAL (unknown, verbatim as retrieved)

﻿ Crypto Trader Loses $24M in Violent Attack

A crypto trader known as Sillytuna was reportedly violently extorted, resulting in the theft of about $23.6 million in aEthUSDC from his wallet. Blockchain tracking shows the attacker quickly converted most of the stolen funds into around $20.34 million in DAI, while a smaller portion was bridged to Arbitrum and later moved to Hyperliquid. The funds were reportedly used to purchase Monero (XMR), a privacy-focused cryptocurrency, making the stolen assets harder to trace.

------------------------------------------------------------------------------------------------
FETCHED ARTICLE 3
  Source     tradingview.com
  URL        https://www.tradingview.com/news/coinpedia:e26a909d6094b:0-crypto-og-loses-24m-in-suspected-address-poisoning-attack-peckshield/
  Field      url_4
  Retrieved  2026-08-06T13:42:25+00:00 via raw HTTP retrieval, deterministic extraction (HTTP 200)
  Language   unknown
  Kept       paragraphs headline [0] + 15-19 of 28
  Length     718 chars
  Integrity  sha256 46fd74012bb529015e2214d3068102eca3e748ef2564726e1fb4ff8a77ab86f1
  Trimmed    trimmed on read-through
  Caveat     retrieved from a live page on the date above. Unlike text copied
             from the spreadsheet, there is no second copy to hash it against.
------------------------------------------------------------------------------------------------

ORIGINAL (unknown, verbatim as retrieved)

Crypto OG Loses $24M In Suspected Address Poisoning Attack – PeckShield — TradingView News

Blockchain monitoring also shows the attacker has started bridging small portions of the funds to the Arbitrum network.

One tracked transfer indicates a bridge transaction sending roughly 49.85 ETH, which resulted in over 106,000 USDC appearing on Arbitrum through a cross-chain bridge.

Security researchers believe the attacker may continue moving funds in smaller portions to avoid triggering alerts.

Victim Claims Physical Threats Were Involved

Shortly after the attack became public, sillytuna confirmed the compromised wallet was his personal address, revealing that the situation involved serious real-world threats.

------------------------------------------------------------------------------------------------
FETCHED ARTICLE 4
  Source     beincrypto.com
  URL        https://beincrypto.com/crypto-attack-sillytuna-violent-threats/
  Field      url_5
  Retrieved  2026-08-06T13:42:26+00:00 via raw HTTP retrieval, deterministic extraction (HTTP 200)
  Language   unknown
  Kept       paragraphs headline [0] + 1-12 of 24
  Length     1,772 chars
  Integrity  sha256 55bee6a9a3b495aa6c127d9c7f7ef7c221a7095dde898ccad6e793686fdc8820
  Trimmed    trimmed on read-through
  Caveat     retrieved from a live page on the date above. Unlike text copied
             from the spreadsheet, there is no second copy to hash it against.
------------------------------------------------------------------------------------------------

ORIGINAL (unknown, verbatim as retrieved)

Crypto Holder Loses $24 Million in Address Poisoning Attack Tied to Violent Threats

A crypto holder identified as Sillytuna lost approximately $24 million in aEthUSDC after an address poisoning attack, with the incident also involving violent threats.

According to on-chain data, the attacker has already converted most of the stolen funds.

An address poisoning attack is a crypto scam in which scammers create a lookalike address and send a small transaction to the target’s address book.

This “poisons” the target’s address book, leading them to mistakenly send funds to the scammer’s address instead of the intended recipient.

It relies on the fact that people may copy wallet addresses from recent transactions rather than verify the full address.

The attack on Sillytuna is part of a broader escalating pattern. According to blockchain security firm CertiK, 2025 was the most violent year in the cryptocurrency space, with 72 recorded incidents.

PeckShieldAlert identified the exploited address as 0xd2e8…ca41, linked to Sillytuna, with approximately $24 million in aEthUSDC drained.

Sillytuna confirmed on X that the attack involved violence, weapons, and kidnapping threats, with police now involved.

Lookonchain tracked the attacker converting most funds into 20.34 million DAI (DAI), with a smaller portion bridged to Arbitrum and deposited into Hyperliquid to buy Monero (XMR).

Sillytuna is offering a 10% bounty on any funds recovered by individuals or platforms.

Physical violence against crypto holders surged 75% year over year in 2025. Kidnapping was the most common attack method, with assaults also rising sharply.

XMR purchases by attackers indicate a deliberate pivot to privacy coins to obstruct on-chain tracing and asset recovery efforts.

================================================================================================
generated from attacks-export-Gart-website.json + reported_K&R  |  case 409
================================================================================================
