📈 Get daily crypto insights that make you smarter about your money

Remilia Treasury Breach: How a Password Manager Compromise Drained $3 Million in Ethereum and NFTs

The cryptocurrency community woke up to alarming news on March 17, 2024, as the Remilia Treasury — the organization behind the popular Milady NFT collection — confirmed a devastating security breach. The attacker siphoned approximately 850 ETH, valued at nearly $3 million at the time, along with multiple high-value NFTs from wallets controlled by founder Charlotte Fang. The incident highlights a growing and often underappreciated attack vector in the crypto space: the compromise of personal operational security rather than smart contract vulnerabilities.

The Exploit Mechanics

According to Fang’s public statement, the breach originated from unknown malware that infiltrated a password manager storing seed phrases for all connected wallets. This gave the attacker access to the private keys necessary to authorize transactions from the Remilia treasury multisig wallet and other linked accounts. The attacker then systematically moved assets to a drainer wallet — identified as 0x778Be423ef77A20A4493f846BdbcDDfc30252cE9 — where liquidation began immediately. The stolen NFTs and tokens were sold for approximately 850 ETH, equivalent to roughly $3 million given Ethereum’s price of $3,642 at the time.

Security firm PeckShield was among the first to analyze the on-chain activity, flagging suspicious transfers that preceded the public disclosure. The attack did not exploit a smart contract vulnerability or a protocol-level flaw. Instead, it was a textbook operational security failure — the digital equivalent of leaving the keys to the vault in an unlocked desk drawer.

Affected Systems

The breach impacted multiple wallets connected to the Remilia organization, including the multisig wallet designated for treasury funds. Among the assets drained were Milady NFTs — a collection of 10,000 generative anime-style artworks on the Ethereum blockchain that had become a cultural phenomenon in crypto circles. Fang confirmed, however, that the NFT contract ownership and metadata had been transferred to a hardware wallet prior to the attack and were not compromised. Additionally, the operating treasury had been moved off-chain, which limited the overall financial damage to the organization’s operational capacity.

This distinction is critical: the hack primarily affected Fang’s personal wallets and those directly connected to them, rather than the core smart contract infrastructure of the Milady ecosystem. Nevertheless, the reputational damage and community concern were immediate and significant.

The Mitigation Strategy

In the aftermath, Fang issued a public warning to Milady NFT holders, advising heightened vigilance against suspicious communications that might attempt to exploit the confusion. The response highlights several key mitigation principles that apply broadly across the crypto industry:

First, never store seed phrases in password managers or any internet-connected software. Seed phrases should be written on physical media and stored in secure locations — ideally across multiple geographic sites. Second, multisig wallets should use hardware wallet signers exclusively, ensuring that even if one signer’s credentials are compromised, the attacker cannot unilaterally authorize transactions. Third, organizations should implement strict separation between personal and treasury wallets, with independent key management for each.

Lessons Learned

The Remilia hack underscores a sobering reality: as the crypto ecosystem matures and smart contract security improves through rigorous auditing and formal verification, attackers are increasingly pivoting to social engineering and operational security exploits. The attack surface is not limited to code — it extends to the human operators who control that code.

With Bitcoin trading at $68,390 and the broader crypto market capitalization exceeding $2.7 trillion in mid-March 2024, the financial incentives for attackers have never been greater. A single compromised seed phrase can unlock millions of dollars in seconds, and the pseudonymous nature of blockchain transactions makes recovery exceedingly difficult.

This incident also follows a pattern of controversy surrounding the Milady project, including a September 2023 disclosure by Fang that a rogue developer misappropriated $1 million from the treasury, followed by a lawsuit from co-founders alleging misuse of $1.7 million in project funds. These prior incidents raise questions about internal controls and governance that extend beyond the immediate technical vulnerability.

User Action Required

If you hold significant cryptocurrency or NFT assets, take immediate stock of your operational security posture. Move seed phrases out of any digital storage. Ensure that multisig wallets use hardware signers. Consider implementing a geographic key distribution strategy where recovery materials are stored in separate physical locations. And remain skeptical of any unsolicited communications claiming to be from projects you’re invested in — especially in the wake of a publicized breach.

