The crypto detectives traced funds stolen by North Korean Lazarus Group through two mixers and various networks to identify 350 addresses where the funds remain today.
The data encryption tracking service platform MistTrack tracked the funds involved in the hacking of Harmony Bridge and released 350 address lists related to the attack. Lazarus Group, sponsored by the North Korean state, was called the person behind the attack. According to a tweet posted on January 23, funds are transferred through some trading centers to avoid trackers
According to MistTrack, on June 23, funds in several tokens worth about US $100 million were stolen from the Harmony Bridge, then quickly changed to BTC (BTC), and returned to the beginning and transferred to the wallet. This bridge is conducive to the transfer between Harmony and Ethereum Internet, Binance Chain and BTC. Harmony clearly proposed to refund the fund of US $1 million, but the proposal was not accepted.
On the other hand, such hackers were later identified as Lazarus Group Corporation of North Korea, which operated 85700 Ethereum (ETH) according to the Tornado Cash switching valve and stored it in several detailed addresses. Until January 13, they were transferred to Railgun, a anonymized private system on Ethereum. From there, it is transferred to an explicit address.
Other funds are transferred to Avalanche (AVAX) blockchain technology, where they are exchanged for the USDD tokens of Tether (USDT) or Tron, and then deposited into the detailed addresses on the Internet of Ethereum and Tron.
Some progress has been made in recovering stolen funds. Zhao Changpeng (CZ), CEO of Binance, announced in a tweet on January 15 that after Binance detected the existence of the hot currency exchange, 121 BTCs were gradually recovered from the hot currency exchange center.
Harmony suggested forging new native ONE tokens to compensate some of the 65000 money clips lost due to the invasion of hackers, but this idea proved unpopular. On the contrary, he announced a plan to compensate for the loss from the financial sector in September. In November, Harmony said that this would add seven coins on a new LayerZero bridge that were not damaged by hackers, so that the coin holder could remove them from the Internet.
Tom Blackstone added.