Dear Astar Community, Council, and Collators,
I am reaching out to the forum with deep humility to open a transparent discussion regarding a complex situation involving a significant amount of ASTR, currently locked in a technical stalemate due to a cyber attack.
First and foremost, I want to clarify what this post is NOT:
I am not asking for a bailout.
I am not asking for treasury funds or financial compensation from the Astar Foundation.
My specific request to the community, Council, and technical team is to evaluate the feasibility of a Governance-backed resolution (a Root-level authorized transfer) to enable a safe technical migration to a new wallet, for funds that are legally mine as an early participant, but are currently under active attack.
Background and the Stalemate Dynamics:
This started last April, when I realized that my primary key had been compromised by a malicious browser extension. For several months, I managed to contain the threat and handle the situation manually; so far, the attacker has only managed to steal the tokens that were not staked and ended up on the Soneium network.
Recently, the attacker escalated their strategy by employing automated scripts and bots. A few days ago, I noticed on-chain that another address — belonging to a different user — suffered a complete loss of approximately 900k ASTR due to the exact same attack pattern. I do not know who that user is, nor have I seen any posts from them on X or the Forum, but seeing that wallet drained made it abundantly clear how fast the attacker’s scripts operate.
To avoid the same outcome with my remaining primary capital, we utilized standard native network functionalities to revoke the attacker’s proxy permissions and keep the tokens locked. The current situation is an active stalemate/duel:
The funds remain frozen thanks to standard chain unbonding delays: Whenever the attacker triggers an unlock action, the standardized protocol delay before tokens become withdrawable gives me the window needed to intercept the action and re-stake them immediately.
The attacker is waiting with bots: They are monitoring the address, ready to drain the funds the moment the unbonding period ends or a withdrawal attempt is executed.
The Result: Every time they initiate an unlock, I leverage the network’s built-in delay period to re-lock the tokens, preventing the theft; however, I cannot safely withdraw them to a new wallet because their script would front-run me the exact block they become claimable.
Strategic Note on Specific Details:
I carefully evaluated whether to publish on this forum, as posting publicly means revealing my hand and potentially signaling my intentions to the attacker, which could cause them to react or become even more aggressive. For this reason — rather than simple privacy concerns — I am intentionally withholding specific technical parameters and on-chain identifiers from this public thread.
Why I Am Seeking Your Input:
I fully acknowledge that wallet security is an individual responsibility, and I respect the fundamental immutability of the blockchain. I make no excuses for the initial compromise.
However, given that these funds have not been stolen but remain trapped on-chain in this forced equilibrium, I would like to understand if the governance, collators, and community see any path toward authorizing a guided migration via a governance proposal.
My Request:
I would like to respectfully ask the Community, Council, Collators, and developers:
Is there political willingness and technical capability to pass a Governance proposal authorizing a Root-level transfer to execute the safe migration of verified funds currently in this active stalemate condition?
What level of proof or ownership guarantees would the community require to consider and potentially vote in favor of such a proposal?
I remain fully available to privately provide authorized representatives with all necessary verification to prove my historical and legitimate ownership of the address.
Thank you all for your time and for your continuous work for the network.