The Remilia Treasury hack is a stark reminder that in crypto, you are your own bank. And that means you are also your own security department.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research and consult with security professionals before making decisions about digital asset protection.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “Remilia Treasury Breach: How a Password Manager Compromise Drained $3 Million in Ethereum and NFTs”

    1. putting seed phrases in a password manager connected to the internet is mind blowing. this is day 1 opsec and she ran a major NFT project

      1. nft_vault_ day 1 opsec and she was running a 9 figure NFT project. metal plate, air gapped, never typed into anything connected to the internet. not that hard

    1. 850 ETH gone because of malware on one machine. multisig means nothing when every key lives in the same compromised app

      1. 850 ETH drained because one laptop got malware. the multisig didnt help because all seed phrases were in the same password manager. brutal lesson

        1. sara kowalski

          password manager holding every seed was the real mistake. multisig means nothing if one device gets hit like that

      1. drainer_watch_

        wallet 0x778B still being tracked years later. once stolen funds hit a drainer address they get laundered through blur and opensea within hours

    1. multisig_farce_

      0xVanguard.eth multisig with all keys in one password manager is just single sig with extra steps. the whole point is geographic key separation

      1. cold_storage_jim

        multisig_farce_ literally this. multisig with keys in one manager is just a complicated single sig. geographic separation is the entire point

  1. 850 ETH from a password manager compromise. not a smart contract bug, not a zero day, just bad opsec from someone managing millions

    1. seedplate_metal_

      Keiko M. not just bad opsec, it was catastrophic. managing a 9 figure treasury with all keys in one password manager is neglignece at that level

  2. seed_in_keepass_

    storing seed phrases in a password manager connected to the internet. the irony of a 3M hack caused by opsec failure not smart contract failure

    1. seed_in_keepass_ 850 ETH gone because someone typed a seed phrase into malware. hardware wallet with air gap would have prevented the entire thing

  3. multisig_truth_

    treasury multisig where one person holds all the keys is just a singlesig with extra steps. the Remilia setup failed at the most basic level

  4. metalplate_skeptic

    850 ETH from a password manager. every time i think opsec in NFT circles has improved someone loses 8 figures to malware again

  5. the multisig had all keys in one password manager. thats not a multisig thats a singlesig pretending to be safe

  6. managing a 9 figure NFT treasury with all seed phrases in one password manager. words fail me. this was opsec 101 and she failed it completely

    1. Tomasz J. people managing 9 figure treasuries should have armed guards and bank vaults for keys not a 9 dollar Bitwarden subscription

  7. hardware_purse_

    850 ETH stolen not from a smart contract bug or zero day exploit but from typing a seed phrase into infected software. the most expensive lesson in crypto history

  8. opsec_or_die_

    storing multisig keys in a cloud password manager connected to a machine with malware. every single opsec principle violated in one move. 850 ETH worth of negligence

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$78,157.00+0.8%ETH$2,457.69+0.9%SOL$104.97+1.5%BNB$693.16+0.7%XRP$1.39+0.7%ADA$0.2009+0.5%DOGE$0.0847+0.3%DOT$0.8444+0.7%AVAX$7.34+1.1%LINK$11.39+0.7%UNI$4.90+12.1%ATOM$1.48-0.5%LTC$49.00-0.6%ARB$0.0865-0.8%NEAR$1.89+5.6%FIL$0.6824+0.4%SUI$0.7411+0.8%BTC$78,157.00+0.8%ETH$2,457.69+0.9%SOL$104.97+1.5%BNB$693.16+0.7%XRP$1.39+0.7%ADA$0.2009+0.5%DOGE$0.0847+0.3%DOT$0.8444+0.7%AVAX$7.34+1.1%LINK$11.39+0.7%UNI$4.90+12.1%ATOM$1.48-0.5%LTC$49.00-0.6%ARB$0.0865-0.8%NEAR$1.89+5.6%FIL$0.6824+0.4%SUI$0.7411+0.8%
Scroll to Top