Cointime

Download App
iOS & Android

White Hat v. Black Hat: What Really Happened With the FTX Hack?

Cointime Official

Bankruptcy lawyers are battling Bahamian regulators over crypto tied to former billionaire Sam Bankman-Fried’s FTX empire — raising questions about a peculiar half-billion-dollar hack on the exchange last week.

Last weekend, blockchain analytics unit Elliptic reported that $663 million in various cryptocurrencies had been drained from FTX wallets just 24 hours after 134 affiliated entities had filed for Chapter 11 bankruptcy on Nov. 11.

Elliptic at the time attributed $186 million of those outflows to FTX personnel, who’d appeared to be securing compromised funds to avoid further losses. The remaining $447 million in digital assets were said to have been siphoned in “unauthorized transfers,” with $220 million cashed out for ether and stablecoin DAI. Blockchain data shows the attacker interacting with decentralized exchanges such as Uniswap alongside aggregators 1inch and CoW Protocol.

At the time of the attack, FTX representatives in the firm’s Telegram channel characterized the situation as a hack and urged FTX users not to interact with the exchange’s website and apps for fear of malware.

FTX US general counsel Ryne Miller later shared a statement from FTX’s appointed restructurer John J. Ray III, who confirmed that “unauthorized access to certain assets has occurred.”

Fast forward to Thursday, and the Securities Commission of the Bahamas announced via Twitter it had assumed control of assets belonging to FTX Digital Markets, leading onlookers to question whether the commission was the hacker — albeit a “white hat” — all along.

“On [Nov. 12], the Commission, in the exercise of its powers as regulator acting under the authority of an Order made by the Supreme Court of the Bahamas, took the action of directing the transfer of all digital assets of FTX Digital Markets to a digital wallet controlled by the Commission, for safekeeping,” the Commission said.

It went on: “Urgent interim regulatory action was necessary to protect the interests of clients and creditors of FTX Digital Markets.”

The statement aligns with evidence provided by FTX representatives in their court filing, released shortly after the Commission’s tweet. They say government officials allegedly directed Bankman-Fried and co-founder Gary Wang — described as “effectively in the custody of Bahamas authorities” — to make the presumably unauthorized transfers.

According to FTX lawyers, the crypto is being kept with New York-based direct custody-service startup Fireblocks under control of the Bahamian government. Fireblocks declined to comment on the record.

FTX hacker could’ve been in waiting for a long time

The question remains: Was FTX actually hacked? On-chain data reviewed by Blockworks does indeed show addresses linked to an attacker draining almost half a billion dollars in various cryptocurrencies from FTX hot wallets — including FTX US — on Nov. 12.

Tokens were apparently siphoned across multiple blockchains including Ethereum, Solana and Binance Chain. Cryptocurrencies such as gold-pegged asset pax gold, tether, ether, chainlink, shiba inu and bitcoin all featured prominently in the haul, as well as aave and apecoin.

As earlier noted by Elliptic, much of the funds in question were quickly sold for MakerDAO’s decentralized stablecoin DAI and ether — assets considered uncensorable. Notably, no funds were sent to crypto mixers such as Tornado Cash.

Tether, on the other hand, quickly moved to freeze around $47 million in USDT, rendering the tokens moot and valueless.

But Tom Robinson, chief scientist at Elliptic, isn’t totally convinced the incident was a hack. In an email to Blockworks, Robinson explained that based on the information shared publicly it’s still not clear exactly what happened. But his interpretation would be that the Bahamian regulator gave instructions to convert the stablecoins and other tokens into ETH and DAI to avoid them being frozen by their issuers.

“That or whoever was directed to move the assets took it upon themselves to perform the conversion. But that’s just speculation on my part at the moment,” Robinson said.

Bankman-Fried addressed the apparent hack in recent conversations with Vox journalist Kelsey Piper, saying that the hacker was either a disgruntled employee or a bad actor who had smuggled malware onto an employees machine, leading to compromised hot wallet private keys.

Indeed, court filings recently showed just how lax FTX cybersecurity practices were. Lawyers maintain that former CEO Bankman-Fried and chief technology officer Wang used an “unsecured group email account to access confidential private keys and other critically sensitive information.”

Retrieving FTX’s stolen crypto could take years — if at all

To Nick Bax, head of research at crypto research and development startup Convex Labs, this leaves open the possibility that a company insider was phished — which could’ve directly led to the hack last week. Similar prominent thefts have been linked to the Lazarus hacking group affiliated with the North Korean government, which has cultivated vulnerabilities within crypto companies, although there has been no direct evidence or allegations made by law enforcement in this case.

Bax remained confident that the initial Ethereum wallet labeled as FTX Account Drainer on Etherscan was a black hat hacker. He described a scenario where a hacker had gotten to FTX’s unsecured email account and FTX private keys.

“Like everybody else, you think FTX has $10 billion or $20 billion — what do you do? Stay in the network and wait for your opportunity to steal it all,” Bax said.

