{"id":78189,"date":"2024-05-07T05:29:12","date_gmt":"2024-05-07T09:29:12","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=78189"},"modified":"2024-05-07T05:29:15","modified_gmt":"2024-05-07T09:29:15","slug":"kronos-research-hacker-moves-exploit-to-tornado-cash","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/kronos-research-hacker-moves-exploit-to-tornado-cash\/","title":{"rendered":"Kronos Research Hacker Moves Exploit to Tornado Cash"},"content":{"rendered":"\n<p>Six months after the $25 million hack on quantitative trading firm Kronos Research, one of the six wallets linked to the hacker has moved funds to <a href=\"https:\/\/coinscreed.com\/staging\/arbitrum-dao-votes-to-finance-tornado-cash-devs-legal-expenses.html\" target=\"_blank\" rel=\"noreferrer noopener\">Tornado Cash<\/a>.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"533\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-21-1024x533.png\" alt=\"Kronos Research Hacker Moves Exploit to Tornado Cash\" class=\"wp-image-78199\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-21-1024x533.png 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-21-300x156.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-21-768x400.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-21-750x391.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-21.png 1123w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Kronos Research Hacker Moves Exploit to Tornado Cash<\/figcaption><\/figure>\n\n\n\n<p>The compromised wallet initially transmitted 1,314 Ether, valued at $4 million, to an address beginning with 0x8F5e4 and then transferred the entire amount to an address beginning with 0x164A24b.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-jnews-featured-750\"><img decoding=\"async\" width=\"750\" height=\"160\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-19-750x160.png\" alt=\"Source: PeckShield\" class=\"wp-image-78196\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-19-750x160.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-19-300x64.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-19-768x164.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-19.png 948w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><figcaption class=\"wp-element-caption\"><em>Source: PeckShield<\/em><\/figcaption><\/figure>\n\n\n\n<p>The hacker transmitted ten transactions totaling one hundred Ethereum from the final wallet to the cryptocurrency mixing application Tornado Cash.\u00a0<\/p>\n\n\n\n<figure class=\"wp-block-image size-jnews-featured-750\"><img decoding=\"async\" width=\"750\" height=\"259\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-20-750x259.png\" alt=\"The hacker made several transfers to Tornado Cash. Source: Etherscan\" class=\"wp-image-78197\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-20-750x259.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-20-300x104.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-20-768x265.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-20.png 950w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><figcaption class=\"wp-element-caption\">The hacker made several transfers to Tornado Cash. Source: Etherscan<\/figcaption><\/figure>\n\n\n\n<p>Tornado Cash is an open-source cryptocurrency aggregator on <a href=\"https:\/\/ethereum.org\/en\/developers\/docs\/evm\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Ethereum Virtual Machine<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>-compatible networks. The blending services significantly complicate tracing the origin of the funds by obfuscating the path of the cryptocurrency transactions.\u00a0<\/p>\n\n\n\n<p>Hackers frequently exploit blending services to launder stolen funds through decentralized exchange platforms despite their inception as privacy tools.\u00a0<\/p>\n\n\n\n<p>The substantial adoption of Tornado Cash for illegitimate money transfers led to the imposition of sanctions by the United States government on its usage in August 2022. Following this, in 2023, the organization's founders faced charges of money laundering and sanctions violations.&nbsp;<\/p>\n\n\n\n<p>Although there is some disagreement among crypto community members concerning the adoption of privacy tools, a general stance opposes state persecution of application developers.&nbsp;<\/p>\n\n\n\n<p>PeckShield, a crypto analytics provider, issued a warning concerning the transfer of funds on X. The advisory noted that the transfer to Tornado Cash indicates the hacker's intention to engage in money laundering with the stolen funds.&nbsp;<\/p>\n\n\n\n<p>As exploiters can exchange block addresses once identified, they have favored <a href=\"https:\/\/coinscreed.com\/staging\/swan-to-block-accounts-of-customers-using-crypto-mixing-services.html\" target=\"_blank\" rel=\"noreferrer noopener\">crypto-mixing s<\/a>ervices over centralized exchanges.\u00a0<\/p>\n\n\n\n<p>The unauthorized individuals gained access to Kronos Capital's application programming interface keys in November 2023, thereby facilitating an infiltration of the organization. Initially, the company refuted any financial loss in its initial announcement.&nbsp;<\/p>\n\n\n\n<p>Later, on-chain investigator ZachXBT disclosed that the theft and transfer of approximately $12,800 ETH valued at $25 million to six unique crypto wallet addresses had occurred. While investigating the loss, Kronos Capital suspended its trading services.&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Six months after the $25 million hack on quantitative trading firm Kronos Research, one of the six wallets linked to the hacker has moved funds to Tornado Cash. The compromised wallet initially transmitted 1,314 Ether, valued at $4 million, to an address beginning with 0x8F5e4 and then transferred the entire amount to an address beginning [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":78199,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[2118,19453,10782],"class_list":["post-78189","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-hacker","tag-kronos-research","tag-tornado-cash-2"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/05\/image-21.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/78189","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=78189"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/78189\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/78199"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=78189"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=78189"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=78189"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}