Top

North Korean Hackers Take Off With $100M Atomic Wallet Honeypot

Policy & Regulation·June 14, 2023, 11:44 PM

Having reported last week on a $35 million hack of Atomic Wallet users’ funds, an update on the matter reveals that the situation is much worse than originally thought, with losses now exceeding $100 million.

Photo by Kenny Eliason on Unsplash

 

5,500 wallets compromised

The attack has sent shockwaves throughout the crypto community, raising concerns about the security of decentralized wallets. Atomic Wallet, an Estonia-based project known for its non-custodial approach where users take full responsibility for storing their assets securely, has been hit hard by this unforeseen breach.

Elliptic, a crypto compliance analysis company, published an update on the situation on Tuesday. According to that blog article, it estimates that approximately 5,500 crypto wallets have been compromised, meaning that losses have risen to more than $100 million, highlighting the severity of the attack.

Despite the significant impact on users, Atomic Wallet has yet to provide an explanation regarding the root cause of these substantial losses. Users have taken to social media in frustration, demanding clarification from the company. Surprisingly, the company’s last direct update on Twitter dates back to June 7, leaving users feeling even more anxious.

 

User frustration

One user, Ezra Carlson, expressed frustration, questioning why Atomic Wallet didn’t warn users when they were aware of the ongoing hack. Carlson tweeted: “@AtomicWallet why won’t AM give me a straight answer about why they didn’t warn me, knowing full well that they were being hacked, that it was not safe to use AM last week before I made a transfer to my wallet that was then hacked.”

Another user, “Real Deal Crypto,” criticized Atomic Wallet’s lack of updates, stating: “Your last update was five days ago — SERIOUSLY?!?!”

Although Atomic Wallet acknowledged reports of compromised wallets on June 3, downplaying the impact by claiming that less than 1% of users were affected, the staggering sum of losses indicates a significant breach. Its last communication on the matter came on June 11 when, in responding to a user, the firm said that it continued to investigate and to await Twitter updates on the matter.

 

Hack tied to North Korea’s Lazarus Group

Elliptic has connected this heist to the notorious Lazarus Group, a cyber-criminal organization with ties to the North Korean regime, responsible for stealing over $2 billion in crypto assets through various thefts. This attribution marks the first time a significant crypto heist has been openly linked to the Lazarus Group since their $100 million exploit of Horizon Bridge in June 2022.

In response to the heist, Elliptic has been collaborating with international investigators and exchanges, mobilizing resources to recover the stolen assets. Their efforts have reportedly led to the freezing of over $1 million worth of funds. However, the thief has adapted its behavior in response to the freezing of assets, turning to the Russia-based Garantex exchange to launder the stolen assets, as noted by Elliptic.

This recent attack adds to a series of notable breaches in the crypto industry. Jimbos Protocol experienced an exploit resulting in a loss of $7.5 million, and Tornado Cash faced a malicious proposal that seized control of its governance in May. According to a report by Chainalysis, crypto hackers made off with an estimated $3.8 billion in 2022, with North Korea being responsible for a significant portion of the attacks.

More to Read
View All
Web3 & Enterprise·

Jan 18, 2024

Lillius selected to join Cronos Accelerator Program

AI sports challenge app Lillius has been selected as the first South Korean project in the Web3, sports and lifestyle categories to participate in the Cronos Accelerator Program, according to an official announcement on Wednesday (KST).Photo by Kelly Sikkema on UnsplashBridging exercise and Web3Lillius is a mobile app that allows users to participate in different sports and exercise challenges that use AI motion detection technology to analyze their form while performing the movements. After they complete a challenge, users can receive rewards based on their score. Notably, some of the challenges feature exclusive lessons from Korean Olympic medalists like taekwondo athlete Lee Dae-hoon, fencer Nam Hyun-hee and wrestler Jung Ji-hyun. Fostering innovationThe Cronos Accelerator Program, operated by global blockchain firm Cronos Labs, is an initiative aimed at nurturing and propelling startups in the Defi, Web3 and blockchain sphere, providing support in areas like technology, tokenomics, marketing, fundraising and more. In particular, participants in the program can receive mentoring and secure investment opportunities from industry experts. All participants are also eligible to receive an immediate stipend of $30,000 and the chance to win a $100,000 follow-up investment from Cronos Labs and its other partners. By participating in the Accelerator Program, Lillius plans to leverage its market potential, product appeal, cutting-edge AI technology and networks across the Cronos chain to become an innovative Web3 sports platform used worldwide.

