Top

Atomic Wallet Hacker Uses Lazarus Crypto Mixer

Web3 & Enterprise·June 07, 2023, 12:27 AM

The stolen cryptocurrency from the recent $35 million hack of Atomic Wallet is already being moved to a crypto mixer favored by North Korea’s notorious cyber-hacking group.

Photo by Micha Brändli on Unsplash

 

Sinbad.io

According to UK-based crypto compliance analysis firm Elliptic, the funds have made their way to a crypto mixer used by Lazarus Group, a notorious hacker group that focuses on crypto heists which is believed to have direct ties with the North Korean government.

On June 5, Elliptic’s Investigations Team revealed that it had traced the funds from the Atomic Wallet hack to the crypto mixer Sinbad.io. Lazarus had previously used the mixer to launder over $100 million in stolen crypto assets.

While the exact amount sent to the mixer was not specified, Elliptic noted that the stolen funds were being exchanged for Bitcoin before undergoing obfuscation through the mixer. Additionally, Elliptic reported that Sinbad.io is likely a rebranded version of Blender.io, another mixer extensively used to launder funds by the Lazarus Group. Blender.io has been sanctioned by the US Treasury.

 

Atomic Wallet hack

The hack of several user accounts on Atomic Wallet occurred on June 3, resulting in losses of up to $35 million. News of the issue broke with the following tweet from the project team (which has subsequently been deleted): “We have received reports of wallets being compromised. We are doing all we can to investigate and analyze the situation. As we have more information, we will share it accordingly.”

In a follow-up tweet the next day, the team confirmed that it was investigating the matter with the assistance of a number of “leading security companies.”

However, Atomic Wallet later downplayed the incident, stating that less than 1% of its monthly active users were affected. The project team was castigated by users for trying to present the hack as a minor incident. One user took to Twitter to call out the Atomic Wallet team for “having the nerve to come to the networks and say that only 1% of wallets were affected.”

The Atomic Wallet project is based out of Tallinn, Estonia, having been founded in 2017. It claims to provide a non-custodial decentralized multi-currency crypto wallet. The product supports over fifty coins and two hundred tokens. It also offers atomic swaps between digital assets, while also supporting integrations with instant exchanges such as Changelly, ShapeShift, and others.

Roland Säde, the Chief Marketing Officer of Atomic Wallet, assured users that the team is working tirelessly to recover the stolen funds. He emphasized the need to complete the investigation to develop a concrete plan.

Despite the ongoing efforts, Säde urged victims to track the illicit transfers and report them to popular crypto exchanges. By doing so, it was thought that may hinder the scammers from exchanging the funds.

 

Crypto hacking menace

Lazarus Group hackers have been the bane of the crypto space in recent years. Elliptic released a report last month that identified Japan as having been the country most adversely affected by the North Korean hackers. It’s understood that the estimated $721 million in stolen crypto from Japan-based entities amounts to nearly nine times the value of North Korea’s exports based on 2021 data.

While Atomic Wallet is directly reporting the incidents, Säde believes that having more individuals monitoring the hackers’ activities will make it more challenging for them to move the funds undetected. Unfortunately, Elliptic’s recent findings suggest that for many victims, it may already be too late to prevent further misuse of their stolen cryptocurrency.

More to Read
View All
Policy & Regulation·

Oct 11, 2023

Hong Kong Police Issue Warning as Binance Users Lose Funds to Phishing Scam

Hong Kong Police Issue Warning as Binance Users Lose Funds to Phishing ScamHong Kong has witnessed a surge in phishing scams targeting Binance users, prompting local law enforcement to issue a cautionary advisory.Photo by Serey Kim on UnsplashCyberDefender warningThe warning was issued by Hong Kong police via its CyberDefender Facebook page on Monday. Over the past two weeks, at least 11 Binance customers in Hong Kong fell victim to phishing scams, collectively losing over $446,000 (equivalent to HKD 3.5 million). These scams primarily involve fraudulent text messages.According to Hong Kong police, these fraudulent text messages claim to be from Binance and ask users to verify their accounts by clicking on a link provided within the message. On Facebook, the warning stated:“Recently, fraudsters posing as Binance sent text messages claiming that users must click the link in the message to verify their identity details before a deadline, otherwise their account would be deactivated.”Upon clicking the phishing link and entering their login credentials to “verify” their accounts, victims unwittingly grant fraudsters full access to their Binance accounts. This modus operandi mirrors the tactics commonly employed in phishing scams.CZ chimes inBinance CEO Changpeng Zhao (CZ) also joined in the cautionary chorus, issuing a warning to customers on his X account.The crypto sector in Hong Kong has been facing challenges recently, largely related to the recent JPEX fraud case. The losses incurred from the JPEX exchange scandal have swelled to an estimated $180 million, with over 2,300 victims filing complaints with local authorities.The JPEX scandal led to multiple arrests in Hong Kong and prompted authorities to intensify their efforts against illegal crypto activities. The Securities and Futures Commission (SFC) of Hong Kong introduced regulations mandating the licensing of all crypto exchanges operating within its jurisdiction earlier this year.To date, only two exchanges, HashKey and OSL, have secured licenses under this regulatory framework. Numerous other crypto exchanges in Hong Kong have submitted license applications, but Dubai-headquartered JPEX, despite heavily promoting its application for a Hong Kong license, failed to submit an application to the local regulator. In the wake of the JPEX scandal, the SFC published a comprehensive list of companies seeking crypto licenses and expanded its list of suspicious platforms.Cyber security firm Kaspersky found earlier this year that phishing related to crypto trading is on the rise in Asia, particularly in the Philippines. Binance’s CZ has had to issue warnings where phishing is concerned on previous occasions. He did so in July when the founder of decentralized crypto exchange (DEX) Uniswap was hacked.In February of last year, CZ came out again to warn users of a massive SMS-related crypto phishing scam. Back in 2018 a serious attempt was made to compromise the credentials of Binance platform users via phishing techniques.As phishing scams continue to pose a significant threat to crypto users in Hong Kong, and with the aftermath of the JPEX debacle still reverberating through the industry, vigilance and caution remain paramount for participants in the region’s crypto ecosystem.

