{"investigation":{"slug":"wintermute","entity_name":"Wintermute","trust_score":38,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Wintermute is a London-headquartered algorithmic trading firm and cryptocurrency market maker founded in 2017 by Evgeny Gaevoy. On September 20, 2022, the firm's DeFi operations were exploited for approximately $160 million after an attacker leveraged a known cryptographic vulnerability in the Profanity vanity address tool to compromise Wintermute's admin private key. The stolen funds were never recovered, though the firm remained solvent, repaid its outstanding DeFi loans, and has continued operating and expanding into U.S. markets.","sections":[{"content":"Wintermute was founded in 2017 by Evgeny Gaevoy, who previously ran Optiver's European ETF high-frequency trading and OTC business. The firm is headquartered in London with offices in Singapore and New York City. Wintermute operates as an algorithmic market maker and liquidity provider across more than 60 centralized and decentralized exchanges, trading billions of dollars in digital assets daily. Its business lines include DeFi market making, over-the-counter (OTC) trading, and centralized exchange liquidity provision. Prior to the September 2022 exploit, Wintermute had been named the official DeFi market maker for the Tron network, reflecting its standing as a Tier-1 institutional market maker in the crypto industry. In 2024, Wintermute's OTC volumes grew 313%, and in 2025 the firm expanded into the United States with a New York office.","heading":"Background","sources":[{"url":"https://www.coindesk.com/business/2022/09/20/crypto-market-maker-wintermute-hacked-for-160m-says-ceo","name":"","type":"other","credibility":3},{"url":"https://www.wintermute.com/insights/market-color/reports/wintermute-otc-2024-in-review-2025-outlook","name":"","type":"other","credibility":3},{"url":"https://www.tradersmagazine.com/featured_articles/wintermute-expands-into-u-s-makes-new-policy-hire/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On September 15, 2022, blockchain infrastructure firm 1inch Network published a security disclosure revealing a severe cryptographic vulnerability in Profanity, a popular open-source Ethereum vanity address generator. Profanity seeded its cryptographically pseudo-random number generator (CPRNG) with only a 32-bit value rather than the 256-bit value required for Ethereum private key security. This meant that any address generated by Profanity was theoretically susceptible to brute-force private key recovery given sufficient GPU compute resources — 1inch estimated all seven-character vanity addresses could be cracked within 50 days using 1,000 GPUs. Wintermute had used Profanity in combination with an internal tool to generate hot wallet addresses containing many leading zeroes, intended for gas cost optimization rather than aesthetics. Following the 1inch disclosure, Wintermute transferred all ETH out of the compromised hot wallet. However, the firm critically failed to revoke the hot wallet's administrative permissions over its DeFi vault smart contract. On September 20, 2022, an attacker — having reconstructed the hot wallet's private key by exploiting the Profanity flaw — used the retained admin access to call Wintermute's vault contract and drain approximately $160 million across roughly 90 different ERC-20 tokens. Assets stolen included approximately $118.4 million in stablecoins (USDC, USDT, DAI, BUSD), 671 WBTC (approximately $13 million at the time), and 6,928 WETH (approximately $9.4 million at the time). The attacker subsequently routed approximately $114 million in stablecoins through Curve Finance's 3pool, complicating potential asset freezes by issuers. Wintermute CEO Evgeny Gaevoy confirmed on-chain in a tweet the same day: 'We've been hacked for about $160M in our defi operations. Cefi and OTC operations are not affected.' Gaevoy offered the attacker a 10% white-hat bounty — $16 million — to return the remainder, but the offer was not taken up. An unverified allegation subsequently circulated on social media from a researcher calling himself Librehash that the hack may have been an inside job, based on alleged anomalous on-chain transactions. Blockchain security firm BlockSec publicly assessed this theory as insufficiently supported, and Wintermute denied the allegations. CertiK's independent post-mortem attributed the exploit exclusively to the Profanity vulnerability.","heading":"The Profanity Vanity Address