{"id":42186,"date":"2023-01-24T09:14:46","date_gmt":"2023-01-24T09:14:46","guid":{"rendered":"https:\/\/egrowonline.com\/?p=42186"},"modified":"2023-01-24T09:14:46","modified_gmt":"2023-01-24T09:14:46","slug":"wormhole-hacker-moves-155m-in-biggest-shift-of-stolen-funds-in-months","status":"publish","type":"post","link":"http:\/\/egrowonline.com\/?p=42186","title":{"rendered":"Wormhole hacker moves $155M in biggest shift of stolen funds in months"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div data-v-5a4050f8=\"\">\n<p>The hacker behind the $321 million Wormhole bridge attack has shifted a large chunk of stolen funds, with transaction data showing that $155 million worth of Ether (<a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/ethereum-price\" rel=\"noopener\">ETH<\/a>) was transferred to a decentralized exchange (DEX) on Jan 23. <\/p>\n<p>The Wormhole hack was the <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/the-10-largest-crypto-hacks-and-exploits-in-2022-saw-2-1b-stolen\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/the-10-largest-crypto-hacks-and-exploits-in-2022-saw-2-1b-stolen\/amp\" rel=\"noopener\">third largest crypto hack in 2022<\/a>, after the protocol\u2019s token bridge <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/wormhole-token-bridge-loses-321m-in-largest-hack-so-far-in-2022\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/wormhole-token-bridge-loses-321m-in-largest-hack-so-far-in-2022\/amp\" rel=\"noopener\">suffered an exploit<\/a> on Feb. 2, 2022, that resulted in the loss of 120,000 Wrapped ETH (wETH) around worth $321 million.<\/p>\n<p>According to the transaction <a target=\"_blank\" href=\"https:\/\/etherscan.io\/txs?a=0x629e7da20197a5429d30da36e77d06cdf796b71a&amp;p=1\" rel=\"noopener nofollow\">history<\/a> of the hacker\u2019s alleged wallet address, the latest activity shows that 95,630 ETH was sent to the OpenOcean DEX and then subsequently converted into ETH-pegged assets such as <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/metamask-staking-launches-plugging-into-lido-and-rocket-pool-liquid-staking\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/metamask-staking-launches-plugging-into-lido-and-rocket-pool-liquid-staking\/amp\" rel=\"noopener\">Lido Finance\u2019s staked ETH<\/a> (stETH) and wrapped staked (wstETH). <\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\"><a target=\"_blank\" href=\"https:\/\/twitter.com\/hashtag\/CertiKSkynetAlert?src=hash&amp;ref_src=twsrc%5Etfw\" rel=\"noopener\">#CertiKSkynetAlert<\/a> <\/p>\n<p>We are seeing address \u200b\u200b0x629e\u2026 Wormhole Network Exploiter swap 95,630 Ether (~$155M) to stETH <\/p>\n<p>Stay safe! <a target=\"_blank\" href=\"https:\/\/t.co\/ZR6zxlRuKX\" rel=\"noopener\">pic.twitter.com\/ZR6zxlRuKX<\/a><\/p>\n<p>\u2014 CertiK Alert (@CertiKAlert) <a target=\"_blank\" href=\"https:\/\/twitter.com\/CertiKAlert\/status\/1617614595027308568?ref_src=twsrc%5Etfw\" rel=\"noopener\">January 23, 2023<\/a><\/p><\/blockquote>\n<p>Digging into the transaction history further, crypto community members such as @spreekaway also highlighted that the hacker went on to conduct a slew of odd looking transactions. <\/p>\n<p>For example, the hacker used their stETH holdings as collateral to <a target=\"_blank\" href=\"https:\/\/etherscan.io\/tx\/0xbb0dee4a7f682dc5d8778c0f842b25f937f02663f6b3764813abac72956c31ae\" rel=\"noopener nofollow\">borrow<\/a> 13 million worth of the DAI stablecoin, before swapping it out for more stETH, wrapping into stETH again and then borrowing some more DAI. <\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Wormhole exploiter has converted his ETH to wstETH and is going to borrow DAI against it it seems. <a target=\"_blank\" href=\"https:\/\/t.co\/9rhERSMG5u\" rel=\"noopener\">pic.twitter.com\/9rhERSMG5u<\/a><\/p>\n<p>\u2014 Spreek (@spreekaway) <a target=\"_blank\" href=\"https:\/\/twitter.com\/spreekaway\/status\/1617608174135312385?ref_src=twsrc%5Etfw\" rel=\"noopener\">January 23, 2023<\/a><\/p><\/blockquote>\n<p>Notably, the Wormhole team has taken the opportunity to once again offer the hacker a bounty of $10 