N.Korean hackers stole $100 mn in crypto from Harmony Blockchain bridge

by IANS |

San Francisco, July 1 (IANS) Cyber-security researchers have linked North Korea-backed notorious Lazarus Group with stealing $100 million worth digital tokens from Harmony, the crypto startup behind Horizon Blockchain Bridge.

The Lazarus Group has perpetrated several large cryptocurrency thefts totalling over $2 billion, and has recently turned its attention to Decentralised Finance (DeFi) services such as cross-chain bridges, according to London-based blockchain analysis provider Elliptic.

The same group is believed to be behind the $540 million hack of Ronin Bridge.

"The theft was perpetrated by compromising the cryptographic keys of a multi-signature wallet -- likely through a social engineering attack on Harmony team members. Such techniques have frequently been used by the Lazarus Group," the researchers wrote in a blog post.

Harmony admitted that a malicious attack happened on its proprietary Horizon Ethereum Bridge and multiple transactions occurred that compromised the bridge with 11 transactions that extracted tokens stored in the bridge.

"The estimated value at the time of the attack was approximately $100 million," the US-based company said in a statement late last month.

The hackers stole various digital tokens like Ethereum, Binance Coin, Tether, USD Coin and Dai.

The Horizon Bridge hacker has so far sent 41 per cent of the $100 million in stolen crypto assets into the 'Tornado Cash' mixer, said the researchers.

Mixers such as Tornado Cash are used to hide the transaction trail.

"By sending these funds through Tornado, the thief is attempting to break the transaction trail back to the original theft. This makes it easier to cash out the funds at an exchange," said Elliptic.

In April this year, hackers stole nearly $180 million in cryptocurrency from Beanstalk Farms, a decentralised finance (De-Fi) project.

The FBI in April blamed North Korean hacker group Lazarus for stealing $625 million in cryptocurrency from the Ronin Network, owned by developer group Sky Mavis.

In January this year, hackers stole crypto tokens worth $120 million from Blockchain-based decentralised finance (DeFi) platform BadgerDAO.

Latest News
Reservation given earlier to Muslim community continued in Karnataka: CM Siddaramaiah Thu, Apr 25, 2024, 04:37 PM
Adani Group's ACC Limited logs highest-ever annualised PAT at Rs 2,337 crore in FY24 Thu, Apr 25, 2024, 04:34 PM
Indian rupee to appreciate to Rs 82–82.50 in FY25: CARE Ratings Thu, Apr 25, 2024, 04:33 PM
Commonwealth Secretariat recognises India's Public Redress System as global best practice Thu, Apr 25, 2024, 04:31 PM
Congress, SP playing divisive politics, says PM Modi in Agra Thu, Apr 25, 2024, 04:28 PM
Former Zimbabwe cricketer Guy Whittall injured by leopard Thu, Apr 25, 2024, 04:24 PM
'NWHL provides a platform for our top women's hockey talent to show their skills', says Bhola Nath Singh Thu, Apr 25, 2024, 03:54 PM
ICEA shares blueprint for India to become a global leader in chip value chain Thu, Apr 25, 2024, 03:53 PM
Nestle India’s net profit up 27 pc in Q4; to form a JV with Dr Reddy's Laboratories Thu, Apr 25, 2024, 03:53 PM
More minors being 'groomed' into making sexual videos amid toughened punishment: South Korea Thu, Apr 25, 2024, 03:52 PM
North Korea touts ties with Russia on Kim-Putin summit anniversary Thu, Apr 25, 2024, 03:51 PM
Constituency watch: TMC at advantage in minority-dominated Uluberia Thu, Apr 25, 2024, 03:50 PM
Constituency Watch: BJP, Congress and Kshatriya community in showdown at Gujarat's Surendranagar Thu, Apr 25, 2024, 03:49 PM
Cong candidate in Kerala suspects foul play as list of poll officials leaked, one suspended Thu, Apr 25, 2024, 03:48 PM
Congress tied hands of our soldiers, we gave them full freedom to retaliate: PM Modi Thu, Apr 25, 2024, 02:02 PM