Joined June 2023
5 Photos and videos
Elliptic Investigations retweeted
13 Jul 2024
Following the release of our research linking Huione Guarantee and Huione Pay to the laundering of proceeds of online scams, Tether has blacklisted a TRON address belonging to Huione Pay, freezing $29.6 million. TNVaKWQzau7xL9bcnvLmF9KSEQkWEs4Ug8
1
1
2
1,142
Based on the $PLA market price at the time of the thefts, the total value of stolen tokens is $290 million. However, prior to the breaches the circulating supply was only ~577 million, and it's unlikely the hacker could realise anything close to this amount.
1
376
1/7 The deployment of these contracts is interesting. Not only does it point to further confluence between the laundering of this hack and the Harmony hack (they did the same back in February) - it shows the importance of taking a holistic approach to transaction monitoring...
14 Jun 2023
Replying to @tayvano_
After that aforementioned Railgun run, I guess they didn't want to risk using a thing thats maybe decentralized or maybe decentralization-theatre? Esp. if it wasnt making them anon? So, naturally, they just wrote their own contracts. e.g. on Jan28... library.dedaub.com/ethereum/…
6
4
12
3,488
6/7 After the swapping assets, Lazarus have moved through a large number of complex hops (splitting and reconsolidating), again a deliberate attempt to obfuscate their source of funds, before bridging their assets to Avalanche through the Avalanche Bridge.
2
1
2
1,244
7/7 These two tactics, swapping assets and layering complex transactions, are just two examples of typologies we have observed recently associated with Lazarus. To find more about other typologies read our newly-released Typologies Report here. elliptic.co/resources/ellipt…
2
1
5
1,179
Reported losses from the @AtomicWallet hack are now over $100 million hub.elliptic.co/analysis/nor…

9
13
23
19,075
This includes 10 addresses that have lost more than $1M, and 164 that have lost more than $100k. The median loss is $2.8k
1
615
After a significant and successful cross-community effort between @elliptic, many of our exchange partners and friends to freeze stolen @AtomicWallet funds, Lazarus have now turned to OFAC-sanctioned Exchange, Garantex, to trade their assets for BTC...
11
12
30
9,703
Funds withdrawn as BTC continue to be laundered through Sinbad(Blender?).io.
4
1,302
Atomic Wallet hack funds have just been swapped for USDT and bridged to TRON tronscan.org/#/address/THfkz…

3
4
669
..and another TRON account tronscan.org/#/address/TUrm4…

1
524
We're now confident in attributing the >$35 million Atomic Wallet hack to North Korea's Lazarus Group: hub.elliptic.co/analysis/nor…

9
6
17
4,788
The $35 million stolen from @AtomicWallet users is being laundered through Sinbad - the mixer fka(?) Blender and used heavily by NK's Lazarus Group hub.elliptic.co/analysis/35-…

6
4
9
6,014