Ronin hackers transferred stolen funds from ETH to BTC and used sanctioned mixers

Share This Post

The hackers continue to spread out the stolen funds using Bitcoin privacy tools as a means to remain anonymous, despite the identity of the hackers believed to be a North Korean cybercrime group.

The hackers behind the $625 million Ronin bridge attack in March have since transferred most of their funds from ETH into BTC using renBTC and Bitcoin privacy tools Blender and ChipMixer. 

The hacker’s activity has been tracked by on-chain investigator ‘₿liteZero’, who works for SlowMist and contributed to the company’s 2022 Mid-Year Blockchain Security report. They outlined the transaction pathway of the stolen funds since the Mar. 23 attack.

The majority of the stolen funds were originally converted into ETH and sent to now sanctioned Ethereum crypto mixer Tornado Cash before being bridged over to the Bitcoin network and converted into BTC via the Ren protocol.

According to the report, the hackers, who are believed to be North Korean cybercrime organization Lazarus Group, initially transferred  just a portion of the fund (6,249 ETH) to centralized exchanges including Huobi (5,028 ETH) and FTX (1,219 ETH) on Mar. 28.

From the centralized exchanges, the 6249 ETH appeared to have been converted into BTC. The hackers then transferred 439 BTC ($20.5 million) to Bitcoin privacy tool Blender, which was also sanctioned by the U.S. Treasury on May. 6. The analyst wrote:

“I’ve found the answer in Blender sanction addresses. Most Blender sanction addresses are Blender’s deposit addresses used by Ronin hackers. They have deposited all their withdrawal funds to Blender after withdrawing from the exchanges.”

However the overwhelming majority of stolen funds — 175,000 ETH — was transferred Tornado Cash incrementally between April 4 and May 19.

Related: The aftermath of Axie Infinity’s $650M Ronin Bridge hack

The hackers subsequently used decentralized exchanges Uniswap and 1inch to convert around 113,000 ETH to renBTC (a wrapped version of BTC), and used Ren’s decentralized cross-chain bridge to transfer the assets from Ethereum to the Bitcoin network and unwrap the renBTC into BTC.

From there, approximately 6,631 BTC was distributed to a variety of centralized exchanges and decentralized protocols:

Platforms the hackers used to transfer BTC to. Source: SlowMist.

The report also stated that the Ronin hackers withdrew 2,871 BTC (of the 3,460 BTC) ($61.6 million as of Aug. 22) via Bitcoin privacy tool ChipMixer.

BTC balance on platforms after the hackers withdrew funds. Source: SlowMist.

₿liteZero concluded the Twitter thread by stating that the Ronin hack remains a “mystery to be investigated” and that more progress is to be made.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

$230M Bitcoin Heist Takes Dark Turn — $100M Still Missing, FBI Probes Kidnapping Link

Two young men pulled off a $230 million bitcoin heist in one of the largest crypto thefts from a private individual in US history But after indulging in luxury cars and a $2 million watch, the story

Crypto Analyst Says Dogecoin Price Could Pull An XRP This Cycle, What This Means

A prominent crypto analyst has sparked a thought-provoking debate on social media platform X, suggesting that the Dogecoin price may mirror XRP’s performance during the previous bull market  While

Survey Finds Almost 70% Of Ethereum Institutional Investors Engaged In ETH Staking

Almost 70% of institutional investors in Ethereum (ETH) are participating in ETH staking, with 606% of them using third-party staking platforms Ethereum Staking Landscape At A Glance According to a

Blackrock Targets $3 Trillion Crypto Derivatives Market, Quietly Pushing Game-Changing Token

Blackrock, the world’s largest asset manager, is reportedly seeking to disrupt the $3 trillion crypto derivatives market by pushing to have its BUIDL token accepted as collateral Discussions

Inside GOAT’s Wild Market Ride: What’s Driving This AI-Meme Coin Craze?

The artificial intelligence (AI)-driven meme coin goatseus maximus (GOAT), launched on pumpfun, has reached a market valuation of $418 million after gaining more than 36% against the US dollar by 7

Institutional demand and rising ETP flows signal Bitcoin breakout – VanEck

Bitcoin (BTC) is set for a potential breakout as increasing institutional investment, growing miner holdings, and rising exchange-traded product (ETP) flows signal mounting demand, according to