<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=MyAlgo_Web_Wallet_JavaScript_CDN_Exploit</id>
	<title>MyAlgo Web Wallet JavaScript CDN Exploit - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=MyAlgo_Web_Wallet_JavaScript_CDN_Exploit"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=MyAlgo_Web_Wallet_JavaScript_CDN_Exploit&amp;action=history"/>
	<updated>2026-06-10T09:54:29Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=MyAlgo_Web_Wallet_JavaScript_CDN_Exploit&amp;diff=5439&amp;oldid=prev</id>
		<title>Azoundria: COMPLETE Another 30 minutes. Integrated the Reddit thread into the wiki. Information from about section moved to other sections. Added information on technical analysis. Integrated a few different sources into the article.</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=MyAlgo_Web_Wallet_JavaScript_CDN_Exploit&amp;diff=5439&amp;oldid=prev"/>
		<updated>2024-02-01T19:42:55Z</updated>

		<summary type="html">&lt;p&gt;COMPLETE Another 30 minutes. Integrated the Reddit thread into the wiki. Information from about section moved to other sections. Added information on technical analysis. Integrated a few different sources into the article.&lt;/p&gt;
&lt;a href=&quot;https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=MyAlgo_Web_Wallet_JavaScript_CDN_Exploit&amp;amp;diff=5439&amp;amp;oldid=5438&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=MyAlgo_Web_Wallet_JavaScript_CDN_Exploit&amp;diff=5438&amp;oldid=prev</id>
		<title>Azoundria: COMPLETE Another 30 minutes. Integrated the Reddit thread into the wiki.</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=MyAlgo_Web_Wallet_JavaScript_CDN_Exploit&amp;diff=5438&amp;oldid=prev"/>
		<updated>2024-02-01T17:08:48Z</updated>

		<summary type="html">&lt;p&gt;COMPLETE Another 30 minutes. Integrated the Reddit thread into the wiki.&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 11:08, 1 February 2024&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l109&quot;&gt;Line 109:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 109:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|Reddit Post&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|Reddit Post&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|A Reddit post advises against the typical strategy of buying and holding cryptocurrencies long-term, citing the MyAlgo wallet exploit as one potential pitfall with that strategy.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|A Reddit post advises against the typical strategy of buying and holding cryptocurrencies long-term, citing the MyAlgo wallet exploit as one potential pitfall with that strategy.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;|-&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;|March 9th, 2023 8:11:31 PM MST&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;|MyAlgo Recovery Fund Shot Down&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;|A Reddit post discusses the Algorand community facing a split opinion on a proposed 50 million ALGO recovery fund to assist victims of the myAlgo wallet exploit. Borderless Capital, an Algorand Venture Capital firm, suggested the fund to alleviate losses caused by the exploit&amp;lt;ref name=&quot;:0&quot;&gt;[https://old.reddit.com/r/CryptoCurrency/comments/11ncykj/algorand_community_nearunanimously_disapproves_of/ Algorand community near-unanimously disapproves of a potential last-minute governance proposal for a 50M ALGO recovery fund to help offset myAlgo victims - Reddit] (Jan 31, 2023)&amp;lt;/ref&gt;. However, the community is near-unanimously disapproving of the proposal due to concerns about rushing into a solution without thorough evaluation. Many community members argue that changing governance in the middle of a period sets a bad precedent and could lead to unintended consequences. Some express worries about funding attackers and suggest waiting for more information before making a decision. Overall, the community emphasizes the importance of a rational approach to address the aftermath of the exploit without exacerbating the situation&amp;lt;ref name=&quot;:0&quot;&gt;[https://old.reddit.com/r/CryptoCurrency/comments/11ncykj/algorand_community_nearunanimously_disapproves_of/ Algorand community near-unanimously disapproves of a potential last-minute governance proposal for a 50M ALGO recovery fund to help offset myAlgo victims - Reddit] (Jan 31, 2023)&amp;lt;/ref&gt;.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|March 18th, 2023 9:01:42 AM MDT&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|March 18th, 2023 9:01:42 AM MDT&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=MyAlgo_Web_Wallet_JavaScript_CDN_Exploit&amp;diff=5395&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/myalgowebwalletjavascriptcdnexploit.php}} {{Unattributed Sources}}  MyAlgo Wallet Homepage/LogoWeb-based wallet MyAlgo users found that their assets were being removed from their wallets starting in February 2023. The exploit remained unknown until April 2023, at which time it was revealed that malicious JavaScript code must have been injected on January 21st. The total lo...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=MyAlgo_Web_Wallet_JavaScript_CDN_Exploit&amp;diff=5395&amp;oldid=prev"/>
