{"id":97785,"date":"2024-10-25T14:28:46","date_gmt":"2024-10-25T18:28:46","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=97785"},"modified":"2024-10-25T14:30:28","modified_gmt":"2024-10-25T18:30:28","slug":"us-government-recover-19-3m-after-alleged-hack","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/us-government-recover-19-3m-after-alleged-hack\/","title":{"rendered":"US Government Recovers $19.3M After Alleged Hack"},"content":{"rendered":"\n<p>A government wallet that was drained of US$20 million on Thursday had most of its assets recovered on Friday.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/10\/US-Government-Recovers-19.3M-After-Alleged-Hack-1024x576.webp\" alt=\"US Government Recovers $19.3M After Alleged Hack\" class=\"wp-image-97799\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/10\/US-Government-Recovers-19.3M-After-Alleged-Hack-1024x576.webp 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/10\/US-Government-Recovers-19.3M-After-Alleged-Hack-300x169.webp 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/10\/US-Government-Recovers-19.3M-After-Alleged-Hack-768x432.webp 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/10\/US-Government-Recovers-19.3M-After-Alleged-Hack-860x484.webp 860w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/10\/US-Government-Recovers-19.3M-After-Alleged-Hack.webp 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>A hacker stole $20 million from a U.S. government wallet on Thursday, though most of the funds were unexpectedly returned on Friday, raising speculation about the incident. <\/p>\n\n\n\n<p>The activity, which Twitter flagged as one of the largest <a href=\"https:\/\/coinscreed.com\/staging\/crypto-hackers-steal-over-1-2-billion-in-2024.html\" target=\"_blank\" data-type=\"post\" data-id=\"91704\" rel=\"noreferrer noopener\">thefts this year,<\/a> was discovered by renowned blockchain investigator ZachXBT, who noted that the wallet had been making \u201cnefarious\u201d transfers through multiple DeFi protocols and instant exchanges.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">U.S. Government Recovers Millions in Stolen Crypto<\/h2>\n\n\n\n<p>ZachXBT reported that the hacker allegedly stole around $20 million in crypto assets and returned about $19 million to the government. <\/p>\n\n\n\n<p>Today\u2019s transaction included the return of 2,408 ETH and 13.19 million aUSDC to the original government wallet. However, exchanges Switchain and HitBTC have not yet returned funds sent to them. <\/p>\n\n\n\n<p>Arkham Intelligence said early Friday saw the return of $19.3 million in Ethereum and USDC to the wallet. <\/p>\n\n\n\n<p>However, ZachXBT noted on his <a href=\"https:\/\/t.me\/investigations\/173\" target=\"_blank\" rel=\"noreferrer noopener\">Telegram channel<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> that \u201cthe funds sent to exchanges have not been recovered.\u201d<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">\ud835\udde8\ud835\udde3\ud835\uddd7\ud835\uddd4\ud835\udde7\ud835\uddd8: $\ud835\udfed\ud835\udff5\ud835\udde0 \ud835\udde8\ud835\udde6 \ud835\uddda\ud835\uddfc\ud835\ude03\ud835\uddf2\ud835\uddff\ud835\uddfb\ud835\uddfa\ud835\uddf2\ud835\uddfb\ud835\ude01 \ud835\uddf3\ud835\ude02\ud835\uddfb\ud835\uddf1\ud835\ude00 \ud835\uddff\ud835\uddf2\ud835\ude01\ud835\ude02\ud835\uddff\ud835\uddfb\ud835\uddf2\ud835\uddf1<br><br>The US Government\u2019s address has just received $19.3M back following yesterday\u2019s reported hack, less than 24 hours after the initial address breach.<br><br>88% of the compromised USD value has now been\u2026 <a href=\"https:\/\/t.co\/F8q6iikBrT\" target=\"_blank\">https:\/\/t.co\/F8q6iikBrT<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> <a href=\"https:\/\/t.co\/Vo7I7ZH9K1\" target=\"_blank\">pic.twitter.com\/Vo7I7ZH9K1<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; Arkham (@arkham) <a href=\"https:\/\/twitter.com\/arkham\/status\/1849823544173011372?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">October 25, 2024<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Arkham\u2019s analytics suggest the government wallet is still short about $1.2 million of the original $20 million, with these remaining funds linked to assets seized by the U.S. Department of Justice from the infamous 2016 Bitfinex hack.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Concerns Raised by Arkham Intelligence<\/h2>\n\n\n\n<p>Arkham Intelligence noted earlier suspicious activity in U.S. government crypto wallets when seized assets were moved from Aave, drawing attention to a transfer of $20 million in USDC, USDT, aUSDC, and ETH. <\/p>\n\n\n\n<p>Notably, the address \u201c0xc9E\u201d allegedly received these seized assets from nine different government-linked addresses, including one, \u201c0xE2F,\u201d cited in court documents for the 2016 Bitfinex case involving Ilya Lichtenstein and Heather Rhiannon Morgan. <\/p>\n\n\n\n<p>The documents referenced additional wallets associated with Aave, Curve Finance, and Yearn Finance, where significant USDT holdings were maintained.<\/p>\n\n\n\n<p>After the transfers, Arkham noted the funds ended up in wallet \u201c0x348,\u201d where they appeared to be converted to ETH. Arkham suspects the hacker has started laundering the funds through addresses associated with a money-laundering service.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Analyst Identifies Gaps in Bitfinex Forfeiture Documents<\/h2>\n\n\n\n<p>On-chain analyst Ergo BTC recently identified potential discrepancies and security issues regarding seized crypto within the <a href=\"https:\/\/coinscreed.com\/staging\/us-government-moves-922-million-in-seized-bitcoin-from-bitfinex-hack.html\" target=\"_blank\" data-type=\"post\" data-id=\"72722\" rel=\"noreferrer noopener\">Bitfinex<\/a> forfeiture documents. <\/p>\n\n\n\n<p>He noted inconsistencies between the official records and the custody agencies listed, with the U.S. Marshals Service (USMS) notably absent in reports of the compromised Ethereum address transfer.<\/p>\n\n\n\n<p>Ergo observed that 74 BTC from a seized change output had already been spent and provided a TXID for verification. He also reported another 3,100 BTC spent from a cluster of seizure-related addresses, again backed by a TXID. <\/p>\n\n\n\n<p>Ergo pointed out a gap between the documented seized assets and the actual on-chain movements, adding that it's improbable all Bitfinex-seized assets were compromised. <\/p>\n\n\n\n<p>He suggested that these discrepancies may reflect a need for improved \u201cdevice hygiene\u201d in asset security and management practices.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A government wallet that was drained of US$20 million on Thursday had most of its assets recovered on Friday. A hacker stole $20 million from a U.S. government wallet on Thursday, though most of the funds were unexpectedly returned on Friday, raising speculation about the incident. The activity, which Twitter flagged as one of the [&hellip;]<\/p>\n","protected":false},"author":56,"featured_media":97799,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[1496,1512],"class_list":["post-97785","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-hack","tag-us-government"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/10\/US-Government-Recovers-19.3M-After-Alleged-Hack.webp","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/97785","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/56"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=97785"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/97785\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/97799"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=97785"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=97785"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=97785"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}