• Send Us A Tip
  • Calling all Tech Writers
  • Advertise
Sunday, June 21, 2026
  • Login
TechStory
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
TechStory
No Result
View All Result
Home Crypto

Singapore Entrepreneur’s Crypto Portfolio Wiped Out in “MetaToy” Game Scam

by Anindya Paul
December 18, 2025
in Crypto
Reading Time: 4 mins read
0
Koh

Source: Defence Turkey

TwitterWhatsappLinkedin

A campaign to expose an ongoing threat within Web3 was recently illustrated by Singaporean entrepreneur Mark Koh’s actual loss of his entire cryptocurrency wallet to a complex scam that uses malware presented as a beta-testing opportunity. According to the report, Koh, a long-time investor and founder of RektSurvivor (an error-help organization), had downloaded a game launcher that became a “Trojan Horse” for hackers looking to gain control of his cryptocurrency. Within only months of operating within the Web3 ecosystem, Koh lost about $14,189 (CNY100,000) due to downloading a game launcher that turned out to be a Trojan horse.

You might also like

How Bitcoin ETF Taxes Work: A Complete Guide for Investors

How to Reduce Crypto Taxes Legally: Smart Strategies Every Cryptocurrency Investor Should Know

The Battle of the Stablecoins: A Comprehensive Guide to USDT vs USDC

The attack against Koh demonstrated a new trend of so-called “social-engaged” attack-types that are being increasingly used against software developers and early adopters, who have typically been exposed to new software. Even with his years of experience and many Web3 projects vetted by standard cybersecurity protocols, Koh had all of his investments stripped away, which is due to social engineering techniques.

The “MetaToy” Trap

According to Koh, who detailed the harrowing experience in an interview with Lianhe Zaobao and on LinkedIn, the scam began on December 5. He encountered an opportunity on Telegram to beta test a new online game titled “MetaToy.”

To a casual observer, the project appeared legitimate. The professional design of the website and having a Discord server with active members indicated the Indie Crypto project was credible to investors, therefore Koh was persuaded to download the launcher for the game, which is typically a routine part of due diligence for an investor. This action, however, became a costly mistake for him.

Bypassing the Digital Defenses

Koh immediately ran into trouble following a download because he had Norton Antivirus installed on his system, and it quickly flagged some activity that was suspicious enough for him to take action to defend himself against the activity that was happening on his computer. He ran full system scans, deleted the flagged files and registry entries, and went as far as reinstalling his Windows 11 operating system to ensure a clean slate.

However, these measures were insufficient. Within 24 hours of the initial infection, Koh discovered that every software wallet connected to his browser extensions—specifically Rabby and Phantom—had been drained of all available funds.

“I didn’t even log into my wallet app. I had separate seed phrases. Nothing was saved digitally,” Koh told Decrypt. The theft occurred without him manually authorizing any transactions, suggesting a highly invasive form of malware.

A Technical “Double-Tap”

Koh believes the attackers used an advanced and complex mix of exploits to launch their attack. The type of malware Koh suspects may have been used for the attack was a type of malware known as “a token theft,” which allowed the attackers access to Koh’s currently logged-in web browsers on his device. In addition to Koh’s suspicions concerning the use of a token theft (malware), Koh also mentioned a probable zero-day vulnerability (Google Chrome) that was reported by a third party in September 2025 (the vulnerability was unknown to Google at that time) which allowed the malware to bypass the browser’s security sandboxes and obtain access to the encrypted data (private keys) stored within Koh’s wallet extensions.

The malware used in this attack exploited a number of different channels to infiltrate the target, which demonstrates how complex this attack was. Even though Koh’s antivirus managed to block two DLL (dynamic link library) hijack attempts, a malicious scheduled process had already been implanted deep within his system, waiting to execute the theft.

A Warning for “Hot Wallet” Users

Koh’s concern over the incident is an indication to the cryptocurrency communities and in particular angel investors and developers who consistently stay connected with up-and-coming protocols. The primary lesson, he argues, is that browser-based “hot wallets” are inherently vulnerable if the underlying operating system is compromised.

“I would advise even if the usual precautions are taken to actually remove and delete seeds from browser-based hot wallets when not in use,” Koh advised. He suggests that users should rely on private keys rather than seed phrases for specific wallets, as this compartmentalizes risk—compromising one private key does not necessarily expose an entire tree of derivative wallets.

The Broader Threat Landscape

Koh reported the crime to Singapore’s police department (who confirmed the case to local news agencies), and also spoke with another victim named “Daniel” who stated that the scam artists were still trying to lure him back into downloading the launcher following the theft of his coins. This exploit is just one of many malware campaigns aimed at the cryptocurrency space that started popping up in 2025. Cybercriminals are increasingly moving away from simple phishing emails and toward elaborate ruses involving fake AI tools, compromised GitHub repositories, and fraudulent game betas. By embedding malware in software that users are intended to download and run, attackers bypass the skepticism usually applied to unsolicited links.

As the industry grapples with these threats, the “MetaToy” incident serves as a grim proof-of-concept: in the current landscape, even a complete operating system reinstall may not be fast enough to outrun a drainer.

Tweet55SendShare15
Previous Post

Caroline Ellison Transferred to Halfway House After Serving 11 Months

Next Post

Pronto in Talks to Raise $25 Mn at $100 Mn Valuation

Anindya Paul

Professional content creator with strong expertise in content writing, filmmaking and social media strategy. Skilled in digital storytelling, scriptwriting, video production, sound design and graphic design - crafting compelling narratives across platforms. Known for delivering high-quality, engaging content under tight deadlines. A collaborative team player with a sharp creative instinct, adaptability to evolving trends, and a focus on impactful, results-driven communication.

Recommended For You

How Bitcoin ETF Taxes Work: A Complete Guide for Investors

by Anindya Paul
June 21, 2026
0
Bitcoin ETF

The issuance of Bitcoin exchange-traded funds (ETFs) has boosted investor confidence in cryptocurrency investments. Now, rather than physically owning and storing their investments through digital currency exchanges or...

Read more

How to Reduce Crypto Taxes Legally: Smart Strategies Every Cryptocurrency Investor Should Know

by Anindya Paul
June 21, 2026
0
Taxes

As time goes on, crypto-currency continues its evolution from a niche technological experiment to the newest global investment asset class worth trillions of dollars, with millions of investors...

Read more

The Battle of the Stablecoins: A Comprehensive Guide to USDT vs USDC

by Anindya Paul
June 19, 2026
0
USDC vs USDT

The world of cryptocurrency is well known for its extreme volatility; price can drop or increase by double digits within just a few minutes. For investors trying to...

Read more
Next Post
Pronto in Talks to Raise $25 Mn at $100 Mn Valuation

Pronto in Talks to Raise $25 Mn at $100 Mn Valuation

Please login to join discussion

Techstory

Tech and Business News from around the world. Follow along for latest in the world of Tech, AI, Crypto, EVs, Business Personalities and more.
reach us at info@techstory.in

Advertise With Us

Reach out at - info@techstory.in

Aviator Game India 2026

BROWSE BY TAG

#Crypto #howto 2024 acquisition AI amazon Apple Artificial Intelligence bitcoin Business China cryptocurrency e-commerce electric vehicles Elon Musk Ethereum facebook funding Gaming Google India Instagram Investment ios iPhone IPO Market Markets Meta Microsoft News OpenAI samsung Social Media SpaceX startup startups tech technology Tesla TikTok trend trending twitter US

© 2025 Techstory.in

No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to

© 2025 Techstory.in

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?