		<updated>2024-01-18T20:36:38Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/myalgowebwalletjavascriptcdnexploit.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Myalgo.jpg&quot; title=&quot;File:Myalgo.jpg&quot;&gt;thumb|MyAlgo Wallet Homepage/Logo&lt;/a&gt;Web-based wallet MyAlgo users found that their assets were being removed from their wallets starting in February 2023. The exploit remained unknown until April 2023, at which time it was revealed that malicious JavaScript code must have been injected on January 21st. The total lo...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/myalgowebwalletjavascriptcdnexploit.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Myalgo.jpg|thumb|MyAlgo Wallet Homepage/Logo]]Web-based wallet MyAlgo users found that their assets were being removed from their wallets starting in February 2023. The exploit remained unknown until April 2023, at which time it was revealed that malicious JavaScript code must have been injected on January 21st. The total losses have been estimated at $9.6m and investigation remains ongoing.&lt;br /&gt;
&lt;br /&gt;
This is a global/international case not involving a specific country.&amp;lt;ref name=&amp;quot;reddit-12842&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coindesk-12843&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;reddit-12844&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;redditold-12845&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cointelegraph-12846&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;myalgotwitter-12847&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;halbornsecuritytwitter-12848&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coinspectmedium-12849&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;wallet-12850&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;walletarchive-12851&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About MyAlgo Web Wallet ==&lt;br /&gt;
&amp;quot;MyAlgo, a native wallet for the Algorand blockchain network, has advised users to withdraw funds after it was struck by an exploit last week.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Blockchain sleuth ZachXBT said that 19.5 million ALGO and 3.5 million USDC worth $9.6 million have been stolen and that centralized exchange ChangeNow has frozen $1.5 million.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;We strongly advise all users to withdraw any funds from Mnemonic wallets that were stored in MyAlgo,&amp;quot; MyAlgo confirmed in a tweet.&lt;br /&gt;
&lt;br /&gt;
John Woods, chief technology officer of the Algorand Foundation, said that 25 wallets have been affected and that the exploit is &amp;quot;not the result of an underlying issue with the Algorand protocol or SDK (software development kit).&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;I haven’t seen many posts about this on CT yet but it’s suspected over $9.2m (19.5M ALGO, 3.5m USDC, etc) has been stolen on Algorand as a result of this attack from Feb 19th to 21st.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Algorand-focused developer collective D13.co released a report on Feb. 27 that eliminated multiple possible exploit vectors such as malware or operating system vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
The report determined the “most probable” scenarios were that the affected users’ seed phrases were compromised through socially engineered phishing attacks or MyAlgo’s website was compromised, leadin to the “targeted exfiltration of unencrypted private keys.”&lt;br /&gt;
&lt;br /&gt;
MyAlgo stated it would continue to work with authorities and would conduct a “thorough investigation to determine the root cause of the attack.”&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;I know this is not much to most of you but I put a good amount of my savings in ALGO because I love the tech behind it and believed it is the future.&lt;br /&gt;