million if they return all the funds, after it left an embedded message conveying such in a transaction via the Wormhole: Deployer. <\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2023-01\/ccd48904-c438-4859-a814-349d8a3d0615.png\" \/><figcaption style=\"text-align: center\"><em>Embedded message: Etherscan<\/em><\/figcaption><\/figure>\n<p>The hacker\u2019s hefty ETH transaction appears to have had a direct impact on the price of stETH according to <a target=\"_blank\" href=\"https:\/\/dune.com\/mtgypes\/stetheth\" rel=\"noopener nofollow\">data<\/a> from Dune Analytics. The asset\u2019s price went from slightly under peg of 0.9962 ETH on Jan. 23, to as high as 1.0002 ETH the following day, before dropping back to 0.9981 at the time of writing.<\/p>\n<p><strong><em>Related: <\/em><\/strong><a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/north-korea-s-lazarus-group-masterminded-100m-harmony-hack-fbi-confirms\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/north-korea-s-lazarus-group-masterminded-100m-harmony-hack-fbi-confirms\/amp\" rel=\"noopener\"><strong><em>North Korea&#8217;s Lazarus Group masterminded $100M Harmony hack: FBI confirms<\/em><\/strong><\/a><\/p>\n<p>With the Wormhole hack likely to catch more attention in light of the latest incident, blockchain security firms such as Ancilia, Inc. warned on Jan. 19 that searching the keywords \u201cWormhole Bridge\u201d in Google is currently showing promoted ad websites that are actually phishing operations. <\/p>\n<p>The community has been warned to be diligent on what they are clicking on relating to this term. <\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\"> <a target=\"_blank\" href=\"https:\/\/twitter.com\/hashtag\/phishing?src=hash&amp;ref_src=twsrc%5Etfw\" rel=\"noopener\">#phishing<\/a> alert When you search &#8220;wormhole bridge&#8221; in Google, many of the &#8220;ad&#8221; entries are actually phishing site. E.g.<br \/>hxxps:\/\/wormholebridge-multichain.com\/<br \/>hxxps:\/\/portaltoken-wormholebridge.com. Be careful about what you click and stay safe! <a target=\"_blank\" href=\"https:\/\/t.co\/C6JW2xeaUh\" rel=\"noopener\">pic.twitter.com\/C6JW2xeaUh<\/a><\/p>\n<p>\u2014 Ancilia, Inc. (@AnciliaInc) <a target=\"_blank\" href=\"https:\/\/twitter.com\/AnciliaInc\/status\/1615967029852524550?ref_src=twsrc%5Etfw\" rel=\"noopener\">January 19, 2023<\/a><\/p><\/blockquote>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/cointelegraph.com\/news\/wormhole-hacker-moves-155m-in-biggest-shift-of-stolen-funds-in-months\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The hacker behind the $321 million Wormhole bridge attack has shifted a large chunk of stolen funds, with transaction data showing that $155 million worth of Ether (ETH) was transferred to a decentralized exchange (DEX) on Jan 23. The Wormhole hack was the third largest crypto hack in 2022, after the protocol\u2019s token bridge suffered [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":42187,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[38],"tags":[13523,1887,1351,3288,121,247,3803,959,4562],"class_list":["post-42186","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blockchain","tag-155m","tag-biggest","tag-funds","tag-hacker","tag-months","tag-moves","tag-shift","tag-stolen","tag-wormhole"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"http:\/\/egrowonline.com\/wp-content\/uploads\/2023\/01\/68608218-67ff-4f09-942e-a0c273af784b.jpg","_links":{"self":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/42186","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=42186"}],"version-history":[{"count":1,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/42186\/revisions"}],"predecessor-version":[{"id":42188,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/42186\/revisions\/42188"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/media\/42187"}],"wp:attachment":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=42186"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=42186"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=42186"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}