Crypto market maker Wintermute says hackers stole $160M from its DeFi operations but the firm remains solvent; in total, 90 assets were stolen, most worth <$1M
- Crypto market making firm Wintermute has been hacked. — The firm maintains that it is solvent.
The BlockTim Copeland
Context & Ripple Effects
Wintermute had built its business around supplying liquidity to decentralized exchanges after a $20M Series B for its DeFi market-making operation. The theft therefore strikes a trading intermediary whose ability to keep quoting depends on the assets and counterparties behind its DeFi activity.
Follow-up coverage placed the stated solvency claim alongside $200M in outstanding DeFi debt, including a Tether loan from TrueFi. That makes the incident more than a loss event: it puts Wintermute's balance-sheet resilience under immediate counterparty scrutiny.
First-order effects
Wintermute must absorb the loss across 90 assets while maintaining the liquidity-provision activity on which its DeFi role depends; the firm says it remains solvent.
Wintermute's lenders and trading counterparties, including TrueFi, gain a concrete reason to reassess its ability to meet obligations as they come due.
Second-order effects
The reported debt exposure makes Wintermute's asset recovery and remaining liquidity relevant to DeFi credit counterparties, not only to the firm itself.
Other DeFi market makers and exchanges relying on Wintermute liquidity face greater incentive to review counterparty limits and wallet-security controls.
Third-order effects
Repeated thefts—after DeFi hacks accounted for more than 60% of crypto hack and theft volume in 2021—tie protocol security failures more directly to the creditworthiness of liquidity intermediaries.
If this pattern persists, DeFi liquidity provision will increasingly be evaluated as a balance-sheet and operational-security business, rather than solely a trading service.
The trend: DeFi is shifting toward treating security losses as counterparty-credit events because market makers and lenders are linked through on-chain liquidity and debt.
wintermute's address had 7 leading 0's according to @k06a's estimation, can brute for this in 50 days using 1000 GPUs the attacker was definitely a pro https://twitter.com/...
Wintermute was hacked for ~160m a few hours ago. I took a quick look and my best guess is that it was a hot wallet compromise due to the Profanity bug that was publicly disclosed a few weeks ago. https://twitter.com/...
Out of 90 assets that has been hacked only two have been for notional over $1 million (and none more than $2.5M), so there shouldn't be a major selloff of any sort. We will communicate with both affected teams asap
Oh no oh no oh no 70% of stolen funds ($114.3m) are 3pooliiing 13.6% in ETH & BTC Large holdings in other less liquid tkns (some of them pretty illiquid tbh) — don't be surprised if we see some 20-30% wicks... https://twitter.com/... https://twitter.com/...
1/4 We would like to inform the community that there has been a security breach on one of the external market maker wallets that may impact the $PRIMATE liquidity pools. https://twitter.com/...
This looks like Profanity related. If you used vanity addresses in the past, you might want to move those funds to a different wallet, or @binance for safe keeping. https://twitter.com/...
Always hate to see it. I have a lot of respect for the Wintermute team, particularly @EvgenyGaevoy. I know they'll handle it as well as anyone could. Wish them luck identifying the thief and recovering funds. https://twitter.com/...
Wow Single entry access to over 90 assets. That's ridiculous bad security practices The sell off is inevitable. You better check your portfolio tokens if they have @wintermute_t as a partner - those will be dumped soon We will prepare analysis ASAP #wintermutehack https://twitter…
Man not sure what went on here but hacks of this magnitude from elite operations in the space does not inspire confidence. Hope Wintermute manages to recover the funds. https://twitter.com/...
Wintermute potential attack vector: a vulnerable Profanity-generated vanity address was on the contract whitelist and had permission to drain funds https://etherscan.io/... Anyone in the world with a decent GPU cluster can carry out similar attacks on Profanity addresses! ⚠️