Top

Axie Infinity co-founder suffers $9.5M loss in wallet hack

Web3 & Enterprise·February 24, 2024, 7:54 AM

Jeff “Jihoz” Zirlin, one of the co-founders of Sky Mavis, the Singapore-headquartered development firm behind both Axie Infinity and the Ronin Network, has faced a significant setback as some of his personal crypto wallets have fallen victim to a hack.

https://asset.coinness.com/en/news/6c4d02fadf8c8ffe6c606825b3e5bd7e.webp
Photo by GuerrillaBuzz on Unsplash

Funds drained through Tornado Cash

The hack has resulted in the loss of approximately $9.7 million worth of ether (ETH). The breach, which occurred on Feb. 23, saw two crypto wallet addresses associated with Zirlin compromised. The perpetrator managed to abscond with 3,248 ETH, funneling the stolen funds through Tornado Cash, a privacy-focused Ethereum mixer.

 

The alarm was raised by PeckShield, a blockchain investigation firm, which identified the compromise of a "whale wallet" through the Ronin Bridge. PeckShield attributed the breach to a "wallet compromise," which facilitated unauthorized outbound transfers of funds.

 

PeckShield's investigation revealed that the pilfered 3,248 ETH was initially dispersed across three different wallets before being funneled into Tornado Cash. This service, notorious for its use by hackers seeking to obfuscate the origin and traceability of illicit funds, served as a conduit for the stolen assets.

 

Confirming the attack and remarking on having had a “tough morning,” Zirkin outlined on social media that “the attack is limited to my personal accounts, and has nothing to do with validation or operations of the Ronin chain.”

 

He emphasized the implementation of stringent security protocols across all chain-related activities, seeking to reassure stakeholders of the company’s commitment to safeguarding user assets. Although specific details regarding the breach remain undisclosed, Zirlin's statement suggests a leakage of the private keys associated with his personal wallets, granting unauthorized access to the hacker.

 

Ronin Network secure

PeckShield’s revelation prompted Aleksander Larsen, co-founder of Ronin Network, to swiftly respond, affirming the robust security measures of the Ronin Bridge. The social media post that Larsen had responded to, which he claimed to have an “extremely misleading title,” was later deleted.

 

Larsen suspected that the breach stemmed from a wallet hack rather than a flaw within the bridge itself. Notably, Ronin had been targeted in a high-profile attack in March 2022, orchestrated by the North Korea-backed Lazarus Group, resulting in a $625 million loss.

In response to this previous breach Sky Mavis initiated a comprehensive overhaul of Ronin's core systems to bolster decentralization and mitigate future vulnerabilities.

 

$112M Ripple co-founder hack

In a separate incident, Binance intercepted $4.2 million worth of stolen XRP, part of the $112 million hack targeting Ripple co-founder Chris Larsen's personal wallet on Jan. 31. Unlike the Axie Infinity breach, the perpetrator behind Larsen's hack refrained from leveraging crypto mixer services or decentralized exchanges, enabling Binance to track and immobilize a portion of the illicitly obtained funds.

 

Axie Infinity, heralded as a pioneering "play-to-earn" Web3 game, has emerged as a lucrative platform, enabling players to earn cryptocurrency and trade in-game assets via blockchain technology. Since its inception in 2018, the game has amassed $1.3 billion in revenue, underscoring its prominence within the burgeoning blockchain gaming ecosystem.

 

