Three iToken Engineers Sentenced for 3 Years Each for Stealing 27,622 Digital Wallet Keys
Three frontend development engineers, Liu, Zhang 1, and Dong 2, were sentenced to three years in prison each for conspiring to implant a "backdoor" in the iToken APP application package. The incident occurred between March and May 2023, during which the engineers illegally obtained digital wallet private keys and mnemonic phrases from users. These data were then uploaded to a pre-built VPS backend server database corresponding to a designated domain name and subsequently downloaded to a local server.
The total number of mnemonics and private keys illegally obtained was 27,622 and 10,203 respectively, both deduplicated. These mnemonics and private keys were used to generate 19,487 unique digital wallet addresses. Liu was responsible for writing the request logic code, Zhang 1 for setting up the VPS and database, and uploading on the iToken Android end, while Dong 2 handled domain name purchase, encrypted user private keys, and uploading on the iToken iOS end.
Upon being taken into custody, all three defendants confessed to their criminal activities. The court found that their actions constituted the crime of illegally obtaining computer information system data, which is a violation of state regulations. The public prosecutor's accusations were established, leading to the sentencing of the three defendants to three years in prison and a fine of RMB 30,000 each. Additionally, they are prohibited from engaging in network security management, network operation, and related work within three years after the completion of their sentence.
This case highlights the importance of network security and the potential risks associated with digital wallets. The actions of these engineers not only violated the trust of users but also underscored the need for stringent security measures in the development and management of financial applications. The sentencing serves as a deterrent to similar activities and emphasizes the legal consequences of such actions.




Comentarios
Aún no hay comentarios