Hack Track: Analysis on BitMart Hack

On December 4, 2021, crypto exchange BitMart suffered an attack on its Ethereum and Binance Smart Chain hot wallets, resulting in a loss of nearly $200 million USD. Founder and CEO Sheldon Xia confirmed the incident, writing on Twitter: "We have identified a large-scale security breach related to one of our ETH hot wallets and one of our BSC hot wallets.”

This latest breach happened amidst a rapid increase in attacks suffered by the crypto industry. According to industry reports, a total of 169 blockchain hacking incidents have taken place as of November 2021, with close to $7 billion in funds lost. With the rapid increase in global blockchain hacking incidents, regulatory scrutiny around the crypto industry is also increasing.

In its first government-wide list of priorities for anti-money laundering and countering the financing of terrorism (AML/CFT), the U.S. Financial Crime Enforcement Network (FinCEN) made virtual currency considerations one of its top priorities. Further, FinCEN had also issued a warning, noting that in cases of hacks, criminals may leverage tools such as mixers and tumblers in order to break the connection between the sender address and the receiver address. On October 6, 2021, the U.S. Department of Justice announced the National Cryptocurrency Enforcement Team (NCET), an enforcement team dedicated to investigating and prosecuting criminal misuses of cryptocurrency — in particular, crimes committed by virtual currency exchanges, mixing and tumbling services, and money laundering infrastructure.

With the rise in crypto hacking incidents, enhanced security measures by the industry have become ever more urgent. Since hot wallets are connected to the internet, they are particularly vulnerable to attacks. In fact, exchanges with insufficient blockchain monitoring processes are most vulnerable to attacks.

What Happened?

Attackers stole funds out of BitMart’s Ethereum and Binance Smart Chain hot wallets. After transferring the funds out of BitMart, hackers reportedly used decentralized exchange aggregators 1inch and PancakeSwap to exchange the stolen tokens. From there, the ether coins were deposited into a privacy mixer known as Tornado Cash, thus making it difficult to track the stolen funds.

BitMart revealed in a tweet that the attack was mainly caused by a “stolen private key that had two of our hot wallets compromised.” BitMart claims that only a small percentage of its assets were affected, and all of its other wallets remain secure and unharmed. Even so, the exchange has frozen withdrawals and is reviewing its security measures. BitMart, however, remains confident that it will be able to gradually restart its deposit and withdrawal functions.

BitMart has stated that it will use its own funding to cover the incident and compensate its users for their loss. Merkle Science has already updated its database and blacklisted wallet addresses involved in the attack

Merkle Science’s On-Chain Analysis

Ethereum Blockchain Analysis

  1. On the Ethereum blockchain, the hacker stole 29 types of tokens including ETH. Please refer to Table 1 below for the full list of ERC-20 and ETH tokens and the respective amounts stolen. In total $90,487,593.65 worth of crypto was stolen from Ethereum blockchain.
  2. 148.87 ETH ($599,576.39) was stolen from BitMart’s hot wallet 0x68b22215ff74e3606bd5e6c1de8c2d68180c85f7 and transferred to the hacker’s wallet 0x39fb0dcd13945b835d47410ae0de7181d3edf270 (H1) on December 4, 2021.
  3. Around 18,044.75 ETH ($74.07 million) worth of stolen ERC-20 tokens from H1 were converted into ETH using a well-known decentralized exchange aggregator 1inch.
  4. 18,085 ETH ($74.61 million) from H1 was then transferred to the hacker’s 2nd wallet  0x4bb7d80282f5e0616705d7f832acfc59f89f7091 (H2) on December 5, 2021.
  5. 100 ETH ($417,118.62) was then transferred from H1 to Tornado Cash in order to mix the stolen funds.
  6. Separately, H2 received 3,110.69 ETH ($12.97 million) from the swapped ERC-20 tokens via 1inch. These were not funds that were stolen from BitMart hot wallets.)
  7. In total, H2 received a total 21,195.73 ETH ($85.36 million) from steps 3 and 6.
  8. The hacker then moved more than 99.9% (21,170 ETH) of the total ETH from H2 to Tornado Cash in order to mix the funds.

Image 1: Ethereum on-chain flow of funds with corresponding steps

Binance Smart Chain Blockchain Analysis

  1. On Binance Smart Chain, the hacker stole 20 types of tokens including BNB. Please refer to Table 2 below for the full list of BEP-20 and BNB tokens and the respective amounts stolen. In total $120,601,070.74 worth of crypto was stolen from Binance Smart Chain.
  2. 213.57 BNB ($121,565) was stolen from BitMart’s hot wallet 0x8c128dba2cb66399341aa877315be1054be75da8 and was transferred to the hacker’s wallet 0x25fb126b6c6b5c8ef732b86822fa0f0024e16c61 (H3) on December 4, 2021.
  3. Stolen BEP-20 tokens were swapped on well-known DEXs 1inch and PancakeSwap to the value of 56,637.35 BNB into H3.
  4. Total 99.79% (56,523.78 BNB) of the BNB funds from H3 were transferred to Tornado Cash to mix the stolen funds.

Image 2: Binance Smart Chain on-chain flow of funds