&lt;br /&gt;
Now I know it was a third-party wallet that was hacked but the lack of information around the cause of hack and how it was performed does not instill confidence at all in the algorand community and team.&lt;br /&gt;
&lt;br /&gt;
It reeks of incompetence when I read the cause of the hack is still unknown. This has shaken up my confidence in Algorand and crypto in general.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;As I have been very active on this sub during most of the bear market, I obviously also saw what kind of advices were the most present on this sub from us bear market survivors. While “DCA“ may take the inevitable crone there also were calls to basically just buy your Crypto (or even DCA) and then completely forget about it to come back during a bull run for inevitable gains, right?&lt;br /&gt;
&lt;br /&gt;
Now I know why this is seen as a pretty popular theory as many people from the past basically did that. Someone from 2012 bought Bitcoin and then forgot about it until 2021 to become a millionaire. The problem here is that times have completely changed.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Attackers abused the CDN, to inject malicious code through a man-in-the-middle attack between the actual http://wallet(.)myalgo(.)com webapp and the user.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;It's unclear how the CDN API key was obtained.&lt;br /&gt;
&lt;br /&gt;
- No evidence of exploitation or vulnerability was found in MyAlgo codebase&lt;br /&gt;
&lt;br /&gt;
-No evidence that the CDN user account was compromised.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The audit logs cover 18 months, while the impacted account is 19 months old. Interestingly the account was never used until October 2022 (6 months ago). This raises the unlikely possibility that either logs are missing or the API key was obtained 19 months ago, evading the logs&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The malicious worker (which targeted a specific version of MyAlgo) was uploaded on January 21st, and the attack continued until mid-February when a new version of MyAlgo was released.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;It is important to note that law enforcement and security/forensics professionals will continue investigating, gathering more information that will help shed light on the details of the attack.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
This is a global/international case not involving a specific country.&lt;br /&gt;
&lt;br /&gt;
The background of the exchange platform, service, or individuals involved, as it would have been seen or understood at the time of the events.&lt;br /&gt;
&lt;br /&gt;
Include:&lt;br /&gt;
&lt;br /&gt;
* Known history of when and how the service was started.&lt;br /&gt;
* What problems does the company or service claim to solve?&lt;br /&gt;
* What marketing materials were used by the firm or business?&lt;br /&gt;
* Audits performed, and excerpts that may have been included.&lt;br /&gt;
* Business registration documents shown (fake or legitimate).&lt;br /&gt;
* How were people recruited to participate?&lt;br /&gt;
* Public warnings and announcements prior to the event.&lt;br /&gt;
&lt;br /&gt;
Don't Include:&lt;br /&gt;
* Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.&lt;br /&gt;
* Anything that wasn't reasonably knowable at the time of the event.&lt;br /&gt;
There could be more than one section here. If the same platform is involved with multiple incidents, then it can be linked to a main article page.&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
This sections is included if a case involved deception or information that was unknown at the time. Examples include:&lt;br /&gt;
&lt;br /&gt;
* When the service was actually started (if different than the &amp;quot;official story&amp;quot;).&lt;br /&gt;
* Who actually ran a service and their own personal history.&lt;br /&gt;
* How the service was structured behind the scenes. (For example, there was no &amp;quot;trading bot&amp;quot;.)&lt;br /&gt;
* Details of what audits reported and how vulnerabilities were missed during auditing.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - MyAlgo Web Wallet JavaScript CDN Exploit&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|January 21st, 2023&lt;br /&gt;
|Malicious Worker Uploaded&lt;br /&gt;
|The apparent time when the malicious worker was uploaded to affect certain version of the MyAlgo wallet.&lt;br /&gt;
|-&lt;br /&gt;
|February 19th, 2023&lt;br /&gt;
|First Wallet Drained&lt;br /&gt;
