Skip to content

Crypto Wallet Brute-Forcing Service Offered for a 30% Cut

Threat Service Report Wallet Brute Force Crypto Assets 70/30 Split Unverified

Crypto Wallet Brute-Forcing Service Offered for a 30% Cut

Supplier share70%
Operator share30%
Advertised availability24/7
Input types3

An actor using the handle "MrHuk" is advertising a cryptocurrency wallet-processing and brute-forcing service on an underground forum. The Russian-language post solicits seed phrases, private keys and logs, and claims the operator can identify and withdraw assets across EVM and non-EVM networks. The advertised revenue split is 70% to the material supplier and 30% to the operator.

The listing claims 24/7 availability, private proxies and network analysis, with support for tokens, unclaimed airdrops, staking, vesting, farming, liquidity pools and NFTs. It also advertises brute forcing using custom masks and templates. The screenshot contains promotional claims and contact details, not evidence of successful wallet access or asset withdrawals.

Post details

Actor"MrHuk"
ServiceCrypto wallet processing and brute forcing
Source languageRussian
Requested inputsSeed phrases, private keys and logs
Revenue split70% supplier / 30% operator
Fixed priceNot specified
Availability24/7, as advertised
Report date

What the post claims

  • Processes seed phrases, private keys and logs
  • Accepts material in any volume, as advertised
  • Claims coverage across all EVM and non-EVM networks
  • Locates balances and tokens for withdrawal
  • Searches for hidden assets and unclaimed airdrops
  • Handles staking, vesting, farming and liquidity pools
  • Handles NFTs, including NFT staking and marketplaces
  • Interacts with smart contracts
  • Uses individual private proxies and network analysis
  • Advertises brute forcing with custom masks and templates
  • Advertises 24/7 intake and processing
  • Offers a 70% supplier / 30% operator split
  • Requires exclusive handling until checks are complete
  • Rejects publicly shared collections, free dumps and exchange accounts
  • Says logs previously submitted to bots are likely to be rejected

Screenshots

Supplied screenshot of the service advertisement, including claimed capabilities, cooperation terms and contact identifiers.

IOCs & contact identifiers

Identifiers visible in the source material. These contact identifiers support correlation and do not, on their own, establish compromise.

TypeIdentifierSource
Actor handleMrHukScreenshot 1
Telegram handle@Mr_hukScreenshot 1
Tox IDE44C7F75CEB1E9298E593B8B81E5C8702A90CFD6B5EF0D37CE9A61DB139FBD44545D6EBF2600Screenshot 1

No Session ID, malware hash, attacker-controlled IP address or victim organization domain is visible. The Telegram handle and Tox ID are presented as contact identifiers, not linked destinations. URLs to any data will always be blurred out, but are available to subscribers on the threat feed or ransomware feed.

Mapped techniques

These analytical mappings relate the advertised behavior to MITRE ATT&CK. They describe claimed or potential capabilities, not observed execution. The source does not show how the submitted seed phrases, private keys or logs were obtained.

  • Credential Access T1110 Brute Force Claimed The actor advertises wallet brute forcing with custom masks and templates. This is a broad mapping of the advertised behavior; the screenshot does not establish the credential target, method, success rate or a specific sub-technique.
  • Impact T1657 Financial Theft Claimed The advertised discovery and withdrawal of assets from supplied wallet material could enable financial theft if performed without the wallet owner's authorization. No completed theft or transfer is demonstrated.

Potential impact

If the service functions as advertised and receives compromised wallet material, it could facilitate unauthorized access to cryptocurrency assets and their withdrawal. The claimed attention to staking, vesting, NFTs and other on-chain positions could extend the potential exposure beyond readily visible wallet balances. The revenue-sharing arrangement could incentivize third parties to supply compromised material. No victim count, affected organization or financial loss is established by this screenshot.

Status Unverified

Dark Web Informer has not independently verified the actor's identity, technical capabilities, network coverage, availability or claimed revenue-sharing terms. The post provides no transaction hashes, wallet addresses, successful brute-force results or independent customer evidence. A listing tag mentions bypassing automatic withdrawals, but no mechanism is shown. The source does not establish ownership or authorization for any submitted wallet material, and its relative timestamp does not establish an exact publication date.

Dark Web Informer

Latest