{"id":92209,"date":"2024-09-04T06:53:23","date_gmt":"2024-09-04T10:53:23","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=92209"},"modified":"2024-09-04T06:53:34","modified_gmt":"2024-09-04T10:53:34","slug":"penpie-hacker-moves-funds-via-tornado-cash","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/penpie-hacker-moves-funds-via-tornado-cash\/","title":{"rendered":"Penpie Hacker Moves 7M of Stolen Funds Via Tornado Cash"},"content":{"rendered":"\n<p>Within approximately twelve hours of stealing $27 million on September 3, the hacker responsible for the <a href=\"https:\/\/coinscreed.com\/staging\/penpie-protocol-suffers-27m-loss-to-recent-hack.html\" data-type=\"post\" data-id=\"92149\">Penpie protocol<\/a> transfers roughly $7 million of stolen funds through the crypto mixer Tornado Cash.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"680\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/PENP-1024x680.webp\" alt=\"Penpie Hacker Moves 7M of  Stolen Funds Via Tornado Cash\" class=\"wp-image-92213\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/PENP-1024x680.webp 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/PENP-300x199.webp 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/PENP-768x510.webp 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/PENP-330x220.webp 330w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/PENP-420x280.webp 420w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/PENP-860x571.webp 860w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/PENP.webp 1200w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Penpie Hacker Moves 7M of Stolen Funds Via Tornado Cash<\/figcaption><\/figure>\n\n\n\n<p>The intruder transferred 26% of the hacked funds to a Tornado Cash address on September 4, according to Web3 security firm Cyvers.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">\ud83d\udea8ALERT\ud83d\udea8<a href=\"https:\/\/twitter.com\/Penpiexyz_io?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@Penpiexyz_io<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> exploiter has deposited around $7M to <a href=\"https:\/\/twitter.com\/TornadoCash?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@TornadoCash<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> at <a href=\"https:\/\/t.co\/f17YcJ6blH\" target=\"_blank\">https:\/\/t.co\/f17YcJ6blH<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><br><br>Want to keep your company off our alerts radar? Learn how to secure your assets: Book a Demo \ud83d\ude80 <a href=\"https:\/\/t.co\/uUbFkFTp4h\" target=\"_blank\">https:\/\/t.co\/uUbFkFTp4h<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><a href=\"https:\/\/twitter.com\/hashtag\/CyversAlert?src=hash&ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">#CyversAlert<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> <a href=\"https:\/\/t.co\/zFX85sK9A9\" target=\"_blank\">https:\/\/t.co\/zFX85sK9A9<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> <a href=\"https:\/\/t.co\/J20g3HS2T0\" target=\"_blank\">pic.twitter.com\/J20g3HS2T0<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; \ud83d\udea8 Cyvers Alerts \ud83d\udea8 (@CyversAlerts) <a href=\"https:\/\/twitter.com\/CyversAlerts\/status\/1831221291027755113?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">September 4, 2024<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>The hacker's address is continuously laundering the stolen funds through numerous transactions to <a href=\"https:\/\/en.wikipedia.org\/wiki\/Tornado_Cash\" target=\"_blank\" data-type=\"link\" data-id=\"https:\/\/en.wikipedia.org\/wiki\/Tornado_Cash\" rel=\"noreferrer noopener nofollow\">Tornado Cash<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> addresses, per blockchain security firm PeckShield.<\/p>\n\n\n\n<p>As a result of the $27 million breach, the Penpie protocol has suspended all deposits and withdrawals.<\/p>\n\n\n\n<p>&#8220;The attacker deployed the initial contract for the attack at 1745 UTC,&#8221; Pendle stated in an X post on September 4.<\/p>\n\n\n\n<p>Wi-Fi protocol Pendle stated that it contacted security specialists Seal 911 to prevent any subsequent linked attacks.<\/p>\n\n\n\n<p>The suspension of all contracts on Pendle prevented additional attempts to siphon assets from Penpie, thereby protecting $105M that the attacker could have potentially taken.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cAt 0050 UTC, after rigorous checks and coordination with all relevant parties to confirm step 1 and 2, Pendle contracts were safely unpaused, and normal operations resumed.\u201d<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Crypto Losses resulting from cyberattacks <\/h2>\n\n\n\n<p>An Immunfi report from August 29 indicated that over $1.2 billion in funds had been stolen through breaches and exploits thus far this year, a 15.5% increase from the same period in 2023 when losses stood at slightly over $1 billion.<\/p>\n\n\n\n<p>The United States Federal Bureau of Investigation (FBI) issued a warning on September 3 against <a href=\"https:\/\/coinscreed.com\/staging\/north-korean-cyberattacks-expose-brazilian-fintech-firms.html\" data-type=\"post\" data-id=\"81174\">North Korean cyber criminals<\/a> targeting employees at decentralized finance and cryptocurrency firms to steal funds through &#8220;complex and elaborate&#8221; social engineering campaigns.<\/p>\n\n\n\n<p>PeckShield, a security firm, reported on September 1 that financial losses from breaches in August 2024 exceeded $313 million. <\/p>\n\n\n\n<p>The theft of approximately $238 million in Bitcoin resulted from two of the most significant attacks during the month.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Within approximately twelve hours of stealing $27 million on September 3, the hacker responsible for the Penpie protocol transfers roughly $7 million of stolen funds through the crypto mixer Tornado Cash. The intruder transferred 26% of the hacked funds to a Tornado Cash address on September 4, according to Web3 security firm Cyvers. The hacker&#8217;s [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":92213,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[2118,21629,10782],"class_list":["post-92209","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-hacker","tag-penpie-protocol","tag-tornado-cash-2"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/PENP.webp","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/92209","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=92209"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/92209\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/92213"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=92209"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=92209"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=92209"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}