Three programmers planted a backdoor into the iToken wallet to steal the wallet private key, illegally obtaining a total of 27,622 mnemonic words
On April 16, three programmers were sentenced to three years in prison and fined 30,000 yuan each for planting a "backdoor" in the iToken wallet application to illegally obtain the user's digital wallet private key and mnemonic.
After identification, the three people illegally obtained a total of 27,622 mnemonic words and 10,203 private keys, and successfully converted 19,487 digital wallet addresses. The three defendants were responsible for writing the request logic code, setting up a backend server, and purchasing domain names and encrypting private keys.
The court also ruled that the three were prohibited from engaging in cyber security management and network operation and related work within three years after the execution of the sentence.