{"id":31054,"date":"2022-06-28T04:32:32","date_gmt":"2022-06-28T08:32:32","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=31054"},"modified":"2022-06-28T04:32:47","modified_gmt":"2022-06-28T08:32:47","slug":"harmony-hacker-moves-stolen-funds-through-tornado-cash-mixer","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/harmony-hacker-moves-stolen-funds-through-tornado-cash-mixer\/","title":{"rendered":"Harmony hacker moves stolen funds through Tornado Cash mixer"},"content":{"rendered":"\n<p>Harmony's Horizon Bridge money has started to flow into the <a href=\"https:\/\/coinscreed.com\/staging\/tornado-cash-sets-to-launch-on-ethereums-layer-two-network-arbitrum.html\" target=\"_blank\" rel=\"noreferrer noopener\">Tornado Cash Ethererum mixer<\/a>, indicating that the hacker is not planning to take the $1 million bounty offered by Harmony.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/image-220.png\" alt=\"Harmony hacker moves stolen funds through Tornado Cash mixer\" class=\"wp-image-31059\" width=\"782\" height=\"334\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/image-220.png 579w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/image-220-300x128.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/image-220-150x64.png 150w\" sizes=\"(max-width: 782px) 100vw, 782px\" \/><figcaption>Harmony hacker moves stolen funds through Tornado Cash mixer<\/figcaption><\/figure>\n\n\n\n<p>The Harmony team's decision to conceal the illicit earnings provides an answer to the question of whether their offer of just 1% of the $100 million in cryptocurrency monies taken on June 24 would be sufficient to persuade the exploiter to return them.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/hashtag\/PeckShieldAlert?src=hash&ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">#PeckShieldAlert<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> ~6k <a href=\"https:\/\/twitter.com\/search?q=%24ETH&src=ctag&ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">$ETH<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> (~$7.3m) into 0x432&#8230;47ae from <a href=\"https:\/\/twitter.com\/harmonyprotocol?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@harmonyprotocol<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> exploiters and start transferring to <a href=\"https:\/\/twitter.com\/TornadoCash?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@TornadoCash<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> <br>Intermediary address: 0x1e&#8230;6430 <a href=\"https:\/\/t.co\/cN1nZwPi6I\" target=\"_blank\">pic.twitter.com\/cN1nZwPi6I<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; PeckShieldAlert (@PeckShieldAlert) <a href=\"https:\/\/twitter.com\/PeckShieldAlert\/status\/1541320429666988032?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">June 27, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>At 03:10 ET on June 28, a total of 18,036.3 ETH, or nearly $21 million, were transferred out of the<a href=\"https:\/\/www.google.com\/search?q=Harmony+hacker+moves+stolen+funds+through+Tornado+Cash+mixer&rlz=1C1SQJL_enNG889NG889&oq=Harmony+hacker+moves+stolen+funds+through+Tornado+Cash+mixer&aqs=chrome..69i57j33i10i160l2.3624j0j9&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noreferrer noopener\"> Horizon Bridge <span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>exploiter's main wallet. Over the course of the following 10 hours, these monies were then equally divided into three separate transactions and transmitted to three distinct addresses.<\/p>\n\n\n\n<p>Since Tornado Cash can only mix up to 100 ETH at once, mixing up enormous amounts of money can easily take many hours. The purpose of mixing ETH is to obscure the transaction path of coins so that they cannot be tracked back to earlier transactions.<\/p>\n\n\n\n<p>The first and second wallets that received ETH from the exploiter's main <a href=\"https:\/\/coinscreed.com\/staging\/trust-wallet-binance-connect-partner-to-add-crypto-buying-option.html\" target=\"_blank\" rel=\"noreferrer noopener\">wallet <\/a>have finished combining the funds and are currently sitting on a total of 16.3 ETH, which is probably not enough to warrant their attention.<\/p>\n\n\n\n<p>At the time of writing, the third wallet was actively transferring 100 ETH batches at a time to Tornado, with 2,800 coins remaining in it. <\/p>\n\n\n\n<p>On June 27, the project's Twitter account reiterated that the team was collaborating with &#8220;two highly recognized blockchain tracing and analysis partners&#8221; in addition to the Federal Bureau of Investigation to look into the attack.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">1\/ We are aware the hacker has begun to move funds through Tornado Cash. The team is working with two highly reputable blockchain tracing and analysis partners, and collaborating with the FBI as part of an investigation into this criminal act. \ud83e\uddf5<\/p>&mdash; Harmony \ud83d\udc99 (@harmonyprotocol) <a href=\"https:\/\/twitter.com\/harmonyprotocol\/status\/1541574195615698945?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">June 28, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>The principal wallet of the explorer still contains about $80 million in ETH. It took the exploiter nearly 13 hours to mix just $21 million, so they might be taking a break or returning some of the stolen money to Horizon.<\/p>\n\n\n\n<p>Positive ETH price swings have raised the dollar value of the haul from the initial estimate of roughly $100 million to $101.5 million.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-about-the-harmony-attack\">About the Harmony Attack<\/h2>\n\n\n\n<p>On June 25, Harmony's founder, Stephen Tse, stated that the exploiter had gained access to the two Horizon Bridge signees that were necessary for the multisig address that was being used to secure funds. He mentioned that the vulnerable Ethereum portion of the bridge was switched to a more secure multisig wallet that required four signatories.<\/p>\n\n\n\n<p>The attack on Horizon is the most recent in a long line of attacks against symbolic bridges. <a href=\"https:\/\/coinscreed.com\/staging\/stolen-assets-have-been-fully-recovered-says-poly-network.html\" target=\"_blank\" rel=\"noreferrer noopener\">Poly Network<\/a> was the largest token bridge to be breached in 2021, losing $610 million that was nearly totally recovered.<\/p>\n\n\n\n<p>Through illegal means, so far in 2022, more than $1 billion has been taken from the Meter, Wormhole, Ronin, and now Horizon token bridges.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Harmony&#8217;s Horizon Bridge money has started to flow into the Tornado Cash Ethererum mixer, indicating that the hacker is not planning to take the $1 million bounty offered by Harmony. The Harmony team&#8217;s decision to conceal the illicit earnings provides an answer to the question of whether their offer of just 1% of the $100 [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":31059,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[],"class_list":["post-31054","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/image-220.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/31054","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=31054"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/31054\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/31059"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=31054"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=31054"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=31054"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}