Lazarus attempt to launder additional $27.2M of funds stolen from Harmony bridge hack

Share This Post

On-chain analysis shows that North Korean hackers responsible for Harmony’s Horizon bridge hack spent the weekend attempting to move some of the illicit funds.

On-chain analysis of how Lazarus group attempted to launder the Harmony bridge funds, courtesy Twitter user @zachxbt
On-chain analysis of how Lazarus group attempted to launder the Harmony bridge funds, courtesy Twitter user @zachxbt

Using Railgun, a smart contract system that initiates what is known as “Zero Knowledge Proof,” the hackers attempted to move the illicit funds through six different exchanges, several of which were notified over the weekend. 

At least two of the exchanges, Binance and Huobi, were able to move fast and freeze at least a portion of the laundered funds. 

CZ responds to evidence linking the wallets to Binance
CZ responds to evidence linking the wallets to Binance

The movements come more than a week after the FBI declared Lazarus group, which has links to the Democratic People’s Republic of North Korea (DPRK), as responsible for the exploit of Harmony’s Horizon Protocol, which saw in total more than $100 million worth of cryptocurrency disappear in an attack in June 2022.

That attack and others like it, the FBI allege, are spurring “the DPRK’s use of illicit activities—including cybercrime and virtual currency theft—to generate revenue for the regime.”

Since 2017, $1.2 billion worth of crypto has been stolen by the group, according to an Associated Press report. 

The largest of which was the $624 million hack last April of the Ronin Network, Axie Infinity’s side-chain link to the Ethereum network.

Since the proliferation of decentralized finance, or DeFi, bridge attacks are becoming increasingly more common. 

What are the common types of bridge exploits?

The exploitation of bridges in the world of blockchain is often sophisticated and predictable due to code bugs or leaked cryptographic keys. Some of the most common bridge exploits include:

  • False Deposits: In this scenario, a bad actor creates a fake deposit event without actually depositing funds or uses a valueless token to infiltrate a network, such as that which occurred in the Qubit finance hack last January. 
  • Validator Flaws: Bridges validate deposits before allowing transfers. Hackers may exploit a flaw in the validation process by creating fake deposits, which occurred during the Wormhole hack where a flaw in digital signature validation was exploited.
  • Validator Takeover: Here attackers seek a vulnerability by attempting to gain control over a majority of validators by taking over a certain number of votes to approve new transfers. The Ronin Network hack is an example where five of the nine validators were compromised. 

It is important to note, however, that the most common factor across exploits is human error. Instead of focusing solely on the shortcomings of bridges, post-hack investigations are usually able to patch security fixes, but only after the damage has already been done.

The sheer magnitude of these exploits is concerning for blockchain developers. Other notable bridge exploits from 2022 include:

  • February: Wormhole — $375 million
  • March: Ronin Bridge — $624 million
  • August: Nomad Bridge — $190 million
  • September: Wintermute — $160 million

The post Lazarus attempt to launder additional $27.2M of funds stolen from Harmony bridge hack appeared first on CryptoSlate.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Solana Records New ATH After 3 Years: Is SOL Ready To Flip USDT?

Solana (SOL) has recorded a new all-time high (ATH) of $262, marking a historic recovery after three years of tumultuous price action Notably, the token had once fallen as low as $8 at the peak of

UK Crypto Regulation 2025: Rivalling EU MiCA with New Stablecoin Rules

The post UK Crypto Regulation 2025: Rivalling EU MiCA with New Stablecoin Rules appeared first on Coinpedia Fintech News The UK is gearing up to present its crypto-regulatory framework in 2025 The

Ripple CEO Brad Garlinghouse Backs Trump’s Pick Scott Bessent: End of the SEC Lawsuit Near!

The post Ripple CEO Brad Garlinghouse Backs Trump’s Pick Scott Bessent: End of the SEC Lawsuit Near! appeared first on Coinpedia Fintech News Ripple CEO Brad Garlinghouse shared the good news with

Cardano (ADA) Price Analysis: Is ADA on Track to Hit $2?

The post Cardano (ADA) Price Analysis: Is ADA on Track to Hit $2 appeared first on Coinpedia Fintech News With the crypto market reaching $334 trillion, a massive jump of 44% over the past 24 hours,

Bitcoin Prediction Market Signals $2.5 Trillion Market Cap by January 1st

The post Bitcoin Prediction Market Signals $25 Trillion Market Cap by January 1st appeared first on Coinpedia Fintech News The Bitcoin market has seen a surge of nearly 80% in the last seven days

Crypto News Today (Nov 23, 2024): Bitcoin Dominance Grows | Stellar Leads Gainers

The post Crypto News Today (Nov 23, 2024): Bitcoin Dominance Grows | Stellar Leads Gainers appeared first on Coinpedia Fintech News The global cryptocurrency market has increased, reflecting a 137%