Case Studies
Real operations, real numbers. More cases will be disclosed when the time is right.
SaleSmartly 0day → Adspower Wallet Theft
Discovered a critical vulnerability in the SaleSmartly platform. A single exploit chain yielded $6M+ in extracted funds. Full closed loop from vulnerability discovery to access acquisition to fund extraction.
Technical breakdown (first full-chain disclosure)
- SaleSmartly provides live-chat systems for gambling sites
- Tested the file upload function in the chat feature
- Burp Suite revealed encrypted traffic — reversed the frontend JS encryption to extract the Alibaba Cloud upload policy
- Upload allowed cross-path overwrites — used traffic analysis to find real domains behind the storage bucket
- Confirmed the domains belonged to SaleSmartly assets — injected JS probes
- Observed massive volumes of AdsPower User-Agent requests
- Sniffed AdsPower traffic — found it loads the overwritten JS during the startup splash phase
- AdsPower is Electron-based — injected Node.js code to control compromised PCs at scale
- AdsPower is widely used by grey-market, cross-border, airdrop farming, and Web3 users — extracted mnemonics and controlled screens to move funds
- Web3 community became aware — paused operations temporarily
- Adapted an OKX theft scheme — leveraged AdsPower's built-in wallet update RPC to replace extensions with malicious versions
- When users opened their wallets, the malicious code fired — private keys exfiltrated, funds drained
$ADS Token Launch
Launched the $ADS token leveraging crypto infrastructure access — market cap peaked at $4.5M. Had no experience with airdrops or Web3 mechanics, so found someone online to help with the token launch. Holdings briefly hit $300K but never sold — airdropped most of it to the community instead. Net profit under $10K, but the experience was worth it.
OTC Platform CRM Takeover
Gained control of CRM systems at OTC platforms including Hugos — extracted approximately $250K.
Technical breakdown
- Compromised production servers
- Logged into user accounts, initiated withdrawals — ~$250K extracted
- Bypassed POI and POA verification controls
- Negotiated a 0.7 BTC ransom with *** — once a deal is struck, I never sell that vendor's data. That's my line.
Gambling Platform Payment Gateway
Compromised a four-party payment gateway interface used by a gambling platform — siphoned ¥300K RMB.
More cases will be published when the time is right…