“We do know in other cases, sophisticated or state-sponsored hackers, they had an opportunity to steal a life-changing amount of money, but they stayed and maintained their foothold in the network for months and months, waiting for the opportunity to maximize their theft. In the case of FTX, they could’ve realized that FTX was actually insolvent at the same time as everybody else, and just pulled what they could.”

Kraken Chief Security Officer Nick Percoco tweeted at the time of the attack that the exchange knew the identity of the attacker, as Kraken accounts had funded certain transaction fees for some illicit transactions. Percoco later appeared to walk those comments back, tweeting that the accounts in question may have belonged to FTX, and the cited transactions may have been part of efforts to safeguard crypto from the attack. Blockworks has reached out for comment.

But whether it was a disgruntled employee, North Korean hackers or someone else, the matter of whether the funds could eventually be retrieved and returned to FTX creditors is unclear.

Bax, who has worked extensively in cryptoasset recovery on behalf of hacking victims, explained that retrieving the funds begins with identifying the hacker.

“There’s been several large recoveries from the Silk Road hack and those took years. There’s been a partial recovery from the North Korean hacks of the Ronin network, but they only got around 20% back,” Bax said.

“It really depends on who it is, if it’s an insider — it’s not that hard. If it’s the North Koreans who hacked the insider, then good luck.”

(By DAVID CANELLIS& SEBASTIAN SINCLAIR)

https://blockworks.co/news/what-happened-ftx-hack

Comments

All Comments

Recommended for you

  • 38,244.04 DMD Permanently Burned in the Past 7 Days

    On June 25, 2026, the latest on-chain data from DMDAO revealed that a total of 38,244.04 DMD has been permanently burned through the established transaction and wealth management burn mechanisms over the past 7 calendar days.

  • BTC Falls Below $60,000

    Market data shows that BTC has fallen below $60,000, currently priced at $59,954.84, with a 24-hour decline of 4.19%. The market is experiencing significant volatility, so please ensure proper risk management.

  • ETH Drops Below $1600

    Market data shows that ETH has fallen below $1600, currently priced at $1597.55, with a 24-hour decline of 3.81%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Billionaire Philippe Laffont Prefers Investing in Space Over Bitcoin

    Philippe Laffont, founder and portfolio manager of Coatue Management, stated on the Squawk Box program that he is currently unable to determine his stance on Bitcoin. He mentioned that he is rethinking Bitcoin's positioning and expressed a preference for investing in space over Bitcoin. (thestreet)

  • Tech Giants' Data Center Leasing Commitments Exceed $850 Billion

    On June 24, an analysis by Bloomberg of regulatory filings revealed that as tech giants compete to expand their server clusters, the total amount of future data center leasing commitments by large cloud computing companies has continued to rise over the past year, surpassing $850 billion. Last quarter, Meta added leasing commitments of $79 billion, a 76% increase from the previous period; as of March 31, the total reached $182.9 billion. Meta CEO Mark Zuckerberg has stated that the company plans to invest hundreds of billions of dollars in AI infrastructure by 2030. Microsoft followed closely, adding over $41 billion in leasing commitments, bringing its total to $196.6 billion.

  • Address with $34.61 Million Long Position in 21,000 ETH Faces $1.696 Million Loss at 18x Leverage

    According to on-chain analyst Ai Yi, a certain address took a long position of 21,000 ETH with 18x leverage yesterday, amounting to approximately $34.61 million. Currently, it is facing an unrealized loss of $1.696 million, with an opening price of $1,728.5 and a liquidation price of $1,590.1.

  • U.S. 10-Year Treasury Yield Falls to 4.4138%, Lowest Since May 11

    On June 24, the yield on U.S. 10-year Treasury bonds fell to 4.4138%, the lowest level since May 11. The yield on U.S. 30-year Treasury bonds dropped to 4.8572%, the lowest since April 15.

  • Crypto Market Liquidations Reach $134 Million in the Last Hour, with $125 Million in Long Liquidations

    According to CoinGlass data, the total liquidation amount across the network in the last hour reached $134 million, with long liquidations accounting for $125 million and short liquidations amounting to $8.539 million.

  • BTC Falls Below $61,000

    Market data shows that BTC has fallen below $61,000, currently priced at $60,986.03, with a 24-hour decline of 2.88%. The market is experiencing significant volatility, so please ensure proper risk management.

  • International Oil Prices Plunge as U.S. Oil Futures Fall Below $70

    On June 24, international crude oil prices continued to decline, with U.S. WTI crude oil futures falling below the $70 per barrel mark during trading, down 4.4% for the day, reaching a new low since March 2, and reverting to levels seen before the outbreak of the Iran conflict. Brent crude oil futures for August dropped 4.5%, settling at $73.6 per barrel. Market expectations of easing tensions in the Middle East, a recovery in Iranian oil supply, and rising interest rate expectations due to U.S. inflation have pressured oil prices.