AristoK3
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
AristoK3 is the alias used by an anonymous contractor who carried out a supply chain attack on a decentralized finance platform’s token launchpad. The actor is associated with the GitHub handle AristoK3 and, according to available information, is believed to be based in China. The attack targeted the MISO launchpad of SushiSwap, a community‑driven DeFi platform that enables token creation and trading on the Ethereum blockchain, indicating a focus on the cryptocurrency sector with a global reach due to the nature of the platform. The strategic objective demonstrated in this incident was financial gain, as the actor diverted approximately $3 million in Ethereum to a personal wallet during a single auction.
The threat actor’s tactics, techniques, and procedures involved gaining access to the project’s code repository through a contractor account and pushing a malicious commit that replaced the auctionWallet address with the attacker’s own wallet address. This method constitutes a software supply chain attack where the manipulation of a code component allowed the theft of funds without deploying traditional malware families or exploit kits. The tooling style was limited to a direct code modification, reflecting a low‑complexity but effective approach that relied on trusted access rather than sophisticated intrusion tools. No specific malware families or additional tooling were referenced in the reporting.
Public attribution does not link AristoK3 to any state‑sponsored group or known criminal consortium; the only geographic clue is the possible location in China, which remains unverified. The SushiSwap MISO incident stands as the actor’s sole publicly reported operation, notable for the rapid return of the stolen funds after law enforcement pressure and exchange cooperation. This case illustrates how a single trusted insider with repository access can execute a financially motivated supply chain attack against a DeFi service.
Incidents
Attributed incidents are available to members.
1 incident