Home > Top > Body

Bybit Funds on the Move, Could be Headed for Bitcoin Mixers ‘Next’: Elliptic

clock
2025-02-24 01:33:31

North Korean hackers have started laundering stolen Bybit funds, with blockchain intelligence firm Elliptic tracking over $140 million in initial transactions designed to obscure the money trail.

The stolen funds are being systematically moved through anonymous exchanges before being converted to Bitcoin, a process that makes it harder to trace and recover the assets, the firm wrote in a blog post on Saturday.

“The second step of the laundering process is to ‘layer’ the stolen funds in order to attempt to conceal the transaction trail,” Elliptic wrote. “This transaction trail can be followed, but these layering tactics can complicate the tracing process, buying the launderers valuable time to cash out the assets.”

The $1.46 billion social engineering attack, which took place on Friday and consisted mostly of Ethereum, is the most significant theft in crypto history, surpassing the $611 million stolen from Poly Network in 2021. 

Elliptic and Arkham Intelligence have linked the attack to North Korea’s Lazarus Group, citing the use of decentralized exchanges and other services, including cross-chain bridges and coin swap services in a bid to throw off the scent.

“If previous laundering patterns are followed, we might expect to see the use of mixers next to further obfuscate the transaction trail,” it said. However, that may prove challenging due to the “sheer volume of stolen assets.”

Within hours of the theft, attackers distributed the stolen assets across 50 different wallets, each holding approximately 10,000 ETH. The funds are now being systematically emptied and converted to Bitcoin, according to Elliptic.

The attackers first converted stolen tokens like stETH and cmETH to Ethereum using decentralized exchanges, likely to avoid potential asset freezes. 

This matches Lazarus Group's typical laundering playbook of converting stolen tokens to "native" blockchain assets before further obfuscation, Elliptic wrote.

To date, the group has stolen over $3 billion in crypto assets since 2017, reportedly funding North Korea's ballistic missile program with the proceeds, according to a UN report last year, though that figure is suspected to be much higher, Elliptic noted.

As a result of the theft on Sunday, Bybit is now facing pressure from user withdrawals who have since pulled roughly 23,000 BTC from Bybit's hot wallet, data from Arkham Intelligence shows.

The exchange’s main wallets show its Bitcoin balance has dropped from 70,000 BTC to just over 52,000 BTC, indicating an outflow of roughly $1.7 billion since Friday afternoon.

Further analysis suggests Bybit has seen outflows totaling $6 billion across various crypto.

Elliptic and others, including ZachXBT, have also pointed to anonymous crypto exchange eXch as having processed "tens of millions of dollars" in stolen assets from the hack despite direct requests from Bybit to block the activity.

“The stolen Ethereum is steadily being converted to Bitcoin, using eXch and other services,” Elliptic wrote Sunday.

A purported emailed response from eXch, archived on X on Saturday and cited by Elliptic, alleges the crypto exchange chose not to acknowledge requests from Bybit, claiming the latter has made "direct attacks on the reputation" against the former in the past.

"It is difficult for us to understand the expectation of collaboration" from an organization that has "actively undermined our reputation," the email from eXch reads.

The exchange did not immediately respond to Decrypt’s request for comment.

In a post to a Bitcoin forum on Sunday, eXch claimed allegations it was facilitating money laundering were untrue.

“We are not laundering money for Lazarus/DPRK,” eXch wrote, claiming that such an allegation was the “perspective of some people that wish decentralized coins' fungibility and on-chain privacy to vanish.”

It added: “The insignificant part of funds that was processed by us from the Bybit hack in an isolated case will be donated to various open-source initiatives dedicated to privacy and security both inside and outside crypto space.”

Edited by Sebastian Sinclair

Web3 Desktop Trading Tool
Stay ahead of the game in the cryptocurrency space.

7x24 Newsflash

02:30 2025-06-19
中国互联网金融协会发布虚拟货币安全提示:警惕“空气币”局、传销局、平台局
中国人民银行下属的中国互联网金融协会官方发布提醒,警惕虚拟货币的传销局(新币发行只涨不跌、发展会员福利超多、购币获得会员资格、上下线发展层级)、“空气币”局(去中心化区块链创新项目、XX币上线后价格暴涨、新项目上线认购即送XX币、某大佬推荐XX币)、平台局(注册交易即免费赠送虚拟货币、平台交易海量、提现快捷),这些项目常...
02:21 2025-06-19
Bithumb将上线HUMA和FORT韩元交易对
据官方公告,Bithumb将上线HUMA和FORT韩元交易对。
02:15 2025-06-19
美国司法部将堪萨斯银行倒闭案与2.25亿美元的“杀猪盘”扣押案关联起来
根据周三提交的一份诉状,一名堪萨斯州银行家在2023年从他所在的这个小镇银行窃取了数百万美元,导致银行倒闭。他窃取的资金大部分都输给了海外加密货币诈骗犯,这些诈骗犯是美国司法部一次破纪录的打击行动的目标。 检察官已提起民事没收诉讼,目标是超过2.25亿美元的被洗钱的USDT。这笔资金是一个“杀猪盘”诈骗案的一部分,该诈骗案与菲律宾的一个呼...
02:06 2025-06-19
Pantera Capital关联钱包从Nonco收到价值450万美元HYPE
据Onchain Lens监测,Pantera Capital关联钱包已从Nonco收到117,032枚HYPE,价值约450万美元。
01:51 2025-06-19
Nobitex:被盗资产总额约为1亿美元,用户损失由储备基金全额保障
伊朗加密交易平台Nobitex 发布被盗事件第四次公告:在Nobitex针对近期安全事件的持续应对过程中,目前局势已得到控制,所有对我们服...
01:42 2025-06-19
Melania项目方三个月内出售7613万枚MELANIA代币,价值超3500万美元
据分析师余烬监测,Melania项目方在过去三