|

Poloniex exchange hack likely linked to North Korea hacker Lazarus Group

  • X-explore research speculates that attack on Poloniex exchange could be linked to North Korea hacker Lazarus Group.
  • The attack is attributed to a leakage of private keys, akin to what the infamous hackers’ September  attack on Stake.com, stealing $41 million.
  • The normal withdrawal in Poloniex is the EIP-1559 type and now the attack transaction is in the Legacy type.

Poloniex centralized exchange, owned by Tron founder Justin Sun was exploited for about $125 million, with the controversial executive committing to making users 100% whole while putting out a 5% white hat bounty for the return of funds. As reported, the stolen assets were majorly distributed among ETH, BTC, and TRX together with other altcoins like FLOKI and AAVE, of low market capitalization.

Also Read: Justin Sun confirms Poloniex hack, assures users of 100% reimbursement

Poloniex attacks possibly identified

Poloniex exchange attackers could be the infamous Lazarus Group from North Korea, according to X-plore research, which tabulated addresses and balances related to the hacker. Based on the investigation, the researcher opines that the attack was facilitated by a leakage of the private key, noting that “The normal withdrawal in Poloniex is the EIP-1559 type and now the attack transaction is in the Legacy type.”

According to X-plore, this finding leads to the conclusion that the attack may have been the handiwork of North Korea’s notorious hackers, the Lazarus Group, basing their assumption on the fact that a similar tactic was used against Stake.com in September.

Specifically, the tactic is bi-factor, such that:

  • Different tokens are saved at different addresses, meaning each address will only deal with one kind of token.
  • A middle address is then used to swap the erc20/trc20 token on a decentralized exchange (DEX) and then transfer the ETH/TRX to the new address.

Stake.com attack by Lazarus Group

In a September report by the US Federal Bureau of Investigations (FBI), it was revealed that Lazarus Group executed a cyber-attack on an online casino and betting platform, Stake.com, stealing up to $41 million. The group is also called APT38, comprised of DPRK cyber actors according to the FBI.

In the attack, the exploiters moved stolen funds associated with the Ethereum, Binance Smart Chain (BSC), and Polygon networks from Stake.com into several virtual currency addresses.

Notably, if the perpetrator(s) is actually the Lazarus Group, then the chances of Sun’s 5% white hat bounty yielding fruit are slim to none, considering the Lazarus Group’s modus operandi.

Nevertheless, hope remains alive, considering Sun’s offer has yielded fruit only recently when HTX Global was hacked for $8 million.

Author

Lockridge Okoth

Lockridge is a believer in the transformative power of crypto and the blockchain industry.

More from Lockridge Okoth
Share:

Editor's Picks

XRP and XLM outlook: Mild recovery attempts emerge amid mixed market signals

Ripple and Stellar show mild signs of recovery on Thursday after extending losses earlier this week. XRP is holding above the $1.10 level as bearish momentum begins to fade, while XLM has bounced modestly from a key support zone.

Crypto Overview: Bitcoin consolidates above $60,000  – CRV, WLFI, XMR lead gains

The broader cryptocurrency market maintains risk-off sentiment as Bitcoin lingers above $62,000. The mild recovery in BTC fails to lift the Fear and Greed Index, which at 15 continues to signal extreme fear among investors. Still certain altcoins, Curve DAO, World Liberty Financial, and Monero, have emerged as top performers over the last 24 hours.

Bitcoin faces further downside risk amid growing short-term holder losses, weak ETF demand

Bitcoin's recent decline toward the $60,000 level has pushed the market further into bearish territory, with new investors suffering huge unrealized losses, according to a Glassnode report on Wednesday. The firm noted that Bitcoin's earlier May rally now appears increasingly as a "bear bounce".

CFTC proposes framework to review terrorism, war, assassination-related contracts on prediction markets
The Commodity Futures Trading Commission (CFTC) on Wednesday proposed amendments to Regulation 40.11, seeking to establish a formal framework for reviewing prediction market contracts. The proposed framework targets contracts linked to terrorism, assassination, war, gaming, or conduct that is unlawful under federal or state law.
Bitcoin: After the bloodbath, everyone looks at $60,000
Bitcoin (BTC) hovers above $62,000 at the time of writing on Friday, weighed down by growing risk-off sentiment due to persistent geopolitical tensions in the Middle East and sticky macroeconomic uncertainty. The institutional sell-off continued to wreak havoc on capital flows, with spot Bitcoin Exchange-Traded Funds (ETFs) recording billions in outflows.