Exploit","sources":[{"url":"https://blog.1inch.com/a-vulnerability-disclosed-in-profanity-an-ethereum-vanity-address-tool/","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-wintermute-hack-september-2022","name":"","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/uGiY0j3hwOzQOMcDPGoz9-wintermute-hack","name":"","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/cyber-sleuth-alleges-160m-wintermute-hack-was-an-inside-job","name":"","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2022/09/20/crypto-market-maker-wintermute-hacked-for-160m-says-ceo","name":"","type":"other","credibility":3},{"url":"https://beincrypto.com/1inch-severe-vulnerability-ethereum-vanity-address-tool-risks-millions-dollars/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On-chain data identified the attacker's wallet address as 0xe74b28c2eAe8679e3cCc3a94d5d0dE83CCB84705. Post-exploit, on-chain sleuth ZachXBT tracked the wallet and found it contained approximately $9 million in ETH and $38 million in ERC-20 tokens in the months following the attack, suggesting a large portion of the stolen assets remained unspent. The attacker routed approximately $114 million in stablecoins through Curve Finance's 3pool liquidity contract, a strategy consistent with attempting to blend assets with the pool's existing $869 million TVL and pre-empt issuer freeze actions. Specific on-chain conversions included: 9,470,755 BUSD converted to DAI via Curve.fi; 61,350,986 USDC converted via Curve 3pool; and 23,609,070 DAI converted to USDT via Curve.fi. The exploit transaction itself was executed against Wintermute's vault smart contract using the compromised admin EOA. The attack vector — compromised externally owned account (EOA) calling a privileged vault function — was confirmed by multiple independent security researchers including Halborn, CertiK, Numen Cyber, and QuillAudits. No evidence of smart contract logic flaws was found in Wintermute's vault code; the vulnerability was entirely attributable to the compromised private key.","heading":"On-Chain Evidence","sources":[{"url":"https://www.numencyber.com/an-analysis-of-wintermutes-usd160-million-hacking/","name":"","type":"other","credibility":3},{"url":"https://www.merklescience.com/blog/hack-track-analysis-of-wintermute-attack","name":"","type":"other","credibility":3},{"url":"https://immunebytes.com/blog/wintermute-crypto-exchange-hack-sep-20-2022-detailed-analysis/","name":"","type":"other","credibility":3},{"url":"https://quillaudits.medium.com/wintermutes-160m-exploit-analysis-quillaudits-f1dbd217b9f9","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Despite suffering a $160 million loss, Wintermute CEO Evgeny Gaevoy publicly stated that the firm remained solvent with equity exceeding the hacked amount by more than twice over. At the time of the hack, Wintermute had approximately $200 million in outstanding DeFi lending obligations, including a $96 million loan on TrueFi protocol and additional exposure to Maple Finance ($75 million in USDC and WETH) and Clearpool ($22.4 million). On October 14, 2022 — one day before its deadline — Wintermute repaid its $96 million TrueFi loan in full, with interest, demonstrating continued liquidity despite the hack. The firm subsequently repaid its remaining DeFi obligations. The stolen $160 million was never returned by the attacker; the 10% white-hat bounty offer went unclaimed. Wintermute did not publicly announce any law enforcement action or on-chain attribution identifying the attacker. Following recovery, the firm continued normal operations, grew its OTC business substantially in 2023 and 2024, and in early 2025 opened a U.S. office in New York City, initially focused on OTC and derivatives offerings. In 2025, Wintermute submitted formal feedback to the SEC Crypto Task Force regarding the classification of network tokens and the regulatory treatment of tokenized securities.","heading":"Recovery","sources":[{"url":"https://www.coindesk.com/business/2022/10/14/crypto-market-maker-wintermute-pays-off-96m-truefi-debt-weeks-after-being-hacked","name":"","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/wintermute-repays-92m-truefi-loan-on-time-despite-suffering-160m-hack","name":"","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2022/09/20/hacked-crypto-market-maker-wintermute-has-200m-in-outstanding-defi-debt","name":"","type":"other","credibility":3},{"url":"https://www.sec.gov/files/ctf-written-wintermute-11172025.pdf","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"The Wintermute exploit illustrates several systemic operational security risks relevant to DeFi market participants. First, the use of third-party vanity address generation tools for operationally critical wallets — including those holding admin privileges — represents a category of key management