A long-standing Polkadot community member has fallen victim to a sophisticated social engineering attack resulting in their account being compromised. Approximately 188,932 DOT (~$406,205 USD) is currently at risk. The funds are presently bonded and secure, but require governance intervention to permanently protect them from the scammer.
This discussion post is to inform the community about the situation and gather support before submitting a formal referendum proposal.
Both the Polkadot Support Team and the Polkadot Anti-Scam Team have been notified and are aware of this case.
Address: 16JCybAA88yQ9t8Cus4YhB5mT5DjyBxBLEgYPCpH8HjnePTq
Subscan: https://assethub-polkadot.subscan.io/account/16JCybAA88yQ9t8Cus4YhB5mT5DjyBxBLEgYPCpH8HjnePTq
Unlike typical phishing attacks, this was a months-long sophisticated social engineering operation:
| Status | Amount | Security |
|---|---|---|
| Bonded (Staking) | 188,932 DOT | Safe while bonded |
The funds remain bonded and are currently mostly secure. However:
I am Mario Pino, member of the Polkadot community since the first testnets, former validator, and developer of Polkastats block explorer. I have been coordinating the technical defense of this account.
We have implemented a defense system running across several servers with redundant RPC connections.
The scammer is not an amateur. Our battle has escalated through multiple phases:
On January 2nd, 2025, 58,000 DOT was about to complete its unbonding period. The attacker had previously initiated this unbond in an attempt to drain funds.
What happened:
This battle demonstrated both the sophistication of the attacker AND the power of community coordination.
While our defensive systems are currently effective, this situation is unsustainable:
The ongoing battle is consuming resources that could be better used elsewhere. See https://github.com/paritytech/polkadot-sdk/issues/10719
A similar situation occurred with Parallel Finance where 200,000 DOT was at risk from a compromised sudo key. The community successfully passed Referendum 1424 to secure the funds through governance action.
Reference: https://polkadot.polkassembly.io/referenda/1424
We are preparing a Root track referendum to permanently secure the funds. The proposed approach:
Use balances.forceTransfer to move the bonded funds to a new, secure account controlled by the victim.
We are open to community feedback on the best technical approach.
We are prepared to provide:
I am happy to verify my identity with any community member or Fellowship member who wishes to confirm this case.
For questions or additional information, please comment below or reach out to Mario | Polkastats via the Polkadot Watercooler Matrix channel or also via email to [email protected]
Your support can help protect a community member from losing their life savings to scammers. Thank you.