Skip to content

Case Studies

Real operations, real numbers. More cases will be disclosed when the time is right.

2024.8 – 2025.1$6M+

SaleSmartly 0day → Adspower Wallet Theft

Discovered a critical vulnerability in the SaleSmartly platform. A single exploit chain yielded $6M+ in extracted funds. Full closed loop from vulnerability discovery to access acquisition to fund extraction.

Technical breakdown (first full-chain disclosure)
  1. SaleSmartly provides live-chat systems for gambling sites
  2. Tested the file upload function in the chat feature
  3. Burp Suite revealed encrypted traffic — reversed the frontend JS encryption to extract the Alibaba Cloud upload policy
  4. Upload allowed cross-path overwrites — used traffic analysis to find real domains behind the storage bucket
  5. Confirmed the domains belonged to SaleSmartly assets — injected JS probes
  6. Observed massive volumes of AdsPower User-Agent requests
  7. Sniffed AdsPower traffic — found it loads the overwritten JS during the startup splash phase
  8. AdsPower is Electron-based — injected Node.js code to control compromised PCs at scale
  9. AdsPower is widely used by grey-market, cross-border, airdrop farming, and Web3 users — extracted mnemonics and controlled screens to move funds
  10. Web3 community became aware — paused operations temporarily
  11. Adapted an OKX theft scheme — leveraged AdsPower's built-in wallet update RPC to replace extensions with malicious versions
  12. When users opened their wallets, the malicious code fired — private keys exfiltrated, funds drained
GitHub: AdsPower Stealer →
2025.1Peak $4.5M

$ADS Token Launch

Launched the $ADS token leveraging crypto infrastructure access — market cap peaked at $4.5M. Had no experience with airdrops or Web3 mechanics, so found someone online to help with the token launch. Holdings briefly hit $300K but never sold — airdropped most of it to the community instead. Net profit under $10K, but the experience was worth it.

2025.12$250K

OTC Platform CRM Takeover

Gained control of CRM systems at OTC platforms including Hugos — extracted approximately $250K.

Technical breakdown
  1. Compromised production servers
  2. Logged into user accounts, initiated withdrawals — ~$250K extracted
  3. Bypassed POI and POA verification controls
  4. Negotiated a 0.7 BTC ransom with *** — once a deal is struck, I never sell that vendor's data. That's my line.
2026.3¥300K

Gambling Platform Payment Gateway

Compromised a four-party payment gateway interface used by a gambling platform — siphoned ¥300K RMB.

More cases will be published when the time is right…