{"id":8875,"date":"2024-03-15T05:05:24","date_gmt":"2024-03-15T05:05:24","guid":{"rendered":"https:\/\/www.bitrabo.com\/discover\/massive-ethereum-laundering-operation-north-korean-hackers-exploit-tornado-cash-for-12m\/"},"modified":"2024-03-15T05:05:24","modified_gmt":"2024-03-15T05:05:24","slug":"massive-ethereum-laundering-operation-north-korean-hackers-exploit-tornado-cash-for-12m","status":"publish","type":"post","link":"https:\/\/www.bitrabo.com\/discover\/massive-ethereum-laundering-operation-north-korean-hackers-exploit-tornado-cash-for-12m\/","title":{"rendered":"Massive Ethereum Laundering Operation: North Korean Hackers Exploit Tornado Cash For $12M"},"content":{"rendered":"<p>In a recent development, North Korean hackers associated with the notorious Lazarus Group have exploited the coin-mixing service Tornado Cash to launder approximately $12 million worth of stolen Ethereum (ETH) within the past 24 hours.\u00a0<\/p>\n<p>The incident follows the theft of $100 million in cryptocurrency from the HTX crypto exchange and its HECO Bridge in November 2023, attributed to the Lazarus Group by blockchain analytics firm Elliptic and other experts.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"100M_Crypto_Heist_And_Ethereum_Laundering_Uncovered\"><\/span>$100M Crypto Heist And Ethereum Laundering Uncovered<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The Lazarus Group, a well-known cybercrime organization believed to be backed by the North Korean regime, has a long history of conducting high-profile hacking campaigns.\u00a0<\/p>\n<p>According to Elliptic&#8217;s latest crypto crime <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.elliptic.co\/blog\/north-korean-hackers-return-to-tornado-cash-despite-sanctions\">report<\/a>, in November 2023, the notorious Lazarus Group allegedly orchestrated a major heist targeting the HTX crypto exchange and its cross-chain bridge, resulting in the theft of $100 million in various cryptocurrencies, including Ethereum.\u00a0<\/p>\n<p>Evidence gathered by Elliptic and other experts pointed to the involvement of the Lazarus Group based on the modus operandi and subsequent movement of the stolen funds.<\/p>\n<p>The investigation further notes that, following their \u201cusual pattern\u201d of crypto-laundering, the hackers quickly converted the stolen tokens into Ethereum through decentralized exchanges (DEXs).\u00a0<\/p>\n<p>These illicitly acquired Ethereum funds remained dormant until recently, on March 13, when the hackers began funneling them through Tornado Cash. Tornado Cash is a decentralized, smart contract-based mixer previously sanctioned by the US Treasury in August 2022 for its association with laundering $455 million from the Lazarus Group crypto hacks. <\/p>\n<p>However, the decentralized nature of Tornado Cash&#8217;s operations has prevented it from being shut down like centralized mixers like Sinbad.io.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"The_Last_Resort_For_Lazarus_Group\"><\/span>The Last Resort For Lazarus Group<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>According to the blockchain analytics firm, in response to the sanctions imposed on Tornado Cash, the Lazarus Group shifted its focus to using cross-chain bridges and the Bitcoin-based mixer Sinbad.io as an alternative.\u00a0<\/p>\n<p>However, in November 2023, Sinbad.io itself was seized by US authorities, eliminating another commingling option for the hackers. As a result, the group appears to have returned to Tornado Cash, using its decentralized architecture and resistance to raids to launder funds at scale and obscure its transaction trail.<\/p>\n<p>Ultimately, Elliptic suggests that the resurgence of the Lazarus Group&#8217;s reliance on Tornado Cash can be attributed to the \u201cdiminishing availability\u201d of large-scale mixers due to law enforcement operations targeting services like Sinbad.io and Blender.io.\u00a0<\/p>\n<p>With fewer viable alternatives, the group has capitalized on Tornado Cash&#8217;s continued operation despite sanctions, exploiting smart contracts&#8217; security and decentralized nature on blockchain networks.<\/p>\n<p><\/p>\n<p>As of the time of writing, Ethereum is currently trading at $3,870. Earlier this week, it reached a two-year high of $4,084; however, it failed to sustain consolidation above this level. Consequently, over the past 24 hours, ETH has experienced a 2.5% decline in price.<\/p>\n<p>Featured image from Shutterstock, chart from TradingView.com <\/p>\n","protected":false},"excerpt":{"rendered":"<p>In a recent development, North Korean hackers associated with the notorious Lazarus Group have exploited the coin-mixing service Tornado Cash to launder approximately $12 million worth of stolen Ethereum (ETH) within the past 24 hours.\u00a0 The incident follows the theft of $100 million in cryptocurrency from the HTX crypto exchange and its HECO Bridge in [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":8876,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"slim_seo":{"title":"Massive Ethereum Laundering Operation: North Korean Hackers Exploit Tornado Cash For $12M - Bitrabo","description":"In a recent development, North Korean hackers associated with the notorious Lazarus Group have exploited the coin-mixing service Tornado Cash to launder approxi"},"footnotes":""},"categories":[316],"tags":[2525,654,768,1293,648,2524,823,1927,2523,2522,653],"class_list":["post-8875","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto-news","tag-12m","tag-cash","tag-ethereum","tag-exploit","tag-hackers","tag-korean","tag-laundering","tag-massive","tag-north","tag-operation","tag-tornado"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/posts\/8875","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/comments?post=8875"}],"version-history":[{"count":0,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/posts\/8875\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/media\/8876"}],"wp:attachment":[{"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/media?parent=8875"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/categories?post=8875"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bitrabo.com\/discover\/wp-json\/wp\/v2\/tags?post=8875"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}