Monday, January 6, 2025
HomeCyber CrimeU.S. Recovered $30 Million From North Korean Hackers

U.S. Recovered $30 Million From North Korean Hackers

Published on

Cryptocurrency stolen by North Korean hackers has been seized by the FBI and private investigators for a value of approximately $30 million. There has never been a case where stolen cryptocurrency has been seized from a North Korean hacking group.

In March of this year, a video game company was robbed of $30 million worth of cryptocurrency by government-supported hackers. There is a worrying trend in crypto crime right now that is one of the most troubling – specifically, the theft of funds from: 

  • DeFi protocols
  • Cross-chain bridges

A large amount of cryptocurrency has already been stolen from the DeFi protocol so far in 2022 by North Korean-linked hacker groups.

- Advertisement - SIEM as a Service

Approximately 10 percent of the stolen cryptocurrency is represented by seized funds. As of the time of the theft in March, the total value of the stolen funds was approximately $620 million from Ronin Network, it’s a sidechain that is designed for Axie Infinity, a game with a play-to-earn model.

These seizures were largely made possible by the Chainalysis Crypto Incident Response team. Assisting law enforcement agencies and industry players by using advanced tracing techniques and liaising with them to quickly freeze the stolen funds and follow them to cash out points. 

Hacked Ronin Bridge

A number of private keys held by Ronin Network’s cross-chain bridge transaction validators were obtained by the Lazarus Group during the attack.

Two transactions were approved using this majority, both of which were withdrawals, as follows:-

  • One for 173,600 ether (ETH)
  • The second one was for 25.5 million USD Coin (USDC)

A laundering process was then initiated, and Chainalysis began tracking the funds to find out where they came from. 

Until now, more than 12,000 crypto addresses have been used to launder these funds in order to hide their origins. Clearly, this illustrates the high degree of sophistication at which the hackers were able to launder money. 

Laundering Stages

There are five stages in the typical North Korean DeFi laundering process, and here below we have mentioned them:-

  • Stolen Ether sent to intermediary wallets
  • Ether mixed in batches using Tornado Cash
  • Ether swapped for bitcoin
  • Bitcoin mixed in batches
  • Bitcoin deposited to crypto-to-fiat services for cashout

Tornado Cash, however, has been sanctioned by the US Treasury’s OFAC in response to its involvement in money laundering. There has been a shift away from the Ethereum mixer by Lazarus Group since then.

In the investigation of hacks such as the one suffered by Axie Infinity, the transparency of cryptocurrency plays an essential role. 

In order to understand and disrupt the laundering activities of cybercrime organizations, investigators need to have access to the right tools. There are two key things that need to be stressed: transparency and collaboration.

Download Free SWG – Secure Web Filtering – E-book

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

PoC Exploit Released for Critical OpenSSH Vulnerability (CVE-2024-6387)

An alarming new development emerged in the cybersecurity landscape with the release of a...

Malicious EditThisCookie Extension Attacking Chrome Users to Steal Data

The popular cookie management extension EditThisCookie has been the target of a malicious impersonation....

WordPress Plugin Vulnerability Exposes 3 Million Websites to Injection Attacks

A critical vulnerability has been identified in the popular UpdraftPlus: WP Backup & Migration...

iPhone Sharing the Photos by Default to Apple

A recent blog post by developer Jeff Johnson has brought to light a new...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

Weaponized Python Scripts Deliver New SwaetRAT Malware

The Python script leverages low-level interactions with the Windows operating system, which imports crucial...

North Korean Hackers Wipe Cryptocurrency Wallets via Fake Job Interviews

Cybersecurity experts have uncovered a new wave of cyberattacks linked to North Korean threat...

LegionLoader Abusing Chrome Extensions To Deliver Infostealer Malware

LegionLoader, a C/C++ downloader malware, first seen in 2019, delivers payloads like malicious Chrome...