Elliptic: North Korean hackers may be behind Harmony hack
According to analysts, the exploit and money laundering tactics through the mixer are similar to other incidents that have been linked to the Lazarus group
30.06.2022 - 11:00
495
3 min
0
What’s new? Analysts at Elliptic said that the Lazarus Group hacker group from North Korea may be behind the Horizon bridge hack on the Harmony network. The exploit was carried out by compromising multi-signature wallet cryptographic keys, likely using social engineering techniques against members of the Harmony team. It is noted that this method was frequently used by the Lazarus hackers.
Investigation details. Elliptic has highlighted several other reasons indicating that a North Korean group may have been behind the hack. Lazarus tends to focus on targets in the Asia-Pacific region, perhaps for linguistic reasons. Although Harmony is based in the US, many members of the core team have ties to this region.
According to experts, the attackers have already sent more than 35 000 ETH ($39 million) through the Tornado Cash transaction mixer, which is about 41% of the funds stolen as a result of the exploit. Experts stressed that the transfer continues.
According to the analysts, the regularity of the transfers allows the use of automated software for these purposes. Experts observed a similar method during the laundering of funds stolen from the Ronin sidechain, which Lazarus hackers are suspected to be behind the hack. The attackers back then withdrew more than $625 million in cryptocurrency. Elliptic added that the periods during which the stolen funds stop being withdrawn from Tornado Cash correspond to the night hours in the Asia-Pacific region.
Hacking investigation. Horizon was subjected to an exploit on the morning of June 24. Hackers withdrew $100 million in cryptocurrency and then exchanged the assets on the Uniswap exchange. On June 26, the Harmony developers offered the attackers $1 million for the return of the rest funds and information about the exploited vulnerability, adding that they would oppose criminal prosecution if they did so. On June 28, Harmony said that it was cooperating with the FBI and blockchain analytics companies to investigate the hack. The reward was later increased to $10 million and given until July 4 to recover the stolen funds.
1/ Harmony has begun a global manhunt for the criminal(s) who stole $100M from the Horizon bridge. All exchanges have been notified. Law enforcement, @Chainalysis, and @AnChainAI have active investigations to identify the responsible actors and recover the stolen assets.— Harmony 💙 (@harmonyprotocol) June 30, 2022
Useful material?
Incidents
The search, the reason for which was not announced, took place a week after the election, the results of which Polymarket users predicted quite accurately
Nov 14, 2024
Market
Analysts point to the growing popularity of the first cryptocurrency as a safe haven asset
Nov 13, 2024
Market
The product will begin trading on the Swiss Exchange on November 19
Nov 12, 2024
Market
The company’s unrealized profits from investing in the first cryptocurrency approached $13 billion
Nov 12, 2024
Market
The company predicts that the rate of the first cryptocurrency will grow to $200 000 by the end of next year
Nov 11, 2024
Technologies
The company also unveiled its own blockchain adoption index
Nov 11, 2024