SlowMist Yuxian posted on the X platform: "After reviewing dozens of stolen intelligence reports related to GMGN submitted to SlowMist, we found a common trait: users' private keys were not leaked, but all their SOL and BNB were purchased on the Pixiu platform (i.e., only available for buying, not selling). The hackers primarily siphoned off user funds by removing the Pixiu platform from the pool, profiting over $700,000. This scenario (without private key leakage) is likely the result of a more advanced phishing scheme. Since GMGN has already fixed the issue, reproducing it is difficult. We suspect it's related to the GMGN account model. Users visit phishing websites, which obtain login signature information for their GMGN account model, such as the access_token and refresh_token values, and take over user account permissions. However, without the user's 2FA, they cannot directly export private keys or withdraw tokens. Therefore, they use the Pixiu platform to carry out a "counter-knock" attack on user funds, indirectly stealing user assets."