{"id":61969,"date":"2023-10-03T12:21:18","date_gmt":"2023-10-03T12:21:18","guid":{"rendered":"http:\/\/egrowonline.com\/?p=61969"},"modified":"2023-10-03T12:21:18","modified_gmt":"2023-10-03T12:21:18","slug":"hackers-selling-discounted-tokens-linked-to-coinex-stake-hacks","status":"publish","type":"post","link":"http:\/\/egrowonline.com\/?p=61969","title":{"rendered":"Hackers selling discounted tokens linked to CoinEx, Stake hacks"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div data-v-ff33fc9a=\"\">\n<p>Blockchain analytics investigators have uncovered an individual linked to a cryptocurrency laundering operation that is offering stolen tokens at discounted prices from recent high-profile exchange hacks.<\/p>\n<p>Speaking exclusively to Cointelegraph, a representative from blockchain security firm Match Systems outlined how investigations into several major breaches featuring similar methods through the summer months of 2023 have pointed to an individual who is allegedly selling stolen cryptocurrency tokens via peer-to-peer transfers.<\/p>\n<p><a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/coinex-compromised-private-keys-behind-70-million-hack\" rel=\"noopener\"><strong><em>Related:\u00a0CoinEx hack: Compromised private keys led to $70M theft<\/em><\/strong><\/a><\/p>\n<p>The investigators managed to identify and make contact with an individual on Telegram offering stolen assets. The team confirmed that the user was in control of an address containing over $6 million worth of cryptocurrencies after receiving a small transaction from the corresponding address.<\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2023-10\/d1782783-9913-47a1-99b3-db76427edeaf.jpg\" \/><figcaption style=\"text-align: center\">A message from the seller advertising stolen tokens being linked to CoinEx and Stake hacks. Source: Match Systems<\/figcaption><\/figure>\n<p>The exchange of stolen assets was then conducted through a specially created Telegram bot, which offered a 3% discount off the token\u2019s market price.\u00a0Following initial conversations, the owner of the address reported that the initial assets on offer had been sold and that new tokens would be available some three weeks later:<\/p>\n<blockquote><p>\u201cMaintaining our contact, this individual notified us about the commencement of new asset sales. Based on the available information, it is logical to assume that these are funds from CoinEx or Stake companies.\u201d<\/p><\/blockquote>\n<p>The Match Systems team has not been able to fully identify the individual but has narrowed down their location to the European time zone based on several screenshots they had received and timings of conversations:<\/p>\n<blockquote><p>\u201cWe believe he is not part of the core team but is associated with them, possibly having been de-anonymized as a guarantee that he will not misuse the delegated assets.\u201d<\/p><\/blockquote>\n<p>The individual also reportedly displayed &#8220;unstable&#8221; and &#8220;erratic&#8221; behavior during various interactions, abruptly leaving conversations with excuses like &#8220;Sorry, I must go; my mom is calling me to dinner\u201d.<\/p>\n<blockquote><p>&#8220;Typically, he offers a 3% discount. Previously, when we first identified him, he would send 3.14 TRX as a form of proof to potential clients.\u201d<\/p><\/blockquote>\n<p>Match Systems told Cointelegraph that the individual accepted Bitcoin (BTC) as a means of payment for the discounted stolen tokens and had previously sold $6 million worth of TRON (TRX) tokens.\u00a0The latest offering from the Telegram user has listed $50 million worth of TRX, Ether (ETH) and Binance Smart Chain (BSC) tokens.<\/p>\n<p>Blockchain security firm CertiK <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/hackers-behind-stake-exploit-shifts-bnb-and-matic-latest-move\" rel=\"noopener\">previously outlined<\/a> the movement of stolen funds from the Stake heist in correspondence with Cointelegraph, with around $4.8 million of the total $41 million being laundered through various token movements and cross-chain swaps.<\/p>\n<p><a target=\"_blank\" href=\"https:\/\/www.fbi.gov\/news\/press-releases\/fbi-identifies-lazarus-group-cyber-actors-as-responsible-for-theft-of-41-million-from-stakecom\" rel=\"noopener nofollow\">FBI later identified<\/a> North Korean Lazarus Group hackers as the culprits of the Stake attack, while\u00a0cyber security firm SlowMist also linked the $55 million CoinEx hack to the North Korean group.\u00a0<\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2023-10\/10317f5f-f7b7-4a93-baa7-0ee8d01fbef3.jpg\" \/><\/figure>\n<p>This is in slight contrast to information obtained by Cointelegraph from Match Systems which suggests that the perpetrators of the CoinEx and Stake hacks had slightly different identifiers in methodology.<\/p>\n<p>Their analysis highlights that previous Lazarus Group laundering efforts did not involve Commonwealth of Independent States (<a target=\"_blank\" href=\"https:\/\/www.britannica.com\/topic\/Commonwealth-of-Independent-States\" rel=\"noopener nofollow\">CIS<\/a>) nations like Russia and Ukraine while the 2023 summer hacks saw stolen funds being actively laundered in these jurisdictions.<\/p>\n<p><a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/stake-hack-of-41m-was-performed-by-north-korean-group-fbi\" rel=\"noopener\"><strong><em>Related:\u00a0Stake hack of $41M was performed by North Korean group: FBI<\/em><\/strong><\/a><\/p>\n<p>Lazarus hackers left minimal digital footprints behind while recent incidents have left plenty of breadcrumbs for investigators. Social engineering has also been identified as a key attack vector in the summer hacks while Lazarus Group targeted \u201cmathematical vulnerabilities\u201d.<\/p>\n<p>Lastly the firm notes that Lazarus hackers typically used Tornado Cash to launder stolen cryptocurrency while recent incidents have seen funds mixed through protocols like Sinbad and Wasabi.\u00a0Key similarities are still significant. All these hacks have used BTC wallets as the primary repository for stolen assets as well as the Avalanche Bridge and mixers for token laundering.<\/p>\n<p>Blockchain data reviewed at the end of Sept. 2023 suggests that North Korean hackers have stolen an estimated $47 million worth of cryptocurrency this year, including $42.5 million in BTC and $1.9 million ETH.<\/p>\n<p><a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/magazine\/blockchain-detectives-mt-gox-collapse-birth-chainalysis\/\" rel=\"noopener\"><strong><em>Magazine:\u00a0Blockchain detectives: Mt. Gox collapse saw birth of Chainalysis<\/em><\/strong><\/a><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/cointelegraph.com\/news\/exclusive-hackers-selling-stolen-tokens-coinex-stake\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Blockchain analytics investigators have uncovered an individual linked to a cryptocurrency laundering operation that is offering stolen tokens at discounted prices from recent high-profile exchange hacks. Speaking exclusively to Cointelegraph, a representative from blockchain security firm Match Systems outlined how investigations into several major breaches featuring similar methods through the summer months of 2023 have [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":61970,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[41],"tags":[17375,17877,3562,5184,4226,2185,95,1277],"class_list":["post-61969","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ethereum","tag-coinex","tag-discounted","tag-hackers","tag-hacks","tag-linked","tag-selling","tag-stake","tag-tokens"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"http:\/\/egrowonline.com\/wp-content\/uploads\/2023\/10\/1200_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjMtMTAvNjFkNmRmZjAtODI1Ny00MDhhLTk1Y2ItYzUyZDNjZWRkMWI0LmpwZw.jpg","_links":{"self":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/61969","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=61969"}],"version-history":[{"count":1,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/61969\/revisions"}],"predecessor-version":[{"id":61971,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/61969\/revisions\/61971"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/media\/61970"}],"wp:attachment":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=61969"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=61969"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=61969"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}