FBI confirms North Korean hacker group Lazarus responsible for $100 million Harmony Bridge attack

  • North Korea had been under doubt about the theft since the first report of the incident.
  • FBI identified the hackers following Lazarus' use of RAILGUN, a privacy protocol, to launder $60 million worth of ETH tied to the theft.
  • On the other hand, Wormhole exploiter from February 2022 also began swapping the stolen ETH, borrowing nearly 14 million DAI.

The crypto market has not been privy to attacks and exploits, as over the last few years, billions have been lost to such crimes. One of the leaders in this space is the Lazarus Group, which has been estimated to have exploited the market multiple times now, including the infamous Harmony Horizon bridge attack.

North Korea continues its crypto crimes

Expected to have a hand in the theft, suspicion surrounding the Lazarus Group was confirmed on Monday after the Federal Bureau of Investigation (FBI) made the announcement.

According to the law enforcement agency, the North Korean hacking group tied to the nation's ruling party, the Democratic People's Republic of Korea (DPRK), along with APT38, was responsible for the June 2022 Harmony Horizon bridge theft.

Per the FBI, earlier this month, on January 13, the hackers were found using RAILGUN, a privacy protocol. Using this protocol, more than $60 million worth of ETH was laundered, which was tied to the $100 million Harmony bridge theft.

This amount was then sent to multiple crypto service providers and converted to BTC. The FBI managed to freeze a portion of these funds. Adding to the announcement, the FBI stated,

"FBI Los Angeles and FBI Charlotte…continue to identify and disrupt North Korea's theft and laundering of virtual currency, which is used to support North Korea's ballistic missile and Weapons of Mass Destruction programs."

Wormhole exploiter emerges from the dark

Another hacker on Tuesday reportedly became active who is suspected to be associated with the February 2022 Wormhole exploit. The $256 million worth of ETH stolen from the cross-chain protocol could be seen being shuffled around.

Twitter user Spreek identified the apparent conversion of the stolen Ethereum to wstETH, Lido's liquid-staked ETH, which was then used to borrow stablecoin DAI. According to the Etherscan data, the exploiter took out loans of nearly 14.1 million DAI after swapping $156 million ETH into wstETH.

Following the swaps, the exploiter received another offer from Wormhole, offering $10 million as a bounty reward in exchange for returning all of the stolen funds. No response from the exploiter was noted at the time of this report.

Information on these pages contains forward-looking statements that involve risks and uncertainties. Markets and instruments profiled on this page are for informational purposes only and should not in any way come across as a recommendation to buy or sell in these assets. You should do your own thorough research before making any investment decisions. FXStreet does not in any way guarantee that this information is free from mistakes, errors, or material misstatements. It also does not guarantee that this information is of a timely nature. Investing in Open Markets involves a great deal of risk, including the loss of all or a portion of your investment, as well as emotional distress. All risks, losses and costs associated with investing, including total loss of principal, are your responsibility. The views and opinions expressed in this article are those of the authors and do not necessarily reflect the official policy or position of FXStreet nor its advertisers.


RELATED CONTENT

Loading ...



Copyright © 2024 FOREXSTREET S.L., All rights reserved.