BTC $76,633.37 -0.80%
ETH $2,471.81 -2.06%
BNB $716.34 -1.44%
XRP $1.34 -1.85%
SOL $99.55 -2.17%
TRX $0.3393 -0.16%
DOGE $0.0822 -2.90%
ADA $0.2028 -2.14%
BCH $220.64 -2.35%
LINK $11.18 -2.69%
HYPE $77.37 -2.95%
AAVE $124.53 -0.60%
SUI $0.7003 -3.17%
XLM $0.1769 -1.66%
ZEC $1,064.94 -5.29%
AAPL $330.95 -0.59%
AMZN $253.65 -1.23%
GOOGL $337.45 -1.18%
MSFT $491.68 -0.78%
META $643.36 -0.79%
NVDA $215.17 -1.61%
TSLA $364.27 -0.88%
SNDK $1,573.55 -3.17%
INTC $98.78 -3.09%
SPCX $148.80 -0.92%
MU $937.63 -3.02%
AMD $498.10 -3.44%
BTC $76,633.37 -0.80%
ETH $2,471.81 -2.06%
BNB $716.34 -1.44%
XRP $1.34 -1.85%
SOL $99.55 -2.17%
TRX $0.3393 -0.16%
DOGE $0.0822 -2.90%
ADA $0.2028 -2.14%
BCH $220.64 -2.35%
LINK $11.18 -2.69%
HYPE $77.37 -2.95%
AAVE $124.53 -0.60%
SUI $0.7003 -3.17%
XLM $0.1769 -1.66%
ZEC $1,064.94 -5.29%
AAPL $330.95 -0.59%
AMZN $253.65 -1.23%
GOOGL $337.45 -1.18%
MSFT $491.68 -0.78%
META $643.36 -0.79%
NVDA $215.17 -1.61%
TSLA $364.27 -0.88%
SNDK $1,573.55 -3.17%
INTC $98.78 -3.09%
SPCX $148.80 -0.92%
MU $937.63 -3.02%
AMD $498.10 -3.44%

thorchain

THORChain is a decentralized cross-chain AMM trading protocol that was initially created by a group of anonymous cryptocurrency developers at a Binance hackathon in 2018. The protocol aims to decentralize cryptocurrency liquidity through a network of public nodes and ecosystem products. Any individual, product, or institution can access its native and cross-chain liquidity.
All
Article
Flash

Galaxy Research: Coldcard attackers continue to transfer funds, approximately 45% of the stolen assets have entered mixing or cross-chain pathways

Galaxy Research published that the attackers in the Coldcard "Wave 3" attack are still continuously transferring the stolen funds. During this phase, the attackers created 293 2-of-2 multi-signature wallets for each victim's assets. The first batch of funds was transferred across chains to Ethereum via THORChain; the latest round of transfers has begun entering the CoinJoin mixing process.Currently, the Wave 3 attackers are processing the largest amounts of stolen funds in order of the stolen amount, having sequentially transferred the funds from wallets ranked 1 to 11. The next 10 wallets that have not yet been transferred hold a total of 30.81 BTC, while wallets ranked 61 to 293 hold a total of 33.77 BTC. So far, the attackers have transferred about 45% of the stolen assets from this exploit, with funds flowing to Ethereum (via THORChain) or entering CoinJoin mixing transactions. Additionally, this fund transfer has revealed a previously unknown wallet: 58 addresses jointly spent in a 2-of-2 multi-signature format identical to that of Wave 3, and these were further transferred by the Wave 3 attackers to a jump address that funds CoinJoin.The on-chain analysis team currently marks this wallet as "cause = open," but believes it likely also belongs to Coldcard victims, which means the number of wallets involved in Wave 3 may increase to 294, raising the previously reported total amount stolen from the Coldcard vulnerability to approximately 1806 BTC. Currently, about 82% of the stolen BTC remains in addresses initially controlled by the attackers, while about 18% has been transferred, with the flow of funds indicating that it may be undergoing laundering processes.

THORChain has released a recovery plan for the attack incident, and voting for node operators has begun

THORChain has released its fourth update regarding the attack incident on May 15, and the proposal ADR028 has been announced, with voting for node operators now open.According to the recovery plan, the protocol will first absorb losses through its own liquidity, with the remaining portion to be shared by synthetic asset holders; the specific distribution ratio of the two is still under evaluation. The protocol's own liquidity will be reduced to zero, and will be gradually replenished through system revenue. This plan will not issue or sell RUNE, nor will it dilute any holders.On the technical side, GG20 will be temporarily retained and has completed patch upgrades. Trading will resume after the vulnerabilities are fixed and node rotation is successfully conducted, with a future release pace that is slower and more security-conscious. Innocent nodes located in the same vault as the attacker will be protected, while the attacker nodes will be fully confiscated. The recovered RUNE will be paired with the recovered assets, and any excess will be destroyed.The protocol also offers a white hat bounty to the attacker to recover funds; if some are returned, the recovery plan will be adjusted proportionally. THORChain remains neutral and permissionless, and there will be no review of the attacker's Swap transactions after trading resumes. Node operators are currently voting on the proposal direction, and the numbers in the ADR are only indicative, with adjustments to be made through Mimir later.

Chainalysis tracks the source of the THORChain attack: skilled in money laundering, the attack was carried out weeks after cross-chain fund movements

Chainalysis posted on the X platform that before the theft of THORChain, wallets suspected to be associated with the attacker had been transferring funds through Monero, Hyperliquid, and THORChain for several weeks. The attacker-associated wallets had already deposited into Hyperliquid positions via the Hyperliquid and Monero privacy bridge as early as the end of April. The funds were then exchanged for USDC and transferred to Arbitrum, and later bridged to Ethereum, with some ETH subsequently transferred to THORChain to become staked RUNE for newly added nodes, which are believed to be the source of the attack.Afterward, the attacker bridged some RUNE back to Ethereum and split it into four pathways, one of which went directly to the attacker. After being transferred through intermediate wallets, 8 ETH was sent to the final wallet receiving the stolen funds 43 minutes before the attack. The funds from the other three pathways flowed in the opposite direction. These wallets bridged ETH back to Arbitrum, deposited it into Hyperliquid, and transferred it into Monero through the same privacy bridge, with the last transaction occurring less than 5 hours before the attack began.As of Friday afternoon, the stolen funds have not yet been used, but the attacker has demonstrated their skilled cross-chain money laundering capabilities, and the Hyperliquid to Monero path may become the next move.
app_icon
ChainCatcher Building the Web3 world with innovations.