QUADRIGA INITIATIVE
CRYPTO WATCHDOG & FRAUD RECOVERY PLATFORM
A COMMUNITY-BASED, NOT-FOR-PROFIT
$237 701 000 USD
AUGUST 2024
GLOBAL
NONE
DESCRIPTION OF EVENTS
"It appears that some of the source funds may be related to Genesis Global Trading" "Notably, the wallet had received 642.4 BTC, worth approximately $37.73 million, from the Genesis Trading Bankruptcy Distributions wallet just two weeks before the breach, while another 2,173 BTC, valued at $127.6 million, had been transferred from Genesis Trading two years earlier."
They had also made transactions promoting memo.sv topic hmwyda, which stands for "How much would you donate anonymously?" and features hundreds of users asking for bitcoin donations for various causes, some of which have been funded.
"While the exact method of the hack remains unclear, experts believe the attackers may have used a combination of phishing, social engineering, and exploiting vulnerabilities in wallet security."
$238,000,000 (4064.37689539 BTC) $58,483.96 x 4064.37689539 BTC = $237,700,855.77
"According to on-chain investigator ZachXBT, a suspicious transfer was made from a potential victim for 4064 BTC ($238M). The funds were quickly moved to ThorChain, eXch, Kucoin, ChangeNow, Railgun, and Avalanche Bridge. As of August 27th, $505,000 has been recovered."
"After the initial theft, the 4,064 BTC was quickly divided into smaller amounts and transferred across various platforms. This complex series of transactions was designed to make it difficult to trace the funds back to their original source."
"However, when the hackers attempted to use RAILGUN to shield the funds, the effort failed. The stolen Bitcoin did not meet the criteria for privacy within RAILGUN, leading to its unshielding and return, which left the stolen assets exposed rather than protected by the intended privacy protocols."
"Whilst RAILGUN is permissionless and anyone can send tokens in, any tokens that fail to generate a Private POI proof CANNOT enter the privacy set. In this case, the tokens @zachxbt mentioned were unshielded back to the original address and gained no privacy."
"The transaction map further illustrates the movement of a portion of the stolen Bitcoin through the Avalanche Bridge, which likely facilitated cross-chain transfers. This step added another layer of complexity to the hackers’ efforts to obscure the trail.
In addition to using these platforms, the hackers employed mixing services to further complicate the traceability of the funds, effectively combining multiple transactions to mask the origins and destinations of the Bitcoin."
"Per the detailed fund map Xian shared, 3,163.59 BTC originated from three wallets linked to Genesis Global trading. These funds were moved in three transfers of 50 BTC, 1,000 BTC, and 2,113.59 BTC."
"When asked whether the Lazarus Group was responsible for the incident, ZachXBT said “Not this time,” noting that the funds’ movement was “a bit different.”"
Efforts to recover the funds continue.
A bitcoin whale who was likely involved with Genesis Trading and had previously promoted an anonymous donation group on memo.sv saw their entire fortune of 4064.37689539 BTC wiped out. The funds were quickly distributed across a wide range of protocols including ThorChain, eXch, Kucoin, ChangeNow, Railgun, and Avalanche Bridge. RailGun came out to declare that the thieves had not gained any privacy through their protocol as they had failed the Proof of Innocense model. Some $505k was recovered from swaps conducted through Firn Protocol and NonKYC.io. Firn Protocol closed down their services due to the risk after this incident. Efforts to recover the remaining funds continue.
SlowMist Hacked - SlowMist Zone (Sep 4)
@zachxbt Twitter (Sep 4)
Transaction: 4b277ba298830ea538086114803b9487558bb093b5083e383e94db687fbe9090 | Blockchain.com (Sep 4)
@firnprotocol Twitter (Sep 4)
@nonkyc_exchange Twitter (Sep 4)
NonKYC Cryptocurrency Exchange (Sep 4)
@zachxbt Twitter (Sep 4)
@RAILGUN_Project Twitter (Sep 4)
@_ntaff Twitter (Sep 4)
@anytwocardzz Twitter (Sep 4)
Address 1PaYoyzF4G2BasXkA6trg3URgMAZv51BM7 - Bitcoin(BTC) - Professional Data Service for Global Blockchain Enthusiasts (Sep 4)
Memo - Topic - hmwyda (Sep 4)
RAILGUN - On-chain ZK Privacy Ecosystem (Sep 4)
@firnprotocol Twitter (Sep 4)
@RAILGUN_Project Twitter (Sep 4)
Overview | Wiki (Sep 4)
@SearchDecoder Twitter (Sep 4)
@TobyFrei4 Twitter (Sep 4)
@Eemalir Twitter (Sep 4)
@dazai_0x Twitter (Sep 4)
@0xDesigner Twitter (Sep 4)
@HollanderAdam Twitter (Sep 4)
@WazzCrypto Twitter (Sep 4)
@evilcos Twitter (Sep 4)
@OGLemur Twitter (Sep 4)
@Loopifyyy Twitter (Sep 4)
@Duncan30414908 Twitter (Sep 4)
Bitcoin stolen in $238 million breach fails to get privacy shield, returned to original address (Sep 4)
Hacked Bitcoin whale may have lost $238m: ZachXBT (Sep 4)
https://dailycoin.com/zachxbt-flags-238m-bitcoin-transfer-from-a-potential-victim/ (Sep 4)
MistTrack Investigation (Sep 4)
Bitcoin price today, BTC live marketcap, chart, and info | CoinMarketCap (May 16)