$237 701 000 USD

AUGUST 2024

GLOBAL

NONE

DESCRIPTION OF EVENTS

"It appears that some of the source funds may be related to Genesis Global Trading" "Notably, the wallet had received 642.4 BTC, worth approximately $37.73 million, from the Genesis Trading Bankruptcy Distributions wallet just two weeks before the breach, while another 2,173 BTC, valued at $127.6 million, had been transferred from Genesis Trading two years earlier."

 

They had also made transactions promoting memo.sv topic hmwyda, which stands for "How much would you donate anonymously?" and features hundreds of users asking for bitcoin donations for various causes, some of which have been funded.

 

"While the exact method of the hack remains unclear, experts believe the attackers may have used a combination of phishing, social engineering, and exploiting vulnerabilities in wallet security."

 

$238,000,000 (4064.37689539 BTC) $58,483.96 x 4064.37689539 BTC = $237,700,855.77

 

"According to on-chain investigator ZachXBT, a suspicious transfer was made from a potential victim for 4064 BTC ($238M). The funds were quickly moved to ThorChain, eXch, Kucoin, ChangeNow, Railgun, and Avalanche Bridge. As of August 27th, $505,000 has been recovered."

 

"After the initial theft, the 4,064 BTC was quickly divided into smaller amounts and transferred across various platforms. This complex series of transactions was designed to make it difficult to trace the funds back to their original source."

 

"However, when the hackers attempted to use RAILGUN to shield the funds, the effort failed. The stolen Bitcoin did not meet the criteria for privacy within RAILGUN, leading to its unshielding and return, which left the stolen assets exposed rather than protected by the intended privacy protocols."

 

"Whilst RAILGUN is permissionless and anyone can send tokens in, any tokens that fail to generate a Private POI proof CANNOT enter the privacy set. In this case, the tokens @zachxbt mentioned were unshielded back to the original address and gained no privacy."

 

"The transaction map further illustrates the movement of a portion of the stolen Bitcoin through the Avalanche Bridge, which likely facilitated cross-chain transfers. This step added another layer of complexity to the hackers’ efforts to obscure the trail.

 

In addition to using these platforms, the hackers employed mixing services to further complicate the traceability of the funds, effectively combining multiple transactions to mask the origins and destinations of the Bitcoin."

 

"Per the detailed fund map Xian shared, 3,163.59 BTC originated from three wallets linked to Genesis Global trading. These funds were moved in three transfers of 50 BTC, 1,000 BTC, and 2,113.59 BTC."

 

"When asked whether the Lazarus Group was responsible for the incident, ZachXBT said “Not this time,” noting that the funds’ movement was “a bit different.”"

 

Efforts to recover the funds continue.

A bitcoin whale who was likely involved with Genesis Trading and had previously promoted an anonymous donation group on memo.sv saw their entire fortune of 4064.37689539 BTC wiped out. The funds were quickly distributed across a wide range of protocols including ThorChain, eXch, Kucoin, ChangeNow, Railgun, and Avalanche Bridge. RailGun came out to declare that the thieves had not gained any privacy through their protocol as they had failed the Proof of Innocense model. Some $505k was recovered from swaps conducted through Firn Protocol and NonKYC.io. Firn Protocol closed down their services due to the risk after this incident. Efforts to recover the remaining funds continue.

Sources And Further Reading

 For questions or enquiries, email info@quadrigainitiative.com.

Get Social

  • email
  • reddit
  • telegram
  • Twitter

© 2021 Quadriga Initiative. Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected Users. Hosted in Canada by HosterBox.