{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-282m-in-bitcoin-and-litecoin-stolen-from-a-holder-via-social-engineering"},"incident":{"slug":"2026-282m-in-bitcoin-and-litecoin-stolen-from-a-holder-via-social-engineering","title":"$282M in Bitcoin and Litecoin stolen from a holder via social engineering","date":"2026-01-10","date_precision":"day","year":2026,"victim_org":"Unnamed cryptocurrency holder","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Tech Support Scam","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Cryptocurrency Theft"],"loss_usd":282000000,"loss_kind":"direct_loss","loss_note":"USD value at time of theft of 1,459 BTC and 2.05 million LTC; no recovery reported.","records_affected":null,"threat_actor":null,"summary":"On 10 January 2026 an attacker drained 1,459 BTC and 2.05 million LTC, worth roughly $282 million, from a single hardware-wallet holder in what on-chain investigators described as a social engineering attack. Most proceeds were swapped into Monero across multiple instant exchanges, driving a 70 percent XMR price rise over four days, with some Bitcoin bridged out via Thorchain. Investigator ZachXBT said there was no indication of North Korean involvement.","how_it_worked":"Reporting characterised the theft as a support-impersonation social engineering attack of the kind that has become the dominant loss driver in crypto: the attacker poses as an employee of a wallet or exchange provider, builds trust with the holder, and persuades them to hand over a seed phrase, sign a malicious transaction or surrender login details. The theft came days after hardware-wallet maker Ledger disclosed a breach exposing customer names and contact details, the kind of list that makes such calls credible. The victim has not been identified and the exact pretext was not published.","lessons":"No legitimate wallet or exchange support agent ever needs a seed phrase or a remote-access session; large holdings belong behind multi-signature approval with an out-of-band co-signer.","confidence":"Reported","sources":[{"title":"Hacker steals $282 million crypto from a victim in social-engineering attack","url":"https://www.coindesk.com/business/2026/01/16/hacker-steals-usd282-milion-in-hardware-wallet-social-engineering-attack","publisher":"CoinDesk"},{"title":"Crypto User Loses $282 Million in Bitcoin and Litecoin to Social Engineering Scam","url":"https://bravenewcoin.com/insights/crypto-user-loses-282-million-in-bitcoin-and-litecoin-to-social-engineering-scam","publisher":"Brave New Coin"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-282m-in-bitcoin-and-litecoin-stolen-from-a-holder-via-social-engineering"}}