More to Read
View All
Web3 & Enterprise·

Sep 05, 2023

OKX Enters Final Stages of Securing VASP License in Hong Kong

OKX Enters Final Stages of Securing VASP License in Hong KongSeychelles-headquartered cryptocurrency exchange OKX is on the verge of securing its virtual asset service provider (VASP) license in Hong Kong, with approval expected as early as June 2024.That’s according to Li Zhikai, OKX’s Global Chief Commercial Officer, who, in a recent interview with Infocast, shed light on the exchange’s preparations, including collaborations with banks and other related technological integrations.Photo by Simon Zhu on UnsplashThe Road to a VASP LicenseObtaining a VASP license in Hong Kong is no easy feat. Regulatory requirements impose a 30% cap on investors’ crypto investments, ensuring they do not risk more than one-third of their net income.Furthermore, the Hong Kong regulator has implemented stringent crypto asset storage protocols, mandating that crypto exchanges securely store 98% of their crypto assets in cold wallets. Additionally, they must provide insurance and compensation arrangements to protect clients’ interests.Cost has been another issue. In June it emerged that Web3 businesses have been shelling out anywhere between 20 million and 200 million Hong Kong dollars ($2.55 million and $25.5 million) in order to see out the licensing application process.Alongside these licensing difficulties, Hong Kong’s Securities and Futures Commission (SFC) issued a warning last month aimed at unregistered crypto businesses engaging in “improper practices” within the Chinese autonomous territory.OKX’s remarkable growthWith OKX having reported growth within the Hong Kong market earlier this year, pointing to the onboarding of over 10,000 new users in just one month, it’s likely that licensing is both worthwhile and necessary for the firm despite the difficulties in obtaining it. In March the exchange established OKX Hong Kong, a local entity, with the primary objective of securing a VASP license and operating as a virtual asset trading platform within the city.Hong Kong’s decision to open its doors to retail investors as of June 1 generated significant interest, with more than 80 foreign and Mainland China-based crypto companies expressing their intent to establish a presence in Hong Kong and obtain local licenses. Among these firms are Gate.io, Huobi, CoinEx, and Interactive Brokers.Expanding global reachNotably, OKX has been actively acquiring licenses in various jurisdictions worldwide as part of its strategic expansion plan. The exchange secured a Minimal Viable Product (MVP) license from the Dubai Virtual Assets Regulatory Authority (VARA) in June. This licensing milestone followed the establishment of a new office at the Dubai World Trade Center by OKX.Before venturing into the Middle East, OKX took steps to obtain a French digital asset service provider (DASP) license in May, aiming to position France as its regional hub in Europe. To facilitate this, OKX established a local subsidiary, OKX France. The application and registration process with the French regulator is expected to enable OKX to operate in full compliance with European regulations.Hong Kong embarked on its journey to become a crypto-friendly jurisdiction over the course of the past 12 months, but particularly so when it unveiled its licensing framework for cryptocurrency exchanges catering to retail customers earlier this year. However, only a handful of platforms, such as HashKey and OSL, managed to secure licenses for offering retail crypto trading services. Others, including Huobi and Gate.io, are still awaiting that regulatory nod.

news
Policy & Regulation·

Mar 28, 2025

Central Asian republics work towards crypto bank & crypto hub development

News emanating from the Central Asian republics of Kyrgyzstan and Kazakhstan in recent days points to further rollout and development of cryptocurrency sector infrastructure. A press release published on March 26 outlined that Kyrgyzstan is working on various initiatives in order to copper-fasten its position as a regional crypto hub. Those efforts include the advancement of digital asset regulation, enabling the launch of licensed crypto platforms and ongoing trials of legal frameworks relative to crypto. Photo by Steve Johnson on UnsplashA7A5 stablecoinOne initiative that may aid in the development of the digital assets sector in Kyrgyzstan is the rollout of the A7A5 stablecoin. A7A5 is pegged to the Russian ruble, with the token having been issued by Kyrgyz company Old Vector. The product was first launched in February, with the intention for it to be used on the A7 cross-border payment platform of Russian state-owned bank Promsvyazbank. Garantex, a Russian crypto exchange which had been sanctioned by U.S. and European authorities and was recently shut down, announced on Feb. 19 the listing of the A7A5 stablecoin. The stablecoin’s backers claim that it was issued “in complete accordance with the new national legislation - under the control of regulatory authorities and directed to an officially registered, regulated broker.” The stablecoin is being promoted on the basis of an annual yield of up to 20%, which has been established due to its link to the refinancing rate of the central bank of the Russian Federation. Kazakhstan crypto bank proposalMeanwhile, lawmakers in Central Asian neighbor Kazakhstan have proposed the creation of a national crypto bank. According to The Times of Central Asia, an English-language daily newspaper, Azat Peruashev, leader of the Ak Zhol political party within Kazakhstan’s lower house of parliament, put forward the proposal, which would implicate the involvement of the National Bank of Kazakhstan and a number of the country’s commercial banks. Peruashev addressed the proposal to Kazakhstani Prime Minister Olzhas Bektenov. However, the Central Asian country may have some fundamental issues to address before a crypto bank can become a reality. Currently, Kazakhstan has yet to establish a legal framework for the use of digital assets.  Last year, the authorities shut down 36 cryptocurrency exchanges which were deemed to have been operating illegally. In total, 3,500 illegal crypto exchanges have been shut down in Kazakhstan. Leading American crypto exchange business Coinbase faced a setback in the Central Asian country in November 2023 when the government cut access to its website within the country. While these crypto businesses have struggled to operate in Kazakhstan, Binance Kazakhstan successfully obtained a trading license from the Astana Financial Services Authority (AFSA) in September of last year. Earlier this month, the company added options trading and futures copy trading to the platform. Blockchain industry pioneer Kyle Chasse took to X to report on this most recent development. He suggested that given that 90% of crypto activity in Kazakhstan is off the books, the authorities are interested in launching a crypto bank so as to bring it all under their control. 

