Malaysia man loses 3M in suspected crypto wallet hack

by Adrian Russell
0 comments



Malaysian police have launched an investigation into a suspected cryptocurrency wallet hack after a man in Teluk Intan reported losing approximately RM12.47 million ($3.05 million) in digital assets through transactions he did not authorize.

Summary

  • Malaysian police are investigating suspected unauthorized cryptocurrency transfers worth RM12.47 million, approximately $3.05 million reportedly.
  • The victim discovered missing digital assets around 1 p.m. on October 9 in Teluk Intan.
  • Perak police enlisted Bukit Aman commercial crime investigators to trace transfers across the relevant blockchain.
  • Authorities opened an investigation under Section 420 of Malaysia’s Penal Code, which addresses criminal cheating.
  • Police have not identified the suspected attacker, compromised wallet, stolen cryptocurrencies, or technical intrusion method.

According to Malaysian national news agency Bernama, Perak police chief Mohd Alwi Zainal Abidin confirmed on October 10 that the victim discovered the missing cryptocurrency at approximately 1 p.m. on October 9. Police are working with the Bukit Aman Commercial Crime Investigation Department’s cryptocurrency unit to identify the people responsible and trace the transferred assets.

The case is being investigated under Section 420 of Malaysia’s Penal Code, which covers cheating offenses. Authorities have not established how the wallet was accessed or identified the individuals involved.

Malaysia police investigate $3 million crypto wallet theft

The suspected theft came to light when the victim noticed that cryptocurrency had left his digital wallet without his knowledge or permission.

According to Perak police, the man was in Teluk Intan when he discovered the unauthorized transfers on Friday, October 9. Bernama identified the victim as a 38-year-old man, while a separate report by The Star described him as 39. Authorities have not publicly clarified the difference.

The victim’s name has not been disclosed in the reports reviewed. Police said their initial examination established that the missing assets had been transferred through a blockchain network.

However, investigators did not identify the cryptocurrency involved, the type of wallet used or the blockchain on which the transfers occurred.

The exact number of transactions was not disclosed. Authorities have not confirmed whether the victim used a self-custody wallet, a hardware wallet or a wallet associated with a cryptocurrency exchange. The distinction remains unresolved because investigators have not explained how unauthorized access may have occurred.

Perak police chief Mohd Alwi Zainal Abidin said: “Preliminary investigation found that the transaction involved the transfer of crypto assets through a blockchain network.”

The statement confirmed the transaction mechanism but did not establish whether the incident resulted from phishing, compromised recovery information, malicious software or another form of unauthorized access. The reported loss of RM12.47 million represents the estimated value of the missing cryptocurrency. Police have not published a breakdown showing the amounts held in individual assets.

Investigators begin tracing stolen cryptocurrency

Following the complaint, Perak police requested assistance from specialists within Malaysia’s national commercial crime investigation department. The Bukit Aman cryptocurrency unit is helping investigators examine the movement of the missing assets and identify any individuals connected to the transfers.

According to the police chief, investigators are examining transaction records to establish where the cryptocurrency moved after leaving the victim’s wallet.

In its October 10 coverage, Malaysian public broadcaster RTM confirmed that the cryptocurrency unit was assisting the investigation. Blockchain transactions can provide records of transfers between wallet addresses, although the public visibility of those records depends on the blockchain and assets involved.

In this case, police have not released wallet addresses, transaction identifiers or details of any cryptocurrency exchanges involved.

Investigators have not announced whether the assets remain in identifiable wallets or have been transferred through other services. No cryptocurrency freeze, seizure or recovery has been confirmed.

The investigation is proceeding under Section 420 of the Penal Code, which addresses cheating and dishonestly inducing the delivery of property. Malaysian authorities said a conviction under the provision can carry imprisonment ranging from one to 10 years, whipping and a fine.

The penalties concern individuals convicted of the offense and do not mean that police have established criminal responsibility in this case. No arrests, formal charges or court proceedings connected to the reported theft were identified in the October 10 police statements.

Malaysian police warn against phishing and stolen recovery phrases

While examining the missing funds, Perak police issued advice to cryptocurrency holders about protecting their digital wallets. Mohd Alwi warned users against opening suspicious links or sharing sensitive account information with other people.

According to an October 10 report by Utusan Malaysia, the police chief specifically identified recovery phrases, private keys and passwords as information that wallet owners should protect.

A recovery phrase allows users to restore access to a cryptocurrency wallet. Anyone who obtains the phrase may be able to access the associated assets without possessing the original device.

Private keys serve a similar security function by authorizing cryptocurrency transactions. Police advised wallet owners to regularly examine transaction records and review applications connected to their accounts.

The guidance included separating wallets used for long-term storage from those used for everyday transactions. Authorities recommended that anyone who suspects a device has been compromised stop using it immediately. Affected users were advised to preserve digital evidence, contact relevant service providers through official channels and file a police report.

These precautions were issued as general cybersecurity advice. Police have not confirmed that phishing or recovery phrase exposure caused the Teluk Intan incident.

Separately, cryptocurrency security researchers have documented attacks in which malicious applications obtain permission to move assets from wallets.

An October 5 investigation into malicious USDG wallet approvals examined transactions that allegedly gave attackers broad spending permissions before assets were transferred.

Security firm Salus found that malicious permit signatures could authorize spending and execute transfers within the same blockchain transaction.

The Revenue-related incident involved a separate attack and has not been linked to the suspected Malaysian theft.

Crypto wallet investigations continue across the region

Unauthorized wallet transfers have prompted investigations by cryptocurrency companies and law enforcement agencies in several jurisdictions.

In July 2026, payment services company Triple-A disclosed that attackers had gained unauthorized access to its corporate cryptocurrency wallets.

The company confirmed that company-owned digital assets were stolen but stated that customer funds had not been affected.

Blockchain investigators initially estimated the losses at approximately $11.8 million.

Triple-A said it was working with cybersecurity specialists and Singapore police to investigate the incident and trace the missing cryptocurrency.

A separate July Ethereum wallet phishing case involved a user who reportedly lost almost $1 million after approving a malicious transaction.

The incident was linked to a fraudulent authorization that allowed cryptocurrency to be transferred from the affected wallet.

Those cases involved independently reported security incidents and do not establish how the Malaysian victim’s assets disappeared.

Back in Malaysia, authorities have continued investigating other digital payment operations connected to suspected financial crime.

On October 2, Bernama reported that Perak police arrested 13 people suspected of operating a payment network using Alipay accounts to move proceeds from online gambling scams.

The suspects included five Malaysians and eight Myanmar nationals arrested during raids on September 28.

Police alleged that the group recruited individuals to provide personal information for opening payment accounts, which were subsequently used to process suspected criminal proceeds.

The Alipay investigation is separate from the Teluk Intan cryptocurrency wallet case.

For the reported RM12.47 million theft, the Bukit Aman cryptocurrency unit remains responsible for assisting Perak investigators with tracing the transactions.

The latest police statement did not identify a suspect or provide a recovery timetable, and authorities have not announced whether any of the missing assets have been located.



Source link

Related Posts

Leave a Comment