Files
DB-cleanup/merge-output/sources/409_NFT-collector-and-crypto-trader-Sillytun.txt
T
SofiaandClaude Opus 4.8 ba7529ea50 K&R database cleanup: handoff bundle
Self-contained bundle to continue the case-summary enrichment pass (70/256 done). sources/ holds the 364 .txt dossiers; scripts use relative paths.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018FJRciSWZc9HftS2edbzBf
2026-09-02 19:49:46 -03:00

205 lines
14 KiB
Plaintext
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
================================================================================================
CASE 409 | NFT collector and crypto trader "Sillytuna" | March 4, 2026 | Hong Kong
================================================================================================
DATABASE RECORD
id 409
date March 4, 2026
original_date March 4, 2026
year 2026
month 3
quarter 2026-Q1
victim NFT collector and crypto trader "Sillytuna"
location Hun Hom
country Hong Kong
scenario Home Invasion
description "Sillytuna" claimed violent attack with axes over hands/feet resulting in forced transfer of $24 million in aEthUSDC. Victim posted on X about bruises, weapons, kidnapping/sexual assault threats, stated police involved and "definitely out of crypto," offered 10% bounty.
kidnappings 1
violence_torture 1
drugs_alcohol (null)
weapons 1
theft 1
life_taken 0
money_wanted $24 million
coin_type $24 million in aEthUSDC
reports The Block
notes Blockchain confirmed $24M transfer and rapid laundering to DAI/Monero via Arbitrum/Hyperliquid
has_processed_date 0
created_at 2026-03-05 16:40:45
AI SUMMARY [generated at bulk import, NOT verified against sources]
**Victim:** "Sillytuna" (pseudonym), X account active since June 2008. Longtime NFT collector (formerly owned CryptoPunk #9839, BAYC, CloneX, Meebits, Eufloria). Gaming entrepreneur associated with Soulcast NFT and Clodhoppers/Claymatic Games. Active DeFi participant, primarily used Aave protocol. Real identity not publicly confirmed.
**Attackers:** Unknown. No number, descriptions, names, or identifying details provided by victim.
**Attack Method:** Per victim's X posts March 4, 2026: violent physical assault using weapons. Victim wrote "Bruised, held off while I could, but can't do that much with axes over your hands and feet." Claimed threats of kidnapping and sexual assault. Forced to transfer cryptocurrency under duress. No location disclosed. Victim stated police involved but did not identify agency.
**Violence Used:** Claimed: axes held over/against hands and feet, physical assault leaving bruises, death/kidnapping threats, sexual assault threats. Victim indicated resistance but overcome by force.
**Crypto Demanded/Stolen:** ~$24 million in aEthUSDC (Aave interest-bearing USDC on Avalanche network). Single on-chain transaction March 5, 2026 from victim wallet 0xd2e8…ca41 to attacker wallet 0x6fef…a246032. Blockchain-verified theft.
Attacker laundered rapidly: converted $20.34M to DAI split across 2 wallets (0xd0c…9dd3E: ~$10M; 0xcdCA…eC9C4: ~$9.979M). Bridged ~$2.48M to USDC on Arbitrum. Moved $2.47M to Hyperliquid via 19 Wagyu-linked accounts to purchase Monero (XMR privacy coin). Bridged ~$1.1M to Bitcoin via LiFi. Possibly deposited 0.5 BTC into mixing service. Destination addresses linked to known scammer wallet (0xbeef prefix, history of exploits/rug pulls).
**Status:** Victim offered 10% bounty "even if you were involved." Posted "definitely out of crypto" indicating retirement. No arrests, no police statements, no media investigations, no independent corroboration of physical attack. Blockchain security firms (PeckShield, Arkham Intelligence) tracked funds. Wagyu bridge blacklisted wallets but didn't freeze funds.