risk distinct from smart contract auditing. The Profanity vulnerability had been publicly disclosed by 1inch five days before the Wintermute exploit; the firm had partially mitigated the risk by moving ETH, but failed to complete remediation by revoking admin privileges, a step that would have blocked the attack. Second, the inside-job allegation, while assessed as unsubstantiated by multiple independent security firms, highlights the opacity of private key management practices at centralized trading firms that operate in DeFi contexts. Third, the attacker's use of Curve Finance stablecoin pools to obscure stolen assets points to the continued difficulty of freezing large stablecoin flows once they enter deep liquidity pools, even for regulated issuers such as Circle (USDC). Wintermute's post-hack conduct — rapid public disclosure, solvency assertion backed by loan repayment, and continuation of operations — is consistent with a solvent firm managing a serious operational security failure rather than evidence of fraud. The firm has no known regulatory enforcement actions, lawsuits, or government sanctions as of May 2026. However, the $160 million loss was not recovered and no attacker was publicly identified or prosecuted. The risk to counterparties is assessed as reduced relative to the immediate post-hack period, but the incident remains a material part of the firm's history and underscores that institutional DeFi operations carry private key management risks not fully addressed by smart contract auditing alone.","heading":"Risk Assessment","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-wintermute-hack-september-2022","name":"","type":"other","credibility":3},{"url":"https://safeheron.com/blog/how-profanity-caused-wintermute-to-lose-160m/","name":"","type":"other","credibility":3},{"url":"https://www.theblock.co/post/170359/1inch-claims-potential-exploit-on-profanity-generated-ethereum-addresses","name":"","type":"other","credibility":3},{"url":"https://blockbytes.com/2023/02/13/crypto-casefiles-wintermute-hack/","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2017","event":"Wintermute founded in London by Evgeny Gaevoy, formerly of Optiver's European ETF desk.","source":"","date_original":"2017-01-01"},{"date":"2022-09-15","event":"1inch Network publicly discloses a severe cryptographic vulnerability in Profanity, the Ethereum vanity address generator, recommending all users immediately transfer funds away from Profanity-generated addresses.","source":""},{"date":"2022-09-15","event":"Profanity vulnerability exploited by separate actors draining approximately $3.3 million from other wallets, establishing proof of exploitability before the Wintermute attack.","source":""},{"date":"2022-09-20","event":"Attacker uses a reconstructed private key from a Profanity-generated Wintermute admin wallet to drain approximately $160 million from Wintermute's DeFi vault across roughly 90 ERC-20 token types.","source":""},{"date":"2022-09-20","event":"CEO Evgeny Gaevoy publicly discloses the hack via Twitter, confirms solvency, and characterizes the incident as a potential white-hat event, offering the attacker a 10% bounty to return funds.","source":""},{"date":"2022-09-20","event":"Attacker routes approximately $114 million in stablecoins through Curve Finance 3pool to complicate asset freezes.","source":""},{"date":"2022-09-27","event":"Researcher 'Librehash' alleges via social media that the hack was an inside job based on alleged anomalous pre-hack transactions; Wintermute denies the allegation. BlockSec assesses the inside-job theory as unsubstantiated.","source":""},{"date":"2022-10-14","event":"Wintermute repays its $96 million TrueFi DeFi loan one day before deadline, demonstrating continued solvency following the hack.","source":""},{"date":"2023","event":"Stolen $160 million remains unrecovered; attacker's 10% white-hat bounty offer unclaimed. Wintermute resumes normal operations.","source":"","date_original":"2023-01-01"},{"date":"2025-02","event":"Wintermute opens U.S. headquarters in New York City, expanding OTC and derivatives offerings.","source":"","date_original":"2025-02-01"},{"date":"2025-09-03","event":"Wintermute submits formal feedback to the SEC Crypto Task Force, arguing network tokens should not be classified as