{"id":10291,"date":"2024-04-18T02:18:46","date_gmt":"2024-04-18T02:18:46","guid":{"rendered":"https:\/\/www.bitrabo.com\/discover\/chain-of-exploits-investigator-unveils-connection-between-multiple-crypto-hacks\/"},"modified":"2024-04-18T02:18:46","modified_gmt":"2024-04-18T02:18:46","slug":"chain-of-exploits-investigator-unveils-connection-between-multiple-crypto-hacks","status":"publish","type":"post","link":"https:\/\/www.bitrabo.com\/discover\/chain-of-exploits-investigator-unveils-connection-between-multiple-crypto-hacks\/","title":{"rendered":"Chain Of Exploits? Investigator Unveils Connection Between Multiple Crypto Hacks"},"content":{"rendered":"<p style=\"font-weight: 400\">Over the years, crypto hacks have become more elaborate and common. In 2024, the community has seen hundreds of millions swept away from exploits and scams, leaving investors empty-handed.<\/p>\n<p style=\"font-weight: 400\">Sometimes, the exploiters return the funds and point out a project\u2019s vulnerabilities, helping prevent future incidents. However, it\u2019s more common to see hackers take the stolen funds and flee the scene.<\/p>\n<p style=\"font-weight: 400\">Crypto investigator ZachXBT unveiled a chain of exploits seemingly connected to the self-called Whitehat hacker responsible for the Prisma Finance exploit that took $12 million last month.<\/p>\n<h2 style=\"font-weight: 400\"><span class=\"ez-toc-section\" id=\"Stained_Whitehat_Hacker\"><\/span>Stained Whitehat Hacker<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p style=\"font-weight: 400\">On March 28, Prisma Finance, the Ethereum-based decentralized lending protocol, suffered a hack that stole 3,479.24 ETH. After being warned and observing the suspicious activity, Prisma&#8217;s team alerted the community.<\/p>\n<p style=\"font-weight: 400\">At the time, the hacker contacted the Prisma team through an on-chain message, declaring to be a &#8220;Whitehat\u201d looking out for users. During their conversation, the exploiter claimed they wanted to \u201craise better awareness on serious contract audits\u201d and the use of DeFi.<\/p>\n<p style=\"font-weight: 400\">The following day, the lending protocol released a detailed post-mortem of the incident. This post seemingly ruffled the hacker\u2019s feathers, as they demanded that the team change all the \u201caccusatory terms\u201d like \u2018exploit\u2019 and \u2018hacker.\u2019<\/p>\n<p style=\"font-weight: 400\">The messages raised alarms about whether the funds would be returned. Seemingly unsatisfied with the Prisma team\u2019s compliance to edit the post-mortem post, the exploiter asked for a bounty of $3.8 million, worth 34% of the total funds.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">1\/ An investigation into the alleged $11.1M <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/PrismaFi?ref_src=twsrc%5Etfw\">@PrismaFi<\/a> exploiter 0x77 (Trung) and the multiple other exploits they are connected to. <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/t.co\/QU1Oy7Txbb\">pic.twitter.com\/QU1Oy7Txbb<\/a><\/p>\n<p>&mdash; ZachXBT (@zachxbt) <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/zachxbt\/status\/1780244613808160958?ref_src=twsrc%5Etfw\">April 16, 2024<\/a><\/p>\n<\/blockquote>\n<p style=\"font-weight: 400\">The amount asked was triple the industry standard of 10%. According to the crypto detective, the exploiter was \u201cessentially extorting the team\u201d as the treasury didn\u2019t have enough funds to reimburse the victims.<\/p>\n<p style=\"font-weight: 400\">Despite the Whitehat claims and apparent discomfort with terms that stated otherwise, the hacker contradicted himself by sending the funds to Tornado Cash. Further investigation by the crypto detective revealed that this Whitehat has several stains.<\/p>\n<h2 style=\"font-weight: 400\"><span class=\"ez-toc-section\" id=\"Prismas_Exploiter_Connected_To_Several_Crypto_Hacks\"><\/span>Prisma\u2019s Exploiter Connected To Several Crypto Hacks<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p style=\"font-weight: 400\">ZachXBT\u2019s deep dive into the timing of related transactions resulted in the discovery of \u201cactivity connected to them on Tron.\u201d One address, TGviNZ, was linked to numerous exploits.<\/p>\n<p style=\"font-weight: 400\">Per the investigation, TGviNZ was <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/x.com\/zachxbt\/status\/1780244639066243417\">funded<\/a> by the Arcade_xyz exploit from March 2023. During this incident, the exploiter requested additional funds from the project via Telegram.<\/p>\n<p style=\"font-weight: 400\">Similarly, the address was connected to the Pine Protocol exploit from February 2024. This time, the hacker asked for 50% of the funds and allegedly made \u201cadditional unreasonable requests over email.\u201d<\/p>\n<p><\/p>\n<p style=\"font-weight: 400\">The crypto sleuth then discovered that TGviNZ is linked to the deployer of Modulus protocol, a \u201cdecentralized, non-custodian platform.\u201d \u00a0Further investigation revealed that an X user, \u201c0x77,\u201d was among the few followers of the protocol.<\/p>\n<p style=\"font-weight: 400\">This proved crucial in piecing together the puzzle, as the Arcade exploiter used the alias \u201c0x77\u201d on Telegram. A deeper look into the phone number, email addresses used, and other details pointed out the same suspect behind these exploits.<\/p>\n<p style=\"font-weight: 400\">The details of the suspected exploiter are now in the hands of the Prisma team, which is investigating whether to pursue legal action against the individual in Vietnam and Australia.<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"alignnone size-large wp-image-295034 aligncenter\" src=\"https:\/\/www.bitrabo.com\/discover\/wp-content\/uploads\/2024\/04\/Chain-Of-Exploits-Investigator-Unveils-Connection-Between-Multiple-Crypto-Hacks.png\" alt=\"Crypto, TOTAL,\" width=\"980\" height=\"468\" data-recalc-dims=\"1\" \/><\/p>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Over the years, crypto hacks have become more elaborate and common. In 2024, the community has seen hundreds of millions swept away from exploits and scams, leaving investors empty-handed. Sometimes, the exploiters return the funds and point out a project\u2019s vulnerabilities, helping prevent future incidents. However, it\u2019s more common to see hackers take the stolen [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":10292,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"slim_seo":{"title":"Chain Of Exploits? Investigator Unveils Connection Between Multiple Crypto Hacks - Bitrabo","description":"Over the years, crypto hacks have become more elaborate and common. In 2024, the community has seen hundreds of millions swept away from exploits and scams, lea"},"footnotes":""},"categories":[316],"tags":[1869,3481,504,1770,3482,2412,3167,801],"class_list":["post-10291","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto-news","tag-chain","tag-connection","tag-crypto","tag-exploits","tag-hacks","tag-investigator","tag-multiple","tag-unveils"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/posts\/10291","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/comments?post=10291"}],"version-history":[{"count":0,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/posts\/10291\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/media\/10292"}],"wp:attachment":[{"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/media?parent=10291"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/categories?post=10291"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/tags?post=10291"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}