On February 19, a significant portion of the funds stolen from the Singapore-based cryptocurrency exchange Phemex during a January hack began to move to new addresses. Analysts from Global Ledger reported that over 2,080 ETH, valued at approximately $6 million, was transferred to 14 new addresses, while less than 4,000 ETH remains in the primary wallet associated with the attack.
Key Takeaways
-
Over 2,080 ETH (~$6 million) moved to new addresses.
-
Less than 4,000 ETH remains in the original wallet.
-
The hackers displayed advanced blockchain knowledge through complex transaction patterns.
-
Phemex has resumed trading and is implementing security upgrades.
The Hack and Its Aftermath
The January breach of Phemex was marked by a series of suspicious transactions involving hot wallets. Initial investigations revealed over 275 transactions utilizing EVM chains, leading to an estimated loss of $85 million. Experts suspect that North Korean hackers may be behind the incident.
Following the hack, Phemex has taken steps to enhance its security measures. CEO Federico Variola announced that part of the exchange's funds would be moved to cold storage as part of a comprehensive security update. The exchange has also warned customers against using old deposit addresses to prevent further losses.
Complex Transaction Patterns
The movement of the stolen funds has been characterized by a convoluted series of transactions. One newly created wallet received 601.34 ETH through five separate transfers before consolidating the funds on another new address associated with the cross-chain bridge, Across Protocol. This was followed by additional obfuscation of the funds through transfers to a second address.
The hackers utilized various platforms and protocols to anonymize the stolen assets, including:
-
Tornado Cash and eXch for direct transfers to mixers.
-
Wintermute, DLN Trade, and THORChain for asset exchanges.
Additionally, some of the stolen funds were sent to custodial platforms like OKX and CoinEx, but the majority of the transactions were executed using on-chain tools such as cross-chain services Bitget and the ChangeNOW wallet.
Ongoing Investigations
Global Ledger has been monitoring the movements of the stolen assets, noting that prior to the recent transactions, the hackers had been transferring stolen assets over the past few weeks, including the liquidation of 50 BTC and 4 million XRP. The complexity of the transaction patterns suggests a high level of expertise in blockchain technology among the perpetrators.
As the investigation continues, the cryptocurrency community remains vigilant, with exchanges and users alike taking precautions to safeguard their assets against potential future attacks. Phemex's proactive measures and the ongoing scrutiny of the stolen funds highlight the importance of security in the rapidly evolving world of cryptocurrency.
In conclusion, the Phemex hack serves as a stark reminder of the vulnerabilities present in the cryptocurrency space and the need for robust security protocols to protect against cyber threats.