LINKED SOURCES
[url] https://www.theblock.co/post/392363/sillytuna-x-account-claims-crypto-stolen
[url_2] https://x.com/sillytuna/status/2029311564633809279
[url_3] https://coinpedia.org/crypto-live-news/crypto-trader-loses-24m-in-violent-attack/
[url_4] https://www.tradingview.com/news/coinpedia:e26a909d6094b:0-crypto-og-loses-24m-in-suspected-address-poisoning-attack-peckshield/
[url_5] https://beincrypto.com/crypto-attack-sillytuna-violent-threats/
OTHER LINKED SOURCES
[NOT AN ARTICLE] url_2 None — video or social post; recorded as a source reference, not transcribed
https://x.com/sillytuna/status/2029311564633809279
------------------------------------------------------------------------------------------------
FETCHED ARTICLE 1
Source theblock.co
URL https://www.theblock.co/post/392363/sillytuna-x-account-claims-crypto-stolen
Field url
Retrieved 2026-08-06T13:42:23+00:00 via raw HTTP retrieval, deterministic extraction (HTTP 200)
Language unknown
Kept paragraphs headline [0] + 7-23 of 29
Length 2,811 chars
Integrity sha256 41ae939a5366857bd417dc707c0e6480380d92118bef04029f1a87baea2b723a
Trimmed trimmed on read-through
Caveat retrieved from a live page on the date above. Unlike text copied
from the spreadsheet, there is no second copy to hash it against.
------------------------------------------------------------------------------------------------
ORIGINAL (unknown, verbatim as retrieved)
Discover the institutional crypto exchange LMAX Digital through high-level info and live data here.
The X account of crypto trader “Sillytuna” claimed that roughly $24 million in aEthUSDC was stolen in a violent attack.
Arkham Intelligence said the attacker moved the funds across Layer 2 networks, Bitcoin, and Monero in an apparent attempt to obscure the trail.
We'd love your feedback.
Take a 30-second survey to help improve The Block.
Across several X posts shared on Wednesday, Sillytuna said that the attack included violence, weapons, kidnapping, and threats of sexual assault. Although the X user stated that law enforcement is involved, authorities have yet to confirm the details of the alleged incident.
"Bruised, held off while I could, but can't do that much with axes over your hands and feet," the X user wrote, adding that he is now "definitely out of crypto."
The posts quickly circulated across the crypto community, drawing attention to the scale of the alleged theft and the disturbing circumstances surrounding it.
Sillytuna also offered a 10% bounty for recovering the funds. "Reminder: 10% bounty of any funds individuals or platforms can recover for me. Even if you were involved," the account said.
"I had to fight off 4 armed attackers but couldn't keep that up for long," Sillytuna later told The Block. "There is now a large movement both from law enforcement and white hats to recover funds and find the culprits."
Moved across Layer 2s, Bitcoin and Monero
Blockchain analytics platform Arkham Intelligence said that the attacker moved the funds across Layer 2 networks, Bitcoin, and Monero in what appeared to be an effort to obscure the trail.
According to Arkham's analysis, roughly $20 million of the stolen funds were stored in two Ethereum addresses in the form of DAI, while other portions were bridged to different networks.
About $2.48 million was bridged to USDC on Arbitrum, while $2.47 million was sent to Hyperliquid across 19 separate Wagyu-linked accounts, which were then used to purchase the privacy-focused cryptocurrency Monero (XMR).
The attacker also bridged about $1.1 million to the Bitcoin network via LiFi, Arkham added, noting that the thieves may have deposited 0.5 BTC into a mixing service.
Blockchain security firm PeckShield also flagged the wallet activity shortly after the claims surfaced, echoing that roughly $24 million in assets linked to the trader's account had been drained and transferred to another address.
Violent attempts to steal crypto from social media influencers or key opinion leaders have been on the rise in recent months.
The Sillytuna X account, which has been active since June 2008, appears connected to a longtime non-fungible token and gaming entrepreneur who has used the alias across several platforms.
------------------------------------------------------------------------------------------------
FETCHED ARTICLE 2
Source coinpedia.org
URL https://coinpedia.org/crypto-live-news/crypto-trader-loses-24m-in-violent-attack/
Field url_3
Retrieved 2026-08-06T13:42:23+00:00 via raw HTTP retrieval, deterministic extraction (HTTP 200)
Language unknown
Kept paragraphs headline [0] + 1-1 of 12
Length 520 chars
Integrity sha256 9d739165e15949b8d3a1ede85b8922d48b4d2d26c7e9d9389faa48f2810a1c56
Trimmed trimmed on read-through
Caveat retrieved from a live page on the date above. Unlike text copied
from the spreadsheet, there is no second copy to hash it against.
