Summary
Wintermute is a London-headquartered algorithmic trading firm and cryptocurrency market maker founded in 2017 by Evgeny Gaevoy. On September 20, 2022, the firm's DeFi operations were exploited for approximately $160 million after an attacker leveraged a known cryptographic vulnerability in the Profanity vanity address tool to compromise Wintermute's admin private key. The stolen funds were never recovered, though the firm remained solvent, repaid its outstanding DeFi loans, and has continued operating and expanding into U.S. markets.
Connected Entities
1 entitiesTimeline(11 events)
2017-01-01
Wintermute founded in London by Evgeny Gaevoy, formerly of Optiver's European ETF desk.
2022-09-15
1inch Network publicly discloses a severe cryptographic vulnerability in Profanity, the Ethereum vanity address generator, recommending all users immediately transfer funds away from Profanity-generated addresses.
2022-09-15
Profanity vulnerability exploited by separate actors draining approximately $3.3 million from other wallets, establishing proof of exploitability before the Wintermute attack.
2022-09-20
Attacker uses a reconstructed private key from a Profanity-generated Wintermute admin wallet to drain approximately $160 million from Wintermute's DeFi vault across roughly 90 ERC-20 token types.
2022-09-20
CEO Evgeny Gaevoy publicly discloses the hack via Twitter, confirms solvency, and characterizes the incident as a potential white-hat event, offering the attacker a 10% bounty to return funds.
2022-09-20
Attacker routes approximately $114 million in stablecoins through Curve Finance 3pool to complicate asset freezes.
2022-09-27
Researcher 'Librehash' alleges via social media that the hack was an inside job based on alleged anomalous pre-hack transactions; Wintermute denies the allegation. BlockSec assesses the inside-job theory as unsubstantiated.
2022-10-14
Wintermute repays its $96 million TrueFi DeFi loan one day before deadline, demonstrating continued solvency following the hack.
2023-01-01
Stolen $160 million remains unrecovered; attacker's 10% white-hat bounty offer unclaimed. Wintermute resumes normal operations.
2025-02-01
Wintermute opens U.S. headquarters in New York City, expanding OTC and derivatives offerings.
2025-09-03
Wintermute submits formal feedback to the SEC Crypto Task Force, arguing network tokens should not be classified as securities.
Decision Log
- hash: 2dBNSyGvxMJTvMrQgAgzRNs6d1gr9AsU9sBd6czMwZtp
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:49 AM
last updated: 5/20/2026, 6:58:59 PM
avoid.net — verified advice for a post-truth world