Top

North Korean Hackers Take Off With $100M Atomic Wallet Honeypot

Policy & Regulation·June 14, 2023, 11:44 PM

Having reported last week on a $35 million hack of Atomic Wallet users’ funds, an update on the matter reveals that the situation is much worse than originally thought, with losses now exceeding $100 million.

Photo by Kenny Eliason on Unsplash

 

5,500 wallets compromised

The attack has sent shockwaves throughout the crypto community, raising concerns about the security of decentralized wallets. Atomic Wallet, an Estonia-based project known for its non-custodial approach where users take full responsibility for storing their assets securely, has been hit hard by this unforeseen breach.

Elliptic, a crypto compliance analysis company, published an update on the situation on Tuesday. According to that blog article, it estimates that approximately 5,500 crypto wallets have been compromised, meaning that losses have risen to more than $100 million, highlighting the severity of the attack.

Despite the significant impact on users, Atomic Wallet has yet to provide an explanation regarding the root cause of these substantial losses. Users have taken to social media in frustration, demanding clarification from the company. Surprisingly, the company’s last direct update on Twitter dates back to June 7, leaving users feeling even more anxious.

 

User frustration

One user, Ezra Carlson, expressed frustration, questioning why Atomic Wallet didn’t warn users when they were aware of the ongoing hack. Carlson tweeted: “@AtomicWallet why won’t AM give me a straight answer about why they didn’t warn me, knowing full well that they were being hacked, that it was not safe to use AM last week before I made a transfer to my wallet that was then hacked.”

Another user, “Real Deal Crypto,” criticized Atomic Wallet’s lack of updates, stating: “Your last update was five days ago — SERIOUSLY?!?!”

Although Atomic Wallet acknowledged reports of compromised wallets on June 3, downplaying the impact by claiming that less than 1% of users were affected, the staggering sum of losses indicates a significant breach. Its last communication on the matter came on June 11 when, in responding to a user, the firm said that it continued to investigate and to await Twitter updates on the matter.

 

Hack tied to North Korea’s Lazarus Group

Elliptic has connected this heist to the notorious Lazarus Group, a cyber-criminal organization with ties to the North Korean regime, responsible for stealing over $2 billion in crypto assets through various thefts. This attribution marks the first time a significant crypto heist has been openly linked to the Lazarus Group since their $100 million exploit of Horizon Bridge in June 2022.

In response to the heist, Elliptic has been collaborating with international investigators and exchanges, mobilizing resources to recover the stolen assets. Their efforts have reportedly led to the freezing of over $1 million worth of funds. However, the thief has adapted its behavior in response to the freezing of assets, turning to the Russia-based Garantex exchange to launder the stolen assets, as noted by Elliptic.

This recent attack adds to a series of notable breaches in the crypto industry. Jimbos Protocol experienced an exploit resulting in a loss of $7.5 million, and Tornado Cash faced a malicious proposal that seized control of its governance in May. According to a report by Chainalysis, crypto hackers made off with an estimated $3.8 billion in 2022, with North Korea being responsible for a significant portion of the attacks.

