Report: Ronin Crypto Hackers Find New Mixer to Convert Stolen ETH to BTC

Hackers have more recently tapped ChipMixer, a crypto mixing service founded in 2017 that has not yet been added to OFAC’s blocked list

article-image

Blockworks exclusive art by axel rangel

share

key takeaways

  • Ronin bridge hackers moved funds to the Bitcoin network, new report shows
  • Lazarus Group has used various crypto mixing services to conceal funds, including one not yet targeted by OFAC

The hacking collective believed to be behind the $625-million Ronin bridge hack has transferred stolen ether into bitcoin using a cryptocurrency mixing service the US Treasury has not yet targeted, according to a new report. 

Lazarus Group, initially sanctioned by the Office of Foreign Assets Control (OFAC) in 2019, has used OFAC sanctioned cryptocurrency mixing services Blender.io and Tornado Cash to attempt to move and conceal funds. 

Hackers have more recently tapped ChipMixer, a mixer founded in 2017 that has yet to be added to OFAC’s blocked list, according to the report  from blockchain security firm SlowMist. 

Learn: How Crypto Mixers and Privacy Coins Work

Lazarus Group converted 25.5 million USDC to ETH in March 2022. In the days that followed, hackers moved the ETH to various exchanges, including FTX and Crypto.com before withdrawing to the bitcoin network and mixing it through Blender.io, which the Treasury sanctioned in May. 

Between April and May, the group moved funds through Tornado Cash, which was added to OFAC’s blocked list earlier this month. 

Many of the funds were mixed through various services, the report said. Roughly half of the laundered bitcoins have been run through ChipMixer, according to SlowMist. 

“36.6% of laundered funds are currently held at the hacker’s address, totalling 2,586 BTC,” the report noted. “6.2% of funds laundered were moved to Blender, with 3.8% of laundered funds moved to CryptoMixer and a small percentage to other unknown entities.” 

The report comes as 2022 has seen an uptick in the use of crypto mixing services, which allow users to conceal the transaction history of certain cryptocurrencies by pooling and mixing them together with other users’ funds. 

The 30-day moving average of value received by mixers reached an all-time high of nearly $52 million worth of crypto on April 19, according to a July report by Chainalysis — or roughly double the volumes at the same time in 2021.


Start your day with top crypto insights from David Canellis and Katherine Ross. Subscribe to the Empire newsletter.

Explore the growing intersection between crypto, macroeconomics, policy and finance with Ben Strack, Casey Wagner and Felix Jauvin. Subscribe to the On the Margin newsletter.

The Lightspeed newsletter is all things Solana, in your inbox, every day. Subscribe to daily Solana news from Jack Kubinec and Jeff Albus.

Tags

Upcoming Events

Salt Lake City, UT

MON - TUES, OCT. 7 - 8, 2024

Blockworks and Bankless in collaboration with buidlbox are excited to announce the second installment of the Permissionless Hackathon – taking place October 7-8 in Salt Lake City, Utah. We’ve partnered with buidlbox to bring together the brightest minds in crypto for […]

Salt Lake City, UT

WED - FRI, OCTOBER 9 - 11, 2024

Pack your bags, anon — we’re heading west! Join us in the beautiful Salt Lake City for the third installment of Permissionless. Come for the alpha, stay for the fresh air. Permissionless III promises unforgettable panels, killer networking opportunities, and mountains […]

recent research

AERODROME TEMPLATE.png

Research

Aerodrome is a "MetaDEX" that combines elements of various DEX primitives such as Uniswap V2 and V3, Curve, Convex, and Votium. Since its launch on Base, it has become the largest protocol by TVL with more than $495M in value locked, doubling Uniswap's Base deployment.

article-image

Plus, a look into US spot BTC funds six months into trading

article-image

A Swedish energy-focused project named Srcful proposed to become a Helium subnetwork with its own ENERGY token

article-image

Securitize CEO Carlos Domingo thinks BUIDL will potentially hit its next $500 million milestone in just a few months

article-image

Representatives on Thursday opted to back President Biden and uphold his veto of the legislation that sought to invalidate SAB 121

article-image

The former Valkyrie CEO chats with Blockworks about what she has her eye on as Cypherpunk Holdings’ new leader

article-image

Thursday’s CPI report shows prices are coming down more quickly than analysts had anticipated, renewing hope that central bankers will cut rates in the fall