news
Web3 & Enterprise·

Dec 22, 2023

WEMIX Foundation launches omnichain wallet

WEMIX Foundation launches omnichain walletThe WEMIX Foundation, a subsidiary of South Korean blockchain gaming publisher Wemade, has officially launched the una Wallet, according to an official announcement on the company’s website on Thursday (KST). una Wallet is a core application of the Unbound Networking & Accelerating Growth Initiative, or “unagi,” the company’s newest innovative omnichain network and interoperable Web3 gaming platform.Photo by Shubham’s Web3 on UnsplashEasy asset managementThe wallet service offers a solution for users to conveniently earn, manage and trade their digital assets like NFTs and tokens on multiple blockchains — such as WEMIX3.0, Ethereum and Polygon — in one borderless place. The WEMIX Foundation said it would add more supported chains in the future.Effortless access and robust securityIn particular, una Wallet’s convenience and security stem from an easy login procedure utilizing connections to social media accounts and multi-party computation (MPC) technology. MPC is a cryptographic security measure that enables multiple parties to assess a computation without revealing their private information or data. This technology splits private keys, or mnemonic phrases, and allows users to easily recover their wallets through social login even if they lose their keys.The service also provides transaction route recommendations, allowing users to move or trade assets across chains with minimal costs or signature procedures. Subsequently, they can also view their transaction history on each chain and the movement of assets between different chains.WEMIX plans to add various features to make authentication and asset-tracking processes even easier. una Wallet is currently available on Google Play and the Apple App Store.

news
Policy & Regulation·

Mar 18, 2024

Korean tax agency’s move hints at approving corporate crypto accounts

The South Korean National Tax Service (NTS) is reportedly in the process of setting up virtual asset accounts for its district offices. This initiative is aimed at confiscating and liquidating the digital assets of individuals who fail to pay their taxes. This move comes after the creation of similar accounts by public prosecutors' offices, leading to speculation in the crypto industry that virtual asset accounts will soon be allowed for corporate entities as well.Photo by Nataliya Vaitkevich on PexelsDirect confiscation of virtual assetsA report by the local news outlet Etoday today has revealed that each district office of the NTS is working towards establishing a virtual asset account. This development will empower the tax agency to directly sell virtual assets confiscated from tax delinquents. Previously, the NTS would freeze the accounts of overdue taxpayers at Korean cryptocurrency exchanges, compelling them to convert their assets into Korean won. These funds were then confiscated by the NTS. The new initiative is set to streamline the process, enabling the tax authority to directly confiscate virtual assets without the intermediary step of conversion to Korean won. Speaking about this development, an NTS officer said that as each district office director holds the authority to collect taxes from taxpayers with overdue payments, it's necessary for each office to have its own account. Prosecutors’ Offices’ Upbit and Bithumb accountsThe crypto industry views this development as a potential step towards allowing the creation of virtual asset accounts for corporate entities, starting with government agencies. In December, the prosecutors' offices established their entity accounts at major cryptocurrency exchanges Upbit and Bithumb. Since then, the prosecution has utilized these accounts to sell confiscated virtual assets, aiming to recover funds that had not been collected.  An official from a cryptocurrency exchange indicated that the South Korean government is currently focusing on allowing entities that serve the public good to own virtual asset accounts. This approach is seen as the starting point, with expectations that the trend will gain momentum in the future. The official added that it's rare for the government to provide blanket permissions from the outset, suggesting a gradual and cautious approach to the integration of virtual asset accounts.Money laundering concernsMeanwhile, the Financial Intelligence Unit (FIU) of the Financial Services Commission (FSC), along with other financial regulators, has remained silent on the matter of virtual asset accounts for corporate entities. This reticence stems from concerns with the financial authority that the introduction of corporate crypto accounts could potentially lead to money laundering and the creation of slush funds. An official from the National Assembly’s National Policy Committee said that they have not received any comments from the financial authority in response to inquiries about plans to allow such accounts for corporate entities. The current law doesn’t prohibit corporate entities from trading virtual assets. However, under the auspices of the financial authority, banks have refrained from offering real-name accounts to corporate entities. This policy has been a point of contention within the crypto industry. Advocates argue that allowing corporate accounts could mitigate issues of market manipulation and challenge the dominance of Upbit in the Korean cryptocurrency market.  The official from the cryptocurrency exchange pointed out that the financial authority does not have a clear legal basis for prohibiting the creation of corporate crypto accounts. They suggested that the regulator should develop clearer guidelines and enforce these rules for corporate entities. More serious discussions in AprilMore serious discussions about the introduction of corporate crypto accounts are anticipated to take place in April, following the conclusion of the general election. Last month, the main opposition party, the Democratic Party of Korea, made election promises to open the crypto market to institutional investors. Meanwhile, the ruling People Power Party has been quietly deliberating on virtual asset policy. Despite these political movements, earlier reports indicate a disconnect between the political parties' efforts to relax crypto regulations and the financial regulator's stance. Meanwhile, Hwang Seok-jin, a professor at Dongguk University’s Graduate School of International Affairs and Information Security, expects to see a conclusion on the permission of corporate crypto trading by the end of this year. He said that there has been ongoing discussion about the approval of spot Bitcoin exchange-traded funds (ETFs) and that allowing the trading of such funds requires the ownership of virtual assets by institutions. 

news
Loading