More to Read
View All
Policy & Regulation·

Oct 24, 2023

Singapore High Court Embraces NFTs for Financial Investigations

Singapore High Court Embraces NFTs for Financial InvestigationsA recent decision by the Singapore High Court has seen it embrace non-fungible tokens (NFTs) in financial investigations. Financial investigation firm Intelligent Sanctuary, also known as iSanctuary, has been granted permission to attach NFTs containing legal documents to cold wallets linked to a hacking incident.This innovative approach, similar to the one used in Italy and the United States to deliver court summonses recently, signals a new departure in the application of NFT technology in the legal and financial world.Photo by Choong Deng Xiang on UnsplashMoving towards tokenized legal ordersLondon-based iSanctuary set out details of the court decision in a blog post published to its website recently. A pivotal moment in this scenario was the court’s issuance of a global freezing order encapsulated within soulbound NFTs, securely linked to the specified wallets. Soulbound NFTs are special types of NFTs which are tied to a user’s account. They cannot be transferred or traded.Although these NFTs do not halt transactions, they serve as powerful deterrents, notifying counterparties and exchanges about the wallets’ dubious past involvement in a hacking event.Monitoring fund movementsFurthermore, iSanctuary has unveiled an ingenious strategy to actively monitor funds leaving these wallets through the NFTs. This innovative method ensures a permanent and unbreakable connection between the NFTs and the wallets.iSanctuary recounted on its website that it was employed by a businessperson who had lost $3 million in crypto assets and was able to track the stolen funds successfully. Their method, which combines both on-chain and off-chain evidence, was presented by an iSanctuary senior investigator to the Singapore High Court. This led to the issuance of a worldwide injunction.iSanctuary’s financial and crypto investigators identified a series of cold wallets holding the proceeds of the crime, and the court approved their use of NFTs for service delivery.Mintable collaborationiSanctuary accredited Singaporean NFT marketplace Mintable as the creator of the NFTs. As reported by local news media outlet The Straits Times last week, this case revolved around a stolen private key and the alleged involvement of Singapore-based crypto exchanges in laundering the stolen assets. The fraudsters, purportedly from Singapore, are alleged to have orchestrated this saga that spans countries from Singapore to Spain, Ireland, Britain, and other European territories.Taking to X (formerly Twitter) to comment on the saga, Mintable founder Zach Burks stated:”Happy to help clean up the crypto space and move the NFT ecosystem into a realm of utility and away from the speculation of jpegs!”In a subsequent post, Burks highlighted further NFT-related innovation when pointing to a central bank digital currency (CBDC) pilot program led by Mastercard that implicated the use of NFTs to stamp out fraud. Mintable supported that particular use of the technology within that project.iSanctuary’s founder, Jonathan Benton, emphasized the impact of the recent initiative, calling it a “game changer.” The approach enables swift action, allowing for the identification of illicit asset holders and expediting the issuance of civil or criminal orders, even red flags, within hours if necessary. It also demonstrates that NFTs can be put to good use, above and beyond speculative trading.

news
Policy & Regulation·

Aug 26, 2023

Binance Takes P2P Service Measures in Response to Sanctioned Russian Banks

Binance Takes P2P Service Measures in Response to Sanctioned Russian BanksGlobal crypto exchange Binance has removed the option for users to conduct transactions via sanctioned Russian banks on its peer-to-peer (P2P) platform, a decision that comes on the heels of a Wall Street Journal exposé published earlier this week, shedding light on the platform’s involvement in facilitating the movement of funds for Russian users.Previously, Binance’s peer-to-peer service featured five Russian banks under sanctions as a method for ruble transfers between users. However, the company swiftly acted to address potential compliance concerns. Fittingly, this latest news was also broken by the Wall Street Journal on Friday.Dmitry Sidorov on PexelsSailing too close to the windWhen approached regarding the omission of these banks, a Binance spokesperson stated: “We regularly update our systems to ensure compliance with local and global regulatory standards. When gaps are pointed out to us, we seek to address and remediate them as soon as possible.”The Wall Street Journal’s article outlined how Binance’s peer-to-peer platform facilitated ruble-to-crypto trades that frequently involved the sanctioned Russian banks, with Rosbank and Tinkoff Bank being prominent examples.These trades often utilized layers of intermediaries to convert funds from these banks into Binance balances, as detailed by various company resources, user screenshots, and messages in official chat groups. Despite these revelations, Binance’s exchange had continued to handle significant volumes of ruble trading, according to data compiled by digital asset research firm CCData.US DoJ probeBinance’s activities in Russia could potentially contribute to its ongoing legal challenges in the United States. The US Justice Department (DoJ) has been probing the company’s actions for potential violations of American sanctions on Russia. In response to such concerns, the Binance spokesperson emphasized:“Binance aims to diligently comply with the global sanctions rules and enforces sanctions on people, organizations, entities, and countries that have been blacklisted by the international community, denying such actors access to the Binance platform.”WorkaroundsTraders, however, had reportedly found workarounds to the bank removals, as observed in the official Telegram chat group for Russian clients. Many shared that they could still engage with sanctioned banks by selecting alternative payment methods and then manually inputting their Rosbank or Tinkoff bank details.Earlier this year, an investigative report by CNBC alleged that employees of the company had told it that Binance staff regularly helped Chinese customers to bypass Know Your Customer (KYC) controls in order to access the platform. More recently, another report, once again by the Wall Street Journal, found that business in China was booming, which surprised many given that China banned crypto trading within the country in 2021.It’s apparent that the company is reacting to regulatory and legal pressures in taking the decision to make these changes to its P2P service. Perennial crypto critic US Senator Elizabeth Warren took to X (formerly Twitter) on Friday, stating:“I rang the alarm about sanctions evasion by Russia using the crypto platform Binance — and urged [the DoJ] to investigate potentially false statements it made to Congress. We need stronger crypto regulations to rein in illicit finance.“

