PREMINT NFT Incident Analysis
ID: 93ca9cbf-561e-5d82-b5ab-5277675d68f7
STIX ID: report--93ca9cbf-561e-5d82-b5ab-5277675d68f7
Feed Name: CertiK Blog
Threat Score
At ~07:25 AM UTC a malicious JavaScript file hosted on a spoofed CDN was injected into premint.xyz, allowing attackers to drain NFTs from users who approved transactions; on-chain analysis links six exploiter EOAs which stole ~275 ETH (~$375k) worth of NFTs before consolidating proceeds (some transferred to 0x99Ae… and likely laundered via Tornado.Cash).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
