Cointime

Download App
iOS & Android

North Korean Hackers Were Behind Crypto's Largest 'Theft of All Time'

Cointime Official

From coindesk By Aoyon Ashraf

What to know:

  • Arkham said the North Korean hackers Lazarus Group was behind the $1.5 billion hack, citing ZackXBT.
  • The attack appeared to have been caused by something called "Blind Signing."
  • The attackers first withdrew nearly $1.5 billion worth of funds from the exchange into a main wallet and then distributed the assets to several different wallets.

Blockchain analytics firm Arkham Intelligence said North Korea's Lazarus Group was behind Bybit's $1.46 billion hack.

In an earlier post on social media platform X, Arkham offered a bounty of 50,000 ARKM tokens for anyone who could identify the attackers for Friday's hack. Later, the platform said onchain sleuth ZachXBT submitted "definitive proof" that the attackers were the North Korean hacker group.

"His submission included a detailed analysis of test transactions and connected wallets used ahead of the exploit, as well as multiple forensics graphs and timing analyses," the post said.

The hack that rocked the crypto market and saw most prices tumbling was called the "largest crypto theft of all time, by some margin," by Elliptic's Tom Robinson, co-founder and chief scientist. "The next largest crypto theft would be the $611 million stolen from Poly Network in 2021. In fact it may even be the largest single theft of all time."

Blockchain data provider Nansen told CoinDesk that the attackers first withdrew nearly $1.5 billion worth of funds from the exchange into a main wallet and then spread the funds across several others.

"Initially, the stolen funds were transferred to a primary wallet, which then distributed them across more than 40 wallets," Nansen said. "The attackers converted all stETH, cmETH, and mETH to ETH before systematically transferring ETH in $27 million increments to over 10 additional wallets," Nansen said.

The attack appeared to have been caused by something called "Blind Signing," where a smart contract transaction is approved without the comprehensive knowledge of its contents.

"This attack vector is quickly becoming the favorite form of cyber attack used by advanced threat actors, including North Korea," said blockchain security firm Blockaid's CEO Ido Ben Natan. "It’s the same type of attack that was used in the Radiant Capital breach and the WazirX incident."

"The problem is that even with the best key management solutions, today most of the signing process is delegated to software interfaces that interact with dApps. This creates a critical vulnerability — it opens the door for malicious manipulation of the signing process, which is exactly what happened in this attack," he said.

Bybit CEO Ben Zhou wrote earlier on X that a hacker "took control of the specific ETH cold wallet and transferred all the ETH in the cold wallet to this unidentified address." He also confirmed that the exchange "is solvent even if this hack loss is not recovered."

Comments

All Comments

Recommended for you

  • Trump Hints at 'Good News' on Iran Issue

    On April 18, U.S. President Donald Trump stated that there is some 'pretty good news' regarding the Iran issue, but he declined to provide further details. 'We heard some pretty good news about 20 minutes ago, and it seems that progress related to Iran in the Middle East is going very smoothly,' Trump told reporters aboard Air Force One. When asked what the so-called good news was, Trump replied, 'You will hear it. I think it is something that should happen. It is a matter of course. And I believe it will happen. We will see, but I think it will happen.' (Jinshi)

  • Trump Suggests War Will Resume if No Agreement with Iran is Reached

    On April 18, President Trump told reporters aboard Air Force One that if an agreement with Iran is not reached by Wednesday, war will resume. When asked if he was prepared to extend the ceasefire agreement if no deal is made by the time the ceasefire expires on Wednesday, Trump replied, "Maybe I won't extend the ceasefire. But the blockade will continue. So, the blockade remains in place, and unfortunately, we will have to start dropping bombs again," Trump warned.

  • Chinese Ship Trapped in Strait of Hormuz Informs Crew to Prepare for Departure

    On April 18, according to Yicai, around 4 PM local time on the 17th, the Chinese ship trapped in the Strait of Hormuz has informed its crew to 'prepare for departure.' According to CCTV, on the afternoon of the 17th, Iranian Foreign Minister Amir-Abdollahian stated on social media that, based on the ceasefire agreement in Lebanon, all commercial vessels are allowed to pass through the Strait of Hormuz completely open during the remaining time of the ceasefire, following the coordinated routes announced by Iranian ports and maritime organizations.

  • DeepSeek Seeks Over $300 Million in First Round of External Funding

    According to The Information, DeepSeek is seeking over $300 million in its first round of external funding, with a valuation exceeding $10 billion.

  • BTC Surpasses $78,000

    Market data shows that BTC has surpassed $78,000, currently priced at $78,024.64, with a 24-hour increase of 5.63%. The market is highly volatile, so please ensure proper risk management.

  • BTC Surpasses $77,000

    Market data shows that BTC has surpassed $77,000, currently priced at $77,022.24, with a 24-hour increase of 3.42%. Due to significant market fluctuations, please ensure proper risk management.

  • US and Iran Discuss Plan to End War

    On April 17, U.S. media reported, citing two American officials and two sources familiar with the negotiations, that the United States and Iran are communicating about a plan aimed at ending the war. One key topic is the U.S. potentially unfreezing $20 billion of Iran's frozen assets in exchange for Iran giving up its enriched uranium stockpile. The report also quoted another source familiar with the mediation efforts, stating that negotiations are expected to take place this Sunday in Islamabad, the capital of Pakistan. (Xinhua News Agency)

  • ETH Surpasses $2400

    Market data shows that ETH has surpassed $2400, currently priced at $2402.37, with a 24-hour increase of 2.58%. The market is experiencing significant volatility, so please ensure proper risk management.

  • US Plans to Unfreeze $20 Billion in Funds for Iran's Uranium Cessation

    On April 17, according to AXIOS, two US officials and two sources familiar with the negotiations revealed that the US and Iran are negotiating a three-page plan to end the conflict, one element of which involves the US unfreezing $20 billion of Iranian funds in exchange for Iran abandoning its enriched uranium stockpile. According to the two sources, in the early stages of negotiations, the US proposed unfreezing $6 billion for humanitarian supplies, while Iran requested $27 billion. The latest figures being discussed between the US and Iran are $20 billion. One US official stated that this is the US proposal. Another US official described the concept of 'cash for uranium' as 'one of many discussions.' Meanwhile, the US is demanding that Iran agree to send all its nuclear materials to the US, while Iran has only agreed to 'dilution' within its territory. Under the compromise being discussed, some highly enriched uranium would be sent to a third country (not necessarily the US), while some would be diluted under international supervision within Iran.

  • Iranian Foreign Minister Amir-Abdollahian: Commercial Shipping in the Strait of Hormuz is Open

    On April 17, Iranian Foreign Minister Amir-Abdollahian announced that commercial shipping in the Strait of Hormuz is now open.