Incident overview
The victim said the incident began with a file he believed was safe, after which his PC, multiple accounts, and X account were accessed without authorization. No file sample, hash, malware family, wallet address, transaction ID, or forensic report was published, so the entry vector cannot be classified as an infostealer, RAT, clipboard hijacker, malicious signature, or another specific mechanism.
Incident sequence
- The victim ran or opened an unknown file.
- His PC and multiple accounts were accessed without authorization, and his X account was temporarily taken over.
- While restoring the X account, he found that wallet assets and NFTs had been transferred away.
- At 13:00:33 on July 24, 2026, he publicly described the loss and warned users not to run unknown test applications or verification files.
Fund flow
No complete wallet, recipient address, or transaction ID was published. The database therefore does not guess the chain, addresses, or attacker attribution and adds no identifier to the formal address ledger.
Amount basis
The victim said more than $600 in wallet assets was transferred and NFTs were also stolen, bringing total loss above $1,000. The database records $1,000 as the public lower bound and does not separately assign an NFT valuation, avoiding duplication or inflation.
Evidence boundary
The first-party statement supports a public victim report but lacks chain identifiers, a malicious sample, and independent forensics. The specific chain, malware type, attacker addresses, NFT value, and final destination of funds remain unverified.
Current status
The X account was restored, but the stolen assets and NFTs were not confirmed as recovered. No issuer freeze, exchange interception, police document, or asset return was disclosed, and recoveredUsd remains 0.