news
Policy & Regulation·

Sep 26, 2023

Hong Kong Takes Steps to Enhance Crypto Platform Oversight

Hong Kong Takes Steps to Enhance Crypto Platform OversightIn the wake of the ongoing JPEX scandal, the Securities and Futures Commission (SFC) of Hong Kong has pledged to intensify its efforts to combat unregulated cryptocurrency trading platforms operating within the Chinese autonomous territory.Photo by Ruslan Bardash on UnsplashPublic registry plannedAs of Monday, the SFC has announced a comprehensive plan to address these concerns. One key initiative includes the publication of a publicly accessible list encompassing all licensed, deemed licensed, closing down, and application-pending virtual asset trading platforms (VATPs). The purpose of this list is to empower the public with the information needed to identify potentially unregulated VATPs conducting business in Hong Kong.Ongoing JPEX falloutThese new measures arrive in the aftermath of the ongoing JPEX crypto exchange scandal, which local media outlets have characterized as one of the most significant financial fraud cases to ever impact the region. JPEX, a Dubai-headquartered platform, stands accused of offering its services to Hong Kong residents without having applied for a license in the country.The SFC pointed directly to the issues at JPEX in its most recent announcement, stating: “The JPEX incident highlights the risks of dealing with unregulated VATPs and the need for proper regulation to maintain market confidence. It also shows that dissemination of information to the investing public through the Alert List, warnings and investor education can be further enhanced to help members of the investing public better understand the potential risks entailed by suspicious websites or VATPs.”Christopher “Kit” Wilson, the Director of Enforcement at the SFC, discussed these developments at a press briefing held on Monday, alongside addressing the JPEX scandal. Wilson revealed that, due to evasive behavior from stakeholders and unsatisfactory responses to information requests, JPEX was placed on the regulator’s alert list in July 2022.It emerged last week that Hong Kong police had taken social media influencer Joseph Lam into custody related to the scandal. More arrests followed later in the week while authorities indicated that they were looking to tighten up regulation in light of the unfolding JPEX saga. By Friday, access to the web and mobile platforms of JPEX had been blocked with JPEX encouraging users to use VPN to circumvent the measure.Wilson further elaborated that a complex investigation, involving multiple parties across various jurisdictions, was initiated by the SFC, which escalated following the receipt of the organization’s first official investor complaint in April 2023. This coincided with the full implementation of the Anti-Money Laundering Ordinance (AMLO) in June 2023, prompting the commencement of a formal fraud investigation.Wilson stated: “As a result of that investigation, we issued a formal warning on Sept. 13 and referred the matter to the police.”As it stands right now, the financial ramifications of the JPEX scandal are estimated to have reached approximately $178 million. Local law enforcement agencies have received over 2,200 complaints from affected exchange users.

news
Loading