{"id":88956,"date":"2024-08-07T09:27:12","date_gmt":"2024-08-07T13:27:12","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=88956"},"modified":"2024-08-07T09:28:44","modified_gmt":"2024-08-07T13:28:44","slug":"rain-exchange-hacker-launders-eth-via-tornado","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/rain-exchange-hacker-launders-eth-via-tornado\/","title":{"rendered":"Rain Exchange Hacker Launders ETH via Tornado Cash"},"content":{"rendered":"\n<p>This breach and subsequent <a href=\"https:\/\/coinscreed.com\/staging\/tornado-cash-developer-convicted-of-money-laundering.html\" target=\"_blank\" data-type=\"post\" data-id=\"78828\" rel=\"noreferrer noopener\">laundering activity<\/a> show the continued vulnerabilities faced by centralized exchanges, even those with strong security measures.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1000\" height=\"560\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/08\/Rain-Exchange-Hacker-Launders-ETH-via-Tornado-Cash.webp\" alt=\"\" class=\"wp-image-88960\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/08\/Rain-Exchange-Hacker-Launders-ETH-via-Tornado-Cash.webp 1000w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/08\/Rain-Exchange-Hacker-Launders-ETH-via-Tornado-Cash-300x168.webp 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/08\/Rain-Exchange-Hacker-Launders-ETH-via-Tornado-Cash-768x430.webp 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/08\/Rain-Exchange-Hacker-Launders-ETH-via-Tornado-Cash-860x482.webp 860w\" sizes=\"(max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<p>The hacker responsible for the recent attack on the Rain crypto&nbsp;exchange has begun laundering stolen Ether through Tornado Cash, a popular mixing service.<\/p>\n\n\n\n<p>A blockchain security firm, PeckShield, has closely monitored the situation and&nbsp;identified the action.<\/p>\n\n\n\n<p>The most <a href=\"https:\/\/x.com\/PeckShieldAlert\/status\/1821108289817710855\" target=\"_blank\" rel=\"noreferrer noopener\">recent update<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> from PeckShield indicates that the\u00a0attacker transferred 1,155 Ether,\u00a0estimated to be worth $2.9 million, to Tornado Cash.<\/p>\n\n\n\n<p>This transaction appears to be part of a bigger effort to hide the funds' origins and make them more difficult to track.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Rain Exchange Breach<\/h2>\n\n\n\n<p>Rain is a Bahrain-based cryptocurrency exchange that specializes in providing services to users from the Middle East and Southwest Asia.<\/p>\n\n\n\n<p>On April 29, the exchange was exploited, transferring&nbsp;approximately $14.1 million worth of various&nbsp;cryptocurrencies, such as Bitcoin, Ether, Solana, and XRP, to a new wallet under suspicious circumstances.<\/p>\n\n\n\n<p>Onchain investigator ZachXBT initially reported the exploit on May 13 and provided a detailed account of the suspicious transactions that had occurred two weeks prior.<\/p>\n\n\n\n<p>The report exposed the attack's scope and method, which prompted concern within the crypto community.<\/p>\n\n\n\n<p>In an X post, AJ Nelson, the co-founder of Rain, verified the breach.<\/p>\n\n\n\n<p>Nelson assured users in his statement that the exchange had compensated for the stolen assets from its funds, guaranteeing that the platform would continue functioning&nbsp;as intended.<\/p>\n\n\n\n<p>This prompt response aimed&nbsp;to maintain user trust and showcase the exchange's commitment to transparency and security.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Role of Tornado Cash<\/h2>\n\n\n\n<p>Tornado Cash is a decentralized, non-custodial privacy solution based on Ethereum.<\/p>\n\n\n\n<p>It employs zero-knowledge proofs to allow users to disrupt the onchain link between the&nbsp;source and destination of funds.<\/p>\n\n\n\n<p>However, malicious actors have also exploited this technology to launder stolen cryptocurrencies&nbsp;despite its value to privacy-conscious users.<\/p>\n\n\n\n<p>In this case, the Rain hacker's use of Tornado Cash highlights the difficulties exchanges and law enforcement agencies face in identifying and recovering stolen assets.<\/p>\n\n\n\n<p>The crypto mixer service makes it far more difficult to trace the flow of funds, providing a big challenge in the pursuit of&nbsp;cybercriminals.<\/p>\n\n\n\n<p>Meanwhile, the<a href=\"https:\/\/coinscreed.com\/staging\/nexera-protocol-1-5m-smart-contract-exploit.html\" target=\"_blank\" data-type=\"post\" data-id=\"88929\" rel=\"noreferrer noopener\"> Nexera protocol<\/a> was exploited to obtain $1.5 million in digital assets in a separate smart contract security incident on Aug.\u00a06.<\/p>\n\n\n\n<p>Furthermore, a suspected white-hat hacker\u00a0exploited a vulnerability in the Ronin network to get $9.8 million in ETH tokens, but the funds were later returned on Aug.\u00a06.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This breach and subsequent laundering activity show the continued vulnerabilities faced by centralized exchanges, even those with strong security measures. The hacker responsible for the recent attack on the Rain crypto&nbsp;exchange has begun laundering stolen Ether through Tornado Cash, a popular mixing service. A blockchain security firm, PeckShield, has closely monitored the situation and&nbsp;identified the [&hellip;]<\/p>\n","protected":false},"author":56,"featured_media":88960,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476,21],"tags":[376,984,12002,1437,10782],"class_list":["post-88956","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","category-news","tag-cryptocurrencies","tag-cryptocurrency-exchange","tag-hacks","tag-money-laundering","tag-tornado-cash-2"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/08\/Rain-Exchange-Hacker-Launders-ETH-via-Tornado-Cash.webp","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/88956","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/56"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=88956"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/88956\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/88960"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=88956"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=88956"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=88956"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}