{"id":61429,"date":"2023-10-12T13:06:22","date_gmt":"2023-10-12T17:06:22","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=61429"},"modified":"2023-10-12T13:06:22","modified_gmt":"2023-10-12T17:06:22","slug":"elliptic-connects-ftxs-400-million-loss-to-russian-syndicates","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/elliptic-connects-ftxs-400-million-loss-to-russian-syndicates\/","title":{"rendered":"Elliptic Connects FTX&#8217;s $400 Million Loss to Russian Syndicates"},"content":{"rendered":"\n<p>Elliptic traces the $400 million in stolen FTX assets to<a href=\"https:\/\/coinscreed.com\/staging\/us-department-of-justice-charges-two-russians-in-mt-gox-hack.html\" target=\"_blank\" rel=\"noreferrer noopener\"> Russian cyber criminals,<\/a> RenBridge, and money movement mixers.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"536\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/CBDC-1-1024x536.webp\" alt=\"\" class=\"wp-image-61431\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/CBDC-1-1024x536.webp 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/CBDC-1-300x157.webp 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/CBDC-1-768x402.webp 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/CBDC-1-18x9.webp 18w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/CBDC-1-1320x691.webp 1320w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/CBDC-1-750x392.webp 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/CBDC-1-1140x596.webp 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/CBDC-1.webp 1338w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Elliptic Connects FTX's $400 Million Loss to Russian Syndicates<\/figcaption><\/figure>\n\n\n\n<p>Approximately $400 million of stolen assets from the now-defunct FTX cryptocurrency exchange may have been traced to cybercriminal organizations based in Russia. This discovery is based on a comprehensive analysis by <a href=\"https:\/\/www.elliptic.co\/our-story#:~:text=Founded%20in%202013%2C%20Elliptic%20pioneered,of%20crypto%20compliance%20solutions%20globally.\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Elliptic, a prominent research firm. <span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><\/p>\n\n\n\n<p>A significant portion, 65,000 ETH (equivalent to $100 million), was transferred to the Bitcoin blockchain five days after the robbery. For this, the perpetrators utilized RenBridge's services.<\/p>\n\n\n\n<p>In addition, the criminals utilized a blockchain-based tool known as a mixer to conceal their traces further. Elliptic's report emphasized, \u201cOf the 4,536 Bitcoins converted from ether at RenBridge, 2,849 BTC underwent mixing, mainly using a ChipMixer service.\u201d.<\/p>\n\n\n\n<p>Nonetheless, this method is not a failsafe. At least $4 million of these assets were transferred to various exchanges, indicating a potential cash-out effort.<\/p>\n\n\n\n<p>Russian Criminal Organizations Likely Responsible for FTX Robbery, &#8216;ChipMixer', was shut down following international scrutiny and a joint law enforcement operation. <\/p>\n\n\n\n<p>Therefore, the perpetrators shifted their mixing needs to another service named Sinbad. Identifying the perpetrators remains difficult, but certain patterns in the wallet data and the path of fund transfers may provide hints.<\/p>\n\n\n\n<p>In addition, while there have been hypotheses implicating rogue FTX employees or even the notorious North Korean hacker group Lazarus, recent evidence points to a Russian connection. <\/p>\n\n\n\n<p>According to Elliptic's analysis, &#8220;a Russian-affiliated actor appears likely.&#8221; Prior to reaching exchanges, a significant portion of the stolen assets merged with funds linked to Russian criminal syndicates, including funds associated with ransomware attacks and darknet markets. Elliptic states:<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:100%\">\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cpoints to the involvement of a broker or other intermediary with a nexus in Russia.\u201d<\/p>\n<\/blockquote>\n<\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-sam-bankman-fried-faces-charges\">Sam Bankman-Fried Faces Charges<\/h2>\n\n\n\n<p>The story of FTX took a dramatic turn on November 11, 2022. Within hours of announcing bankruptcy and Sam Bankman-Fried's resignation, FTX, and FTX US accounts were depleted. Federal prosecutors charged Bankman-Fried with multiple counts of fraud shortly thereafter.<\/p>\n\n\n\n<p>A few days before Bankman-Fried's trial, the previously inert stolen assets began exhibiting movement. Using the <a href=\"https:\/\/www.railgun.org\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Railgun privacy wallet <span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>and THORChain exchange, thieves exchanged over 15,000 ether from stolen assets for other tokens earlier this month.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Elliptic traces the $400 million in stolen FTX assets to Russian cyber criminals, RenBridge, and money movement mixers. Approximately $400 million of stolen assets from the now-defunct FTX cryptocurrency exchange may have been traced to cybercriminal organizations based in Russia. This discovery is based on a comprehensive analysis by Elliptic, a prominent research firm. A [&hellip;]<\/p>\n","protected":false},"author":53,"featured_media":61431,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21,11476],"tags":[16723,5717,16724,5817],"class_list":["post-61429","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-hacks-and-scams","tag-elliptic-2","tag-ftx-2","tag-ftx-hacker","tag-hack-2"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/CBDC-1.webp","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/61429","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/53"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=61429"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/61429\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/61431"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=61429"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=61429"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=61429"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}