Lazarus attempt to launder additional $27.2M of funds stolen from Harmony bridge hack

Share This Post

On-chain analysis shows that North Korean hackers responsible for Harmony’s Horizon bridge hack spent the weekend attempting to move some of the illicit funds.

On-chain analysis of how Lazarus group attempted to launder the Harmony bridge funds, courtesy Twitter user @zachxbt
On-chain analysis of how Lazarus group attempted to launder the Harmony bridge funds, courtesy Twitter user @zachxbt

Using Railgun, a smart contract system that initiates what is known as “Zero Knowledge Proof,” the hackers attempted to move the illicit funds through six different exchanges, several of which were notified over the weekend. 

At least two of the exchanges, Binance and Huobi, were able to move fast and freeze at least a portion of the laundered funds. 

CZ responds to evidence linking the wallets to Binance
CZ responds to evidence linking the wallets to Binance

The movements come more than a week after the FBI declared Lazarus group, which has links to the Democratic People’s Republic of North Korea (DPRK), as responsible for the exploit of Harmony’s Horizon Protocol, which saw in total more than $100 million worth of cryptocurrency disappear in an attack in June 2022.

That attack and others like it, the FBI allege, are spurring “the DPRK’s use of illicit activities—including cybercrime and virtual currency theft—to generate revenue for the regime.”

Since 2017, $1.2 billion worth of crypto has been stolen by the group, according to an Associated Press report. 

The largest of which was the $624 million hack last April of the Ronin Network, Axie Infinity’s side-chain link to the Ethereum network.

Since the proliferation of decentralized finance, or DeFi, bridge attacks are becoming increasingly more common. 

What are the common types of bridge exploits?

The exploitation of bridges in the world of blockchain is often sophisticated and predictable due to code bugs or leaked cryptographic keys. Some of the most common bridge exploits include:

  • False Deposits: In this scenario, a bad actor creates a fake deposit event without actually depositing funds or uses a valueless token to infiltrate a network, such as that which occurred in the Qubit finance hack last January. 
  • Validator Flaws: Bridges validate deposits before allowing transfers. Hackers may exploit a flaw in the validation process by creating fake deposits, which occurred during the Wormhole hack where a flaw in digital signature validation was exploited.
  • Validator Takeover: Here attackers seek a vulnerability by attempting to gain control over a majority of validators by taking over a certain number of votes to approve new transfers. The Ronin Network hack is an example where five of the nine validators were compromised. 

It is important to note, however, that the most common factor across exploits is human error. Instead of focusing solely on the shortcomings of bridges, post-hack investigations are usually able to patch security fixes, but only after the damage has already been done.

The sheer magnitude of these exploits is concerning for blockchain developers. Other notable bridge exploits from 2022 include:

  • February: Wormhole — $375 million
  • March: Ronin Bridge — $624 million
  • August: Nomad Bridge — $190 million
  • September: Wintermute — $160 million

The post Lazarus attempt to launder additional $27.2M of funds stolen from Harmony bridge hack appeared first on CryptoSlate.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Ethereum Unleashed: ETFs, Whale Activity, Layer 2 Solutions Shape Its Future

Ethereum (ETH) is gaining prominence as Bitcoin maintains its recent highs Despite the fact that ETH is currently 36% below its all-time high of $4,878 from 2021, analysts anticipate that the

XRP Price Prediction For November 23

The post XRP Price Prediction For November 23 appeared first on Coinpedia Fintech News XRP has recently shown a strong and sustained upward price movement, up by more than 65 percent in the last

Bitcoin Genius? Kiyosaki Backs Saylor’s Bold Strategy

The post Bitcoin Genius Kiyosaki Backs Saylor’s Bold Strategy appeared first on Coinpedia Fintech News Robert Kiyosaki has never been one to sugarcoat his opinions, and his latest defense of

Binance Raises Compliance Staff by 34% to Meet Demands of Crypto Industry

Binance expands its compliance team to meet the growing needs of the crypto industry and its user base Compliance Remains Vital for Binance By the end of the year, Binance, one of the world’s

Allianz Bets Big On Bitcoin With MicroStrategy Convertible Note Investment

Allianz SE, Europe’s second-largest insurance company and Germany’s largest, has acquired nearly 25% of MicroStrategy’s recent convertible note offering The investment marks a

Trump Reveals Plan for Crypto, Big Tech, and Immigration!

The post Trump Reveals Plan for Crypto, Big Tech, and Immigration! appeared first on Coinpedia Fintech News Donald Trump is back in the spotlight with some intriguing nominations for his next