FBI: North Korean hackers stole $100 million in Harmony crypto hack

Cryptocurrency falling

The FBI has confirmed that the North Korean state-sponsored ‘Lazarus’ and APT38 hacking groups were behind the theft of $100 million worth of Ethereum stolen from Harmony Horizon in June 2022

Harmony Horizon is a cross-chain bridge for Ethereum that suffered a breach in June 2022, allowing hackers to assume control of a MultiSigWallet contract and use it to transfer large amounts of tokens to their addresses.

Tweet

For more details on the technical aspect of the attack, Certik released a report describing the attack flow and the steps the threat actors took to siphon millions.

Yesterday, the FBI confirmed that two North Korean hacking groups, Lazarus and APT38, were behind the attack.

“Through our investigation, we were able to confirm that the Lazarus Group and APT38, cyber actors associated with the DPRK, are responsible for the theft of $100 million of virtual currency from Harmony’s Horizon bridge, reported on June 24, 2022.” – FBI.

The Lazarus and APT38 hacking groups are linked to the Democratic People’s Republic of Korea (DPRK) and have a history of stealing cryptocurrency assets on behalf of the government.

The FBI states that North Korean hacking groups steal and launder virtual currency to support their country’s ballistic missile and weapons of mass destruction programs.

In this case, the FBI managed to associate Lazarus with the heist thanks to one of the threat group’s laundering efforts last week.

On January 13th, the hackers attempted to move 41,000 ETH ($63.5 million) through Railgun before depositing the funds to many addresses in three cryptocurrency exchanges.

Lazarus laundering diagram
Lazarus laundering diagram (@zachxbt)

At least 350 of these addresses have been identified to be under the direct control of the Lazarus group.

The hackers converted some of these moved funds to Bitcoin, and the FBI seized an undefined portion by working closely with virtual asset service providers.

The FBI states the remaining converted funds are now stored in the following Bitcoin addresses.

  • 1BK769SseNefb6fe9QuFEi8W4KGbtP8gi3 
  • 15FcqYRbwh2JsRUyBjvZ4jJ2XAD3pycGch 
  • 1HwSof6jnbMFpfrRRa2jvydYdopkkGB4Sn 
  • 15emeZ7buVegqhYh9PekH7cwFEJcCeVNpS 
  • 3MSbCJCYtx5sj1nkzD4AMEhhvvviXBc8XJ 
  • 17Z79rZpkk8kUiJseg5aELwYKaoLnirMUn 
  • bc1qp2vvntdedxw4xwtyd4y3gc2t9ufk6pwz2ga4ge 
  • 3P9WebHkiDxCi8LDXiRQp8atNEagcQeRA3 
  • 37fnBxofDeph2fpBZxZKypNkwdXAt9nT6F 
  • 185NxhFAmKZrdwn9rVga3kqbvDP4FkbTNw 
  • 12283Cq1pJ3f1gXwqi6K3bRf5LZb8Bkm6g 

Binance announced at the time that, together with Huobi, they managed to intercept 124 BTC stolen from Harmony Horizon, which was worth approximately $2.5 million.

Moreover, all accounts used in the laundering actions were frozen.

Past Lazarus attacks

North Korean hackers have a long history of targeting cryptocurrency companies to steal assets to fund their country’s initiatives.

Lazarus began targeting cryptocurrency users by spreading trojanized cryptocurrency wallets and trading apps to steal victims’ wallets.

In April 2022, the U.S. Treasury and the FBI linked the Lazarus group to the theft of over $617 million worth of Ethereum and USDC tokens from the blockchain-based game Axie Infinity.

It was later revealed that the hackers conducted this attack after sending a malicious laced PDF file containing a lucrative job offer to one of the blockchain’s engineers.


Original Source


A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon using the button below

Digital Patreon Wordmark FieryCoralv2

To keep up to date follow us on the below channels.

join
Click Above for Telegram
discord
Click Above for Discord
reddit
Click Above for Reddit
hd linkedin
Click Above For LinkedIn