<img src="https://secure.glue1lazy.com/215876.png" style="display:none;">

LastPass Hack: Flow of Funds Analysis

On October 25th, 2023, LastPass, a widely used password manager, fell victim to a security breach. The breach had significant ramifications, affecting approximately 25 users whose assets were distributed across 80 wallets. This breach resulted in a staggering loss of approximately $4.4 million in various cryptocurrencies. Among the affected blockchain networks were Bitcoin, Ethereum, Binance Smart Chain, Polygon, Solana, Cardano, Litecoin, Arbitrum, and Avalanche. 

Read More

Hack Track: Mixin Flow of Funds Analysis

Mixin Network, a Hong Kong-based digital asset transactional platform, reported a security breach on 25 September, revealing a loss of approximately $200 million due to a hack of its cloud service provider. The stolen funds accounted for so far are comprised of ETH, USDT (swapped to DAI), and BTC. If the $200M figure stated by Mixin is accurate, it would make this incident the biggest hack of 2023 so far.

Read More

Stake Suffers $38 million Hack

On the 4th of September 2023, the popular crypto gambling platform Stake suffered a major security breach due to private key leak resulting in the theft of approximately US $38 million.  The preliminary investigation confirms that unauthorized withdrawals were detected from Stake's hot wallets on the Ethereum, Polygon, and Binance Smart Chain networks.

Read More

Hack Track: Analysis of Beanstalk Flash Loan Attack

On April 17, 2022, Beanstalk Farms, a decentralized credit-focused stablecoin protocol built on Ethereum, suffered an exploit. The attackers exploited Beanstalk’s governance protocol to extract $182 million in collateral, around $80 million of which went to the hacker as profit. Beanstalk enables participants to earn rewards such as Stalk and Seeds by contributing to a central funding pool called the Silo. The participants receive four Seeds for every Bean stablecoin deposited in the Silo, which in turn, earns them 0.004 Stalk every hour. Stalks are ERC-20 standards tokens that bestow governance rights over the protocol to its holders and give holders voting power. Unlike Stalks, Seeds are not liquid and do not give voting rights to their holders. 

Read More

Hack Track: Analysis of Ronin Network Exploit

[Update 2022.04.18]

On April 14, 2022, the U.S. Department of Treasury’s Office tied the North Korea-based hacking group, Lazarus, to the Ronin Network exploit. The Office of Foreign Assets Control (OFAC) added an Ethereum wallet address (0x098B716B8Aaf21512996dC57EB0615e2383E2f96) associated with Lazarus to its sanctions list. The sanctioned wallet address contains funds stolen in the Ronin security breach. At the time of the publication, the wallet holds 138,433.136 ETH valuing close to $402 million. The Ronin Bridge was exploited for 173,600 ETH and 25.5 million USDC, worth around $568 million at the time of the transaction.

The North Korean state-sponsored Lazarus group, has been associated with several major cyberattacks over the years, including a 2014 hack on Sony Pictures and the 2017 WannaCry ransomware attacks. The OFAC first imposed sanctions on Lazarus and two of its sub-groups ​​Bluenoroff and Andariel in September 2019. In the announcement, the U.S. Department of Treasury stated Lazarus and its sub-groups are controlled by North Korea’s primary intelligence agency, the Reconnaissance General Bureau (RGB).

In its official update, the Ronin Network confirmed that the FBI has linked Lazarus to its validator security breach. Additionally, the Ronin Network also stated that it is “still in the process of adding additional security measures before redeploying the Ronin Bridge to mitigate future risk.”  The bridge is expected to be deployed by end of April.


 

Around $568 million worth of crypto has been stolen from the Ronin Network, the blockchain underlying the popular crypto game Axie Infinity. The amount lost is calculated based on the ETH/USD price conversion rate on the date of the transaction — March 23, 2022.  On March 29, 2022, Sky Mavis, the creator of both Ronin and Axie Infinity, reported that the Ronin bridge had been exploited for 173,600 Ethereum (ETH) and 25.5 million USDC

Read More