Proprietary 2025-01-27 · 2 days ·Cryptocurrency Theft, Credential Theft, Remote Access

DogWifTools Windows releases drained wallets

An attacker used an exposed GitHub token to replace DogWifTools Windows releases with RAT-laced builds. Versions 1.6.3 through 1.6.6 stole wallet material and drained Solana users.

Story

DogWifTools was a commercial tool for Solana memecoin launches. It automated volume, bundling, comments, and activity simulation for Pump.fun promotion. The users trusted the Windows client with wallets and local trading material.

According to DogWifTools' disclosure as reported by BleepingComputer, an attacker reverse engineered the software and extracted a GitHub token. The token gave access to the project's private GitHub repository. The attacker did not publish malware immediately. After legitimate releases, they waited, modified the builds, and replaced the Windows artifacts.

The affected versions were 1.6.3 through 1.6.6. The malicious build installed a remote access trojan and downloaded updater.exe into the user's local AppData directory. The payload targeted cryptocurrency wallet private keys. Reports also described exchange-account loss and possible exposure of identity documents from systems where DogWifTools had broad permissions.

The estimated theft was more than $10 million, though that figure came from community reporting and was disputed by a person claiming responsibility. DogWifTools denied staff involvement, said macOS users were not affected, and said it was adding security controls while working with investigators.

Affected Artifacts

Observed
2025-01-27 to 2025-01-29
Compromised Versions
Fixed
Not listed
Evidence
distribution: dogwiftools.com, file: updater.exe, path: %LOCALAPPDATA%\updater.exe, observable: Windows builds of DogWifTools versions 1.6.3 through 1.6.6 were replaced with RAT-laced artifacts after legitimate releases.
  • The public sources describe the compromised artifact as the Windows version; macOS users were reported as unaffected.
  • The estimated theft exceeded $10 million in community reporting, but the exact amount remains disputed.

Incident Context

Motive
Financial Gain
Cause
Exposed Secret
Transitive
No

External References

Source record: proprietary/dogwiftools/meta.yaml