Mark RadarMARK RADAR
About
EN
Sign in
Event File CRYPTO USD Coin (USDC)

Bofur Capital Loses $2 Million in Address-Poisoning Attack

1 reports · First detected 2026-08-23 · Last active 2026-08-23

Address poisoning exploits a wallet user’s reliance on abbreviated transaction records. An attacker sends a small “dust” transfer from a spoofed address whose opening and closing characters resemble a legitimate destination, hoping the victim later copies it without checking the full string. The $2 million loss at Bofur Capital highlights how a routine operational mistake can bypass smart-contract safeguards and expose even institutional crypto users to irreversible transfers.

Bofur Capital withdrew funds from decentralized lending protocol Compound and then mistakenly sent about $2 million to an address planted by the attacker through an earlier dust transaction. The attacker quickly converted all of the stolen USDC into DAI, reducing the risk that the assets could be frozen by a centralized stablecoin issuer. As of Aug. 23, 2026, the funds had not been transferred to a cryptocurrency mixer.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)