securities.","source":""}],"sources_used":[{"url":"https://www.coindesk.com/business/2022/09/20/crypto-market-maker-wintermute-hacked-for-160m-says-ceo","name":"","type":"other","archive_url":"http://web.archive.org/web/20260729051215/https://www.coindesk.com/business/2022/09/20/crypto-market-maker-wintermute-hacked-for-160m-says-ceo","credibility":3,"archive_timestamp":"2026-07-29T05:12:15+00:00"},{"url":"https://www.wintermute.com/insights/market-color/reports/wintermute-otc-2024-in-review-2025-outlook","name":"","type":"other","archive_url":"http://web.archive.org/web/20260512060746/https://www.wintermute.com/insights/market-color/reports/wintermute-otc-2024-in-review-2025-outlook","credibility":3,"archive_timestamp":"2026-05-12T06:07:46+00:00"},{"url":"https://www.tradersmagazine.com/featured_articles/wintermute-expands-into-u-s-makes-new-policy-hire/","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://blog.1inch.com/a-vulnerability-disclosed-in-profanity-an-ethereum-vanity-address-tool/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260508164329/https://blog.1inch.com/a-vulnerability-disclosed-in-profanity-an-ethereum-vanity-address-tool/","credibility":3,"archive_timestamp":"2026-05-08T16:43:29+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-wintermute-hack-september-2022","name":"","type":"other","archive_url":"http://web.archive.org/web/20260609214725/https://www.halborn.com/blog/post/explained-the-wintermute-hack-september-2022","credibility":3,"archive_timestamp":"2026-06-09T21:47:25+00:00"},{"url":"https://www.certik.com/resources/blog/uGiY0j3hwOzQOMcDPGoz9-wintermute-hack","name":"","type":"other","archive_url":"https://web.archive.org/web/20260830045441/https://www.certik.com/blog/uGiY0j3hwOzQOMcDPGoz9-wintermute-hack","credibility":3,"archive_timestamp":"2026-08-30T04:54:41+00:00"},{"url":"https://cointelegraph.com/news/cyber-sleuth-alleges-160m-wintermute-hack-was-an-inside-job","name":"","type":"other","archive_url":"http://web.archive.org/web/20250914040040/https://cointelegraph.com/news/cyber-sleuth-alleges-160m-wintermute-hack-was-an-inside-job","credibility":3,"archive_timestamp":"2025-09-14T04:00:40+00:00"},{"url":"https://beincrypto.com/1inch-severe-vulnerability-ethereum-vanity-address-tool-risks-millions-dollars/","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.numencyber.com/an-analysis-of-wintermutes-usd160-million-hacking/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260610031240/https://www.numencyber.com/an-analysis-of-wintermutes-usd160-million-hacking/","credibility":3,"archive_timestamp":"2026-06-10T03:12:40+00:00"},{"url":"https://www.merklescience.com/blog/hack-track-analysis-of-wintermute-attack","name":"","type":"other","archive_url":"http://web.archive.org/web/20260610213211/https://www.merklescience.com/blog/hack-track-analysis-of-wintermute-attack","credibility":3,"archive_timestamp":"2026-06-10T21:32:11+00:00"},{"url":"https://immunebytes.com/blog/wintermute-crypto-exchange-hack-sep-20-2022-detailed-analysis/","name":"","type":"other","archive_url":"http://web.archive.org/web/20251216142559/https://immunebytes.com/blog/wintermute-crypto-exchange-hack-sep-20-2022-detailed-analysis/","credibility":3,"archive_timestamp":"2025-12-16T14:25:59+00:00"},{"url":"https://quillaudits.medium.com/wintermutes-160m-exploit-analysis-quillaudits-f1dbd217b9f9","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.coindesk.com/business/2022/10/14/crypto-market-maker-wintermute-pays-off-96m-truefi-debt-weeks-after-being-hacked","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cointelegraph.com/news/wintermute-repays-92m-truefi-loan-on-time-despite-suffering-160m-hack","name":"","type":"other","archive_url":"http://web.archive.org/web/20260214131034/https://cointelegraph.com/news/wintermute-repays-92m-truefi-loan-on-time-despite-suffering-160m-hack","credibility":3,"archive_timestamp":"2026-02-14T13:10:34+00:00"},{"url":"https://www.coindesk.com/business/2022/09/20/hacked-crypto-market-maker-wintermute-has-200m-in-outstanding-defi-debt","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.sec.gov/files/ctf-written-wintermute-11172025.pdf","name":"","type":"other","archive_url":"http://web.archive.org/web/20260327165832/https://www.sec.gov/files/ctf-written-wintermute-11172025.pdf","credibility":3,"archive_timestamp":"2026-03-27T16:58:32+00:00"},{"url":"https://safeheron.com/blog/how-profanity-caused-wintermute-to-lose-160m/","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.theblock.co/post/170359/1inch-claims-potential-exploit-on-profanity-generated-ethereum-addresses","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://blockbytes.com/2023/02/13/crypto-casefiles-wintermute-hack/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260611010047/https://blockbytes.com/2023/02/13/crypto-casefiles-wintermute-hack/","credibility":3,"archive_timestamp":"2026-06-11T01:00:47+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:49.302874+00:00","updated_at":"2026-08-30T05:14:13.304486+00:00"}}