Ronin hackers transferred stolen assets from Ethereum to the Bitcoin network, according to new findings by blockchain researcher and developer liteZero.
Remember after roninbashi hack In March, attackers moved $625 million worth of USDC and ETH into Tornado Cash, an Ethereum-based cryptocurrency mixer, making it difficult for authorities to track the movement of funds. But Tornado wasn’t the end, and the hackers took further steps to conceal the transaction.
follow the money
liteZero said it was tracking the stolen funds and realized that the attackers used network bridges and several crypto exchanges to transfer all assets to the Bitcoin protocol.
I’m tracking stolen funds in Ronin Bridge.
I noticed that Ronin hackers are transferring all funds to the Bitcoin network. Most of the funds are deposited in the mixer (ChipMixer, Blender).In this thread we will walk you through the tracking analysis steps. pic.twitter.com/yrazcJ22xF
liteZero (@blitezero) August 20, 2022
Use of centralized exchanges
Blockchain investigators found that after withdrawing funds from Tornado Cash, the hackers transferred approximately 6,250 ETH ($20.7 million) to centralized exchanges (CEX) such as: binanceHuobi, and FTX to transfer funds to the North Korean cryptocurrency mixer Blender.
In May, the U.S. Treasury Department Licensed Blender notes that a cryptocurrency mixer helped Ronin hackers process more than $20.5 million in stolen funds.
Interestingly, liteZero said most of the authorized Blender addresses were used by Ronin hackers to receive funds after they withdrew from CEX. Following the money, investigators noted that total funds withdrawn from the exchange amounted to $20.72 million. This is consistent with US Treasury charges.
Hackers bridge stolen funds to the Bitcoin network
Hackers converted the remaining assets into renBTC using 1inch or Uniswap. renBTC is Bitcoin wrapped on the Ethereum network powered by the Ren Protocol. Ren allows the movement of value between blockchains, so hackers have been able to bridge assets from Ethereum to the Bitcoin network.
The hackers then transferred most of the funds to crypto-mixers such as ChipMixer and Blender.
Closing the Twitter thread, liteZero said it is currently working on analyzing the hackers, but believes it will be more complicated.
I’m working on analyzing the Ronin hacker, and the next task gets more complicated.
“Where’s the money?”
There are many mysteries, so I’m looking forward to future developments.
Thanks for reading my thread, good luck!liteZero (@blitezero) August 20, 2022
Binance Free $100 (Limited): use this link Register to receive $100 free and 10% commission on your first month of Binance Futures (Clause).
PrimeXBT Special Offer: use this link Receive up to $7,000 on deposits when you register and enter the POTATO50 code.