news
Policy & Regulation·

Oct 10, 2023

UK Watchdog Adds Crypto Exchanges to Warning List

UK Watchdog Adds Crypto Exchanges to Warning ListThe UK’s Financial Conduct Authority (FCA) has expanded its warning list to include nearly 150 digital asset companies, including crypto exchanges HTX and KuCoin.Photo by Maxim Hopman on UnsplashPromotion without approvalThese firms have been added to the list due to their promotion of services in the UK without obtaining the necessary regulatory approvals. The move comes as the FCA strengthens its oversight of the cryptocurrency sector.The FCA recently broadened its rules on financial promotions, effective from October 8, to encompass crypto-asset service providers, regardless of their geographical location. This means that all crypto platforms are now obligated to display clear risk warnings to UK-based consumers and adhere to more rigorous technical standards. Additionally, they must implement a mandatory 24-hour cooling-off period for new customers.Exchanges respondIn response to the inclusion of their platforms on the FCA’s warning list, both HTX and KuCoin issued statements. A spokesperson for HTX, known until recently as Huobi, clarified that the firm does not operate or market its services in the UK. KuCoin, on the other hand, acknowledged that it doesn’t operate in the UK but expressed its commitment to adapt its products and services to ensure compliance with the relevant laws and regulations in each country.Another exchange, OKX, alongside global exchange Binance, have both indicated that they are working towards complying with the FCA’s regulatory requirements in respect of marketing.The FCA issued a generic warning message for both HTX and KuCoin, stating:“This firm may be promoting financial services or products without our permission. You should avoid dealing with this firm.”Non-compliance with the FCA’s regulations can result in severe penalties, including takedown requests for websites and apps, substantial fines, and potential legal action, which could lead to imprisonment.It’s worth noting that HTX Advisor, Justin Sun, has encountered regulatory challenges in the past. In March, the US Securities and Exchange Commission (SEC) accused Sun of fraud and market manipulation related to TRX, the native cryptocurrency of his Tron blockchain. Despite holding licenses to operate in various jurisdictions, HTX’s website does not specifically mention the UK as a prohibited venue.KuCoin has its platform restricted in several countries, including the US, Singapore, Hong Kong, mainland China, Thailand, Malaysia, and Canada’s Ontario province. Notably, the UK is not listed among these restricted locations.The FCA’s decision to rapidly identify and publicize crypto firms violating the expanded rules underscores increasingly stringent regulatory requirements. The regulator is continuously updating its list of violators as new infractions are uncovered. In August, the UK regulator published data that demonstrated that only 13% of crypto businesses who have applied to trade in the UK have been offered permits to do so.Lucy Castledine, the FCA’s Director of Consumer Investments, emphasized the dynamic nature of the list, which is constantly evolving to keep pace with emerging issues within the crypto sector.As the FCA takes a more proactive stance in overseeing crypto businesses, the warning list serves as a tool for consumer protection, signaling the importance of adherence to regulatory standards in the cryptocurrency ecosystem.

news
Loading