news
Policy & Regulation·

Jun 17, 2024

Malaysia launches operation to clamp down on crypto tax evasion

The Inland Revenue Board (IRB) of Malaysia has launched an operation, which has been dubbed as “Ops Token,” to tackle tax evasion within crypto trading circles in the southeast Asian nation. Klang Valley raids According to the Malaysian English language newspaper, The Star, the special operation is a coordinated effort involving the Royal Malaysia Police and CyberSecurity Malaysia (CSM) alongside the IRB. The Malaysian tax authority raided ten locations, with 38 personnel involved in the raids, which were carried out within the Klang Valley region. The main objective of the raids and the operation overall, is to identify crypto corporate entities and individuals that had failed to report trading activities and therefore, associated revenues, profits and taxes. The initiative aligns with the Malaysian government’s broader strategy of stamping out tax evasion across all sectors, reducing revenue leakage and optimizing the nation’s tax take.Photo by Esmonde Yong on UnsplashStern warning for traders Datuk Abu Tariq Jamaluddin, CEO of the IRB, issued a stern warning to crypto traders: declare and pay taxes or face compliance actions. Jamaluddin clarified that crypto traders are subject to the same income tax rules that are applied to businesses across various sectors throughout Malaysia. While cryptocurrency is not regarded as legal tender by Malaysia’s central bank, crypto-centric businesses must adhere to the nation's income tax regulations. The IRB commented on the operation via a statement published on June 15. It stated: "Through this operation, it was possible to find stored cryptocurrency trading data in mobile devices and computers. We have successfully identified the digital assets that are traded, which has caused significant tax revenue leakage." The agency intends to carry out further analysis on the data that it seized in a bid to ascertain the trading revenues generated, the profits derived from that trading activity and the taxes owed as a consequence. The IRB has asserted that a number of corporate entities and partnerships were specifically formed with the purpose of tax evasion. The agency estimates the total value of crypto-related transactions to date in 2024 to amount to 1.441 trillion Malaysian ringgits, approximately $310 billion. International enforcement efforts Malaysia is not alone in its efforts to ensure tax compliance relative to cryptocurrency trading and investing. The Organization for Economic Cooperation and Development (OECD) has established a set of crypto tax rules, namely the Crypto-Asset Reporting Framework (CARF). The initiative is part of an effort to achieve a Common Reporting Standard (CRS) relative to crypto on an international basis, with OECD member states transposing the CARF into domestic law. The CARF is due to go live in 2027. The International Monetary Fund (IMF) maintains that crypto presents itself as a major headache for tax authorities globally. In a research paper published last year, it outlined that countries would need to update their tax systems in order to deal with the challenge that crypto presents with the potential for a leakage in tax revenues. In the United States, an Internal Revenue Service (IRS) official stated in December 2023 that the agency has seen an increase in its caseload relative to crypto tax cases.

news
Policy & Regulation·

May 06, 2024

Turkish crypto legislation: anticipated reforms await clarity

Turkey, a significant player in the global cryptocurrency market, has been anticipated to introduce comprehensive crypto-related legislation in 2024. Despite initial announcements suggesting an early rollout, the specifics of the anticipated regulatory framework remain pending, leaving stakeholders in anticipation. Currently, Turkey operates with limited crypto regulations. While some measures exist, such as those imposed by the Central Bank and the Ministry of Finance’s financial intelligence unit, others remain informal, such as guidance from the Capital Markets Board. These regulations primarily focus on prohibiting certain activities and implementing anti-money laundering (AML) measures.Photo by Dima Rogachevskiy on UnsplashAnticipated reforms and their purposeThe forthcoming legislation is expected to address various aspects of the crypto market, including licensing requirements for exchanges, investor protection measures and taxation. The aim is to align with international standards, potentially aiding Turkey in exiting the Financial Action Task Force's (FATF) "gray list." The regulations aim to enhance investor protection, especially in light of past incidents like the collapse of the Thodex exchange, while also providing a legal framework for crypto taxation. Timing of implementationDespite expectations for an early introduction, the exact timeline for the enactment of the crypto legislation remains uncertain. Industry observers speculate potential connections between the legislation's timing and Turkey's efforts to exit the FATF's "gray list." While some anticipate a release by mid-year, others suggest a delay until later in the year, underscoring the complexity and importance of the regulatory reforms for Turkey's crypto ecosystem. 

news
Loading