Elliptic: Lazarus hackers returned to using Tornado Cash after blocking the Sinbad mixer
Hackers have started moving funds from the HTX crypto exchange hack into Tornado
![Elliptic: Lazarus hackers returned to using Tornado Cash after blocking the Sinbad mixer](https://storage.getblock.net/source/1/jPkl5UKdxdGGi2mevUst1KZQVedw3EfT.webp)
15.03.2024 - 08:10
183
3 min
0
What’s new? Elliptic analysts have recorded the movement of funds related to the hack of the HTX exchange and its HECO cross-chain protocol. The attack, which experts attribute to the North Korean group Lazarus, caused the platforms to lose $100 million in November 2023. The stolen funds remained stationary for a long time, but on March 13, they began moving into the Tornado Cash crypto mixer, which was placed on a sanctions list by the US Treasury Department back in August 2022.
What else is known? Following common cryptocurrency laundering schemes, immediately after the hack, the hackers exchanged the stolen tokens for ETH coins using decentralized exchanges (DEXs) but then suspended further transfers.
Lazarus then sent over $12 million to Tornado Cash in more than 40 transactions on March 13 and 14. The service was banned by US authorities for helping to launder $455 million stolen by Lazarus. In response, the group stopped using Tornado Cash and switched to using another crypto mixer called Sinbad.
Then in November 2023, the US Treasury Department banned Sinbad as well, also for its ties to DPRK hackers, eliminating its continued use by Lazarus.
![Backdoor has been discovered in the Tornado Cash interface to intercept deposit data](https://storage.getblock.net/source/1/Z0k3dgGv-WQOhe8MdivXS7cLMyh0XEeF.png)
Backdoor has been discovered in the Tornado Cash interface to intercept deposit data
According to community representatives, it has been functioning for two months
However, Elliptic notes that Tornado Cash continues to operate despite the sanctions. The service uses smart contracts on decentralized blockchains, so it can not be seized and shut down in the same way centralized mixers like Sinbad can.
“Lazarus Group now appear to have returned to using Tornado Cash as a way to launder funds at scale and obfuscate their transaction trail,” the company concluded.
In 2023, DPRK hackers carried out a record number of attacks on crypto projects. The damage in this case decreased in comparison with the record of 2022, amounting to just over $1 billion.
Later, the United States, South Korea, and Japan announced the beginning of joint development of measures to combat crypto hackers from the DPRK.
Useful material?
Market
Australia’s largest financial institutions have refused to process payments to digital asset trading platforms due to the risk of fraud
Jul 26, 2024
Politics
According to the politician, the value of the country’s bitcoin reserves should equal the value of gold reserves
Jul 26, 2024
Mining
The capacity of the Bitaxe device used by the network participant is only 500 Gh/s
Jul 25, 2024
Trends
Meanwhile, Trump-inspired assets have not shown significant growth
Jul 22, 2024
Market
The fee will be as much as 2,5% compared to 0,25-0,19% for competitors
Jul 18, 2024
Market
This is the third consecutive month of decline
Jul 18, 2024