------------------------------------------------------------------------------------------------
ORIGINAL (unknown, verbatim as retrieved)
 Crypto Trader Loses $24M in Violent Attack
A crypto trader known as Sillytuna was reportedly violently extorted, resulting in the theft of about $23.6 million in aEthUSDC from his wallet. Blockchain tracking shows the attacker quickly converted most of the stolen funds into around $20.34 million in DAI, while a smaller portion was bridged to Arbitrum and later moved to Hyperliquid. The funds were reportedly used to purchase Monero (XMR), a privacy-focused cryptocurrency, making the stolen assets harder to trace.
------------------------------------------------------------------------------------------------
FETCHED ARTICLE 3
Source tradingview.com
URL https://www.tradingview.com/news/coinpedia:e26a909d6094b:0-crypto-og-loses-24m-in-suspected-address-poisoning-attack-peckshield/
Field url_4
Retrieved 2026-08-06T13:42:25+00:00 via raw HTTP retrieval, deterministic extraction (HTTP 200)
Language unknown
Kept paragraphs headline [0] + 15-19 of 28
Length 718 chars
Integrity sha256 46fd74012bb529015e2214d3068102eca3e748ef2564726e1fb4ff8a77ab86f1
Trimmed trimmed on read-through
Caveat retrieved from a live page on the date above. Unlike text copied
from the spreadsheet, there is no second copy to hash it against.
------------------------------------------------------------------------------------------------
ORIGINAL (unknown, verbatim as retrieved)
Crypto OG Loses $24M In Suspected Address Poisoning Attack PeckShield — TradingView News
Blockchain monitoring also shows the attacker has started bridging small portions of the funds to the Arbitrum network.
One tracked transfer indicates a bridge transaction sending roughly 49.85 ETH, which resulted in over 106,000 USDC appearing on Arbitrum through a cross-chain bridge.
Security researchers believe the attacker may continue moving funds in smaller portions to avoid triggering alerts.
Victim Claims Physical Threats Were Involved
Shortly after the attack became public, sillytuna confirmed the compromised wallet was his personal address, revealing that the situation involved serious real-world threats.
------------------------------------------------------------------------------------------------
FETCHED ARTICLE 4
Source beincrypto.com
URL https://beincrypto.com/crypto-attack-sillytuna-violent-threats/
Field url_5
Retrieved 2026-08-06T13:42:26+00:00 via raw HTTP retrieval, deterministic extraction (HTTP 200)
Language unknown
Kept paragraphs headline [0] + 1-12 of 24
Length 1,772 chars
Integrity sha256 55bee6a9a3b495aa6c127d9c7f7ef7c221a7095dde898ccad6e793686fdc8820
Trimmed trimmed on read-through
Caveat retrieved from a live page on the date above. Unlike text copied
from the spreadsheet, there is no second copy to hash it against.
------------------------------------------------------------------------------------------------
ORIGINAL (unknown, verbatim as retrieved)
Crypto Holder Loses $24 Million in Address Poisoning Attack Tied to Violent Threats
A crypto holder identified as Sillytuna lost approximately $24 million in aEthUSDC after an address poisoning attack, with the incident also involving violent threats.
According to on-chain data, the attacker has already converted most of the stolen funds.
An address poisoning attack is a crypto scam in which scammers create a lookalike address and send a small transaction to the targets address book.
This “poisons” the targets address book, leading them to mistakenly send funds to the scammers address instead of the intended recipient.
It relies on the fact that people may copy wallet addresses from recent transactions rather than verify the full address.
The attack on Sillytuna is part of a broader escalating pattern. According to blockchain security firm CertiK, 2025 was the most violent year in the cryptocurrency space, with 72 recorded incidents.
PeckShieldAlert identified the exploited address as 0xd2e8…ca41, linked to Sillytuna, with approximately $24 million in aEthUSDC drained.
Sillytuna confirmed on X that the attack involved violence, weapons, and kidnapping threats, with police now involved.
Lookonchain tracked the attacker converting most funds into 20.34 million DAI (DAI), with a smaller portion bridged to Arbitrum and deposited into Hyperliquid to buy Monero (XMR).
Sillytuna is offering a 10% bounty on any funds recovered by individuals or platforms.
Physical violence against crypto holders surged 75% year over year in 2025. Kidnapping was the most common attack method, with assaults also rising sharply.
XMR purchases by attackers indicate a deliberate pivot to privacy coins to obstruct on-chain tracing and asset recovery efforts.
================================================================================================
generated from attacks-export-Gart-website.json + reported_K&R | case 409
================================================================================================