|The first MyAlgo wallets are drained of funds.&lt;br /&gt;
|-&lt;br /&gt;
|February 27th, 2023 5:38:00 AM MST&lt;br /&gt;
|Tweet Warning From MyAlgo&lt;br /&gt;
|MyAlgo shares a tweet to strongly advise users to withdraw any funds stored with a mnemonic generated from the MyAlgo wallet.&lt;br /&gt;
|-&lt;br /&gt;
|February 27th, 2023 6:13:00 PM MST&lt;br /&gt;
|ZachXBT Analysis&lt;br /&gt;
|ZachXBT shares his analysis of transactions and reports that he suspects the drainign of funds started on February 19th.&lt;br /&gt;
|-&lt;br /&gt;
|February 28th, 2023 5:01:00 AM MST&lt;br /&gt;
|CoinDesk Article&lt;br /&gt;
|CoinDesk reports on the MyAlgo wallet exploit.&lt;br /&gt;
|-&lt;br /&gt;
|March 6th, 2023 3:35:00 PM MST&lt;br /&gt;
|Funds Still Draining&lt;br /&gt;
|Funds are reportedly still being actively drained from MyAlgo wallets.&lt;br /&gt;
|-&lt;br /&gt;
|March 9th, 2023 11:56:33 AM MST&lt;br /&gt;
|Reddit Post&lt;br /&gt;
|A Reddit post advises against the typical strategy of buying and holding cryptocurrencies long-term, citing the MyAlgo wallet exploit as one potential pitfall with that strategy.&lt;br /&gt;
|-&lt;br /&gt;
|March 18th, 2023 9:01:42 AM MDT&lt;br /&gt;
|Reddit Thread&lt;br /&gt;
|Another Reddit thread is posted by a user concerned about the exploit still not having been determined yet. This user only lost 500 ALGO, however their faith in ALGO is permanently shaken by the experience.&lt;br /&gt;
|-&lt;br /&gt;
|March 18th, 2023 12:17:25 PM MDT&lt;br /&gt;
|Medium Post&lt;br /&gt;
|A medium post is published by CoinSpect to address several rumours and false narratives around the method of exploit.&lt;br /&gt;
|-&lt;br /&gt;
|April 21st, 2023 8:54:00 AM MDT&lt;br /&gt;
|Final Report Tweet&lt;br /&gt;
|Halborn reports on their investigation and MyAlgo shares a final tweet report about the reported exploit, which is apparently traced to a CDN exploit.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited?&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
$9.6m or $9.2m&lt;br /&gt;
&lt;br /&gt;
The total amount lost has been estimated at $9,600,000 USD.&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;reddit-12842&amp;quot;&amp;gt;[https://www.reddit.com/r/CryptoCurrency/comments/11n0emz/just_buying_your_crypto_and_then_forgetting_about/ https://www.reddit.com/r/CryptoCurrency/comments/11n0emz/just_buying_your_crypto_and_then_forgetting_about/] (Mar 9, 2023)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;coindesk-12843&amp;quot;&amp;gt;[https://www.coindesk.com/business/2023/02/28/algorand-wallet-myalgo-struck-by-96m-exploit/ Algorand Wallet MyAlgo Advises Users to Withdraw Funds After $9.6M Exploit] (Jan 18, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;reddit-12844&amp;quot;&amp;gt;[https://www.reddit.com/r/AlgorandOfficial/comments/11uqqex/i_lost_around_500_algo_in_the_myalgo_wallet_hack/ https://www.reddit.com/r/AlgorandOfficial/comments/11uqqex/i_lost_around_500_algo_in_the_myalgo_wallet_hack/] (Jan 18, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;redditold-12845&amp;quot;&amp;gt;[https://old.reddit.com/r/AlgorandOfficial/comments/11uqqex/i_lost_around_500_algo_in_the_myalgo_wallet_hack/ I lost around 500 ALGO in the myalgo wallet hack : AlgorandOfficial] (Jan 18, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cointelegraph-12846&amp;quot;&amp;gt;[https://cointelegraph.com/news/myalgo-users-urged-to-withdraw-as-cause-of-9-2m-hack-remains-unknown https://cointelegraph.com/news/myalgo-users-urged-to-withdraw-as-cause-of-9-2m-hack-remains-unknown] (Jan 18, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;myalgotwitter-12847&amp;quot;&amp;gt;[https://twitter.com/myalgo_/status/1630185695791706120 @myalgo_ Twitter] (Jan 18, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;halbornsecuritytwitter-12848&amp;quot;&amp;gt;[https://twitter.com/HalbornSecurity/status/1649426359016456192 @HalbornSecurity Twitter] (Jan 18, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;coinspectmedium-12849&amp;quot;&amp;gt;[https://coinspect.medium.com/addressing-rumors-and-recommendations-following-the-myalgo-wallet-hack-77b249a80d18 Addressing Rumors And Recommendations Following The Myalgo Wallet Hack] (Jan 18, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;wallet-12850&amp;quot;&amp;gt;[https://wallet.myalgo.com/new-account Algorand Wallet] (Jan 18, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;walletarchive-12851&amp;quot;&amp;gt;[https://web.archive.org/web/20221213115514/https://wallet.myalgo.com/new-account Algorand Wallet] (Jan 18, 2024)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>