Skip to main content
Sign in

Wintermute

avoid.net/wintermute38/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION][src:defillama]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·38s69P…ooPj

Summary

Wintermute is a London-headquartered algorithmic trading firm and cryptocurrency market maker founded in 2017 by Evgeny Gaevoy. On September 20, 2022, the firm's DeFi operations were exploited for approximately $160 million after an attacker leveraged a known cryptographic vulnerability in the Profanity vanity address tool to compromise Wintermute's admin private key. The stolen funds were never recovered, though the firm remained solvent, repaid its outstanding DeFi loans, and has continued operating and expanding into U.S. markets.

Connected Entities

1 entities
Organizations
Wintermute
Relationships
    Have evidence about Wintermute?

    Timeline(11 events)

    2017

    Wintermute founded in London by Evgeny Gaevoy, formerly of Optiver's European ETF desk.

    15 September 2022

    1inch Network publicly discloses a severe cryptographic vulnerability in Profanity, the Ethereum vanity address generator, recommending all users immediately transfer funds away from Profanity-generated addresses.

    15 September 2022

    Profanity vulnerability exploited by separate actors draining approximately $3.3 million from other wallets, establishing proof of exploitability before the Wintermute attack.

    20 September 2022

    Attacker uses a reconstructed private key from a Profanity-generated Wintermute admin wallet to drain approximately $160 million from Wintermute's DeFi vault across roughly 90 ERC-20 token types.

    20 September 2022

    CEO Evgeny Gaevoy publicly discloses the hack via Twitter, confirms solvency, and characterizes the incident as a potential white-hat event, offering the attacker a 10% bounty to return funds.

    20 September 2022

    Attacker routes approximately $114 million in stablecoins through Curve Finance 3pool to complicate asset freezes.

    27 September 2022

    Researcher 'Librehash' alleges via social media that the hack was an inside job based on alleged anomalous pre-hack transactions; Wintermute denies the allegation. BlockSec assesses the inside-job theory as unsubstantiated.

    14 October 2022

    Wintermute repays its $96 million TrueFi DeFi loan one day before deadline, demonstrating continued solvency following the hack.

    2023

    Stolen $160 million remains unrecovered; attacker's 10% white-hat bounty offer unclaimed. Wintermute resumes normal operations.

    February 2025

    Wintermute opens U.S. headquarters in New York City, expanding OTC and derivatives offerings.

    3 September 2025

    Wintermute submits formal feedback to the SEC Crypto Task Force, arguing network tokens should not be classified as securities.

    Provenance & Audit Trail

    Decision Log

    This investigation is cryptographically anchored to the Solana blockchain (1 event). 12 of 19 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 5/4/2026, 2:54:49 AM

    last updated: 8/30/2026, 5:14:13 AM

    avoid.net — verified advice for a post-truth world