Hacker moves $10M from 2023 phishing incident to Tornado Cash

cyptouser4 months agoCryptocurrencies News57
25cc9d4a>

An account linked to a phishing attack in September 2023 has moved $10 million in Ether (ETH) to the crypto-mixing protocol Tornado Cash. 

Hacker transferring funds to Tornado Cash. Source: Etherscan

On March 21, blockchain security firm CertiK flagged an account linked to the $24 million hack transferring 3,700 ETH to Tornado Cash. The funds were taken from a crypto whale in a phishing incident on Sept. 6, 2023.

At the time, the investor lost $24 million in staked ETH on the liquid staking provider Rocket Pool. The hack was done in two transactions — one took 9,579 stETH, while the other drained 4,851 rETH from the crypto whale.

Scam Sniffer, an anti-scam project, said that the victim signed an “Increase Allowance” transaction which enabled token approvals for the hacker. With smart contracts, the feature allows third parties to spend ERC-20 tokens belonging to others if given approval.

The token allowances feature has been talked about a lot within the crypto space, with some warning users about how developers could deploy malicious smart contracts for scams.

Blockchain security company PeckShield flagged that the attacker swapped the assets for 13,785 ETH and 1.64 million Dai (DAI). Some of the DAI was transferred to the FixedFload exchange, while most of the stolen funds were moved into other wallets.

Phishing attacks continue to be a huge headache for the crypto space. Scam Sniffer’s crypto phishing report showed that in February, almost $47 million was lost to crypto phishing scams.

The report highlighted that 78% of the thefts happened on the Ethereum network, and ERC-20 tokens took up 86% of all the assets stolen.

Related: Trezor X account shills fake presale tokens in suspected hack

Token approvals have also caused recent losses for crypto users. On March 20, an old contract previously used by the Dolomite exchange was used to drain $1.8 million from users.

The exploit affected users who authorized approvals for the contract. Because of this, Dolomite’s development team urged users to revoke approvals given to the old contract address.

While some attacks lead to millions lost, some efforts to steal crypto are thwarted very quickly. On March 20, the Layerswap team prevented any further damage from a breach of its website after intervention from its domain provider.

Despite this, the hackers still drained about $100,000 in assets from 50 users. The protocol said that it would refund the affected users and provide additional compensation for the inconvenience.

Magazine: Game firm’s stock triples after it buys Bitcoin, Hong Kong’s in-kind BTC ETF: Asia Express

The content on this website comes from the Internet. Due to the inconvenience of proofreading the authenticity and accuracy of the copyright or content of some content, it may be temporarily impossible to confirm the authenticity and accuracy of the copyright or content. For copyright issues or other issues caused by this, please Call or email this site. It will be deleted or changed immediately after verification.

related articles

Chainlink to join Rapid Addition in building blockchain adapter for institutions

Chainlink to join Rapid Addition in building blockchain adapter for institutions

55966e89˃Blockchain oracle project Chainlink has partnered with Financial Information eXchange (FIX)...

Web3 gaming needs to shift from play-to-earn to 'play-and-earn' — Bitget

Web3 gaming needs to shift from play-to-earn to 'play-and-earn' — Bitget

55966e89˃Web3 games should shift their focus from play-to-earn to “play-and-earn” to attract new mai...

Bitwise predicts 50% odds of spot ETH ETF approval, $88k BTC by year end

Bitwise researcher Ryan Rasmussen believes there is a 50% chance that spot Ethereum ETFs will gain a...

BlockFi secures key $21M agreement with Vrai Nom amid turbulent bankruptcy

BlockFi has reached an agreement in principle with Vrai Nom Investment in its complex bankruptcy pro...

Arthur Hayes sees new arbitrage opportunities in SEC's crypto ETF concerns

Arthur Hayes, the co-founder and former CEO of BitMEX, highlighted the potential “juicy arbitr...

Physical version of gold-backed token replaces Zimbabwe dollar

Physical version of gold-backed token replaces Zimbabwe dollar

55966e89˃The Reserve Bank of Zimbabwe has introduced Zimbabwe Gold, or the ZiG, in paper and coin fo...