Ronin Hackers Transferred Stolen Funds To Bitcoin Network Using Privacy Tools

Share This Post

Hackers who drained around $625 million from the Ronin Bridge attack in March have transferred funds from Ethereum to the Bitcoin network using privacy tools. In order to hide their identity, cybercriminals, who are believed to be part of the North Korean cybercrime group, Lazarus, used the Ren protocol, mixers, and several centralized exchanges to move funds from one blockchain to another.

â‚¿liteZero, a blockchain investigator, developer, and major contributor to SlowMist’s mid-year Blockchain Security report, tracked those stolen funds. It outlined the funds’ movement after March 23 after the exploit and noted that stolen funds are now converted into Bitcoins anonymously.

Related Reading: Crypto Exchange FTX Revenue Reportedly Balloons 1,000% To Over $1 Billion In 2021

â‚¿liteZero noted in a tweet;

I’ve been tracking the stolen funds on Ronin Bridge. I’ve noticed that Ronin hackers have transferred all of their funds to the bitcoin network. Most of the funds have been deposited to mixers(ChipMixer, Blender).

After getting access to the $625 worth of USDC and Ethereum, hackers moved funds to Tornado Cash in an effort to hide from authorities. Tornado is an Ethereum-based virtual currency tumbler that mixes crypto transactions and provides access with specific keys to individuals.

As it was not the end of the process to obscure the transactions, hackers used several crypto exchanges and a network bridge after withdrawing funds from Tornado cash. Investigator revealed in the Twitter thread that Ronin hackers circulated funds from Binance, Huobi, and FTX before sending the funds into the North Korean mixer, Blender.

U.S Treasury Accused Blender Of Assisting Hackers In May
Ethereum’s price is below $1,600, down by over 3%. | Source: ETHUSD price chart from TradingView.com

As per the â‚¿liteZero findings, just a portion of the stolen asset, or 6,249 ETHs, have appeared to be converted into Bitcoins, with Huobi receiving 5,028 ETHs and FTX 1,219 ETHs. Then, hackers sent 439 BTC (20.5 million) to the Bitcoin privacy tool Blender.

The analyst added;

I’ve found the answer in Blender sanction addresses. Most Blender sanction addresses are Blender’s deposit addresses used by Ronin hackers. After withdrawing from the exchanges, they have deposited all their withdrawal funds to Blender.

Interestingly, the â‚¿liteZero report comes after U.S. Treasury imposed sanctions on the mixer tool Blender on May 06, accusing the firm of assisting North Korean hackers in processing 20.5 million stolen funds. This figure of withdrawn amount from exchanges by cybercriminals is constant with the facts provided by â‚¿liteZero(20.72).

In addition, the hackers bridged the rest of the assets with the Bitcoin network using the renBTC protocol. The investigator explained hackers used Uniswap or 1inch to convert the funds into renBTC.

Since the Ren protocol came into existence, it opened the way for money laundering actors around the globe as it paved the way to convert an asset from Ethereum to a Bitcoin network. 

Then again, after converting and passing funds from several platforms, they used a mixer like ChipMex or Blenders. Funds are relocated to ChipMixer before withdrawing some amount from Blender.

Related Reading: Bitcoin Scam Called ‘Pig Butchering’ Grows Alarmingly Popular

The â‚¿liteZero ended up noting that more complex things may come out as the research team is currently analyzing the hackers.

Featured image from Pixabay and chart from TradingView.com

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

FLOKI Breaks Out Of Downtrend: Analyst Predicts 200% Rally To New All-Time High

Meme coin FLOKI has also benefited from recent inflows into the crypto markets, which has left many cryptocurrencies posting gains in both the 24-hour and seven-day timeframes  Notably, this inflow

Stripe Acquires Stablecoin Platform Bridge in Record $1.1 Billion Crypto Deal

Payments company Stripe has acquired stablecoin platform Bridge in a $11 billion transaction, marking the largest acquisition in the crypto industry to date Techcrunch founder Michael Arrington

Farm, Craft, and Thrive in My Neighbor Alice

Follow Regina in her journey down the rabbit hole that is My Neighbor Alice Will she find a wonderful land, or will it be a bore Read on to find out Last episode’s quick recap I’m still

Vitalik Buterin lays down roadmap to minimize centralization risk in Ethereum POS design

Ethereum co-founder Vitalik Buterin believes that the centralization of proof-of-stake (POS) poses a significant threat to Ethereum POS centralization is where large stakers dominate and small

Dogecoin Breaks Above $0.12 Level – Time For DOGE To Catch Up?

Dogecoin (DOGE) has finally broken through the crucial $012 resistance level, marking a significant milestone as it surges to catch up with the broader crypto market rally After weeks of struggling

Bitcoin’s Market Dominance Soars To 3-Year High – Is This The End Of Altcoin Season?

Bitcoin and many other cryptocurrencies have been on significant price increases in the past few weeks Bitcoin, in particular, has been inching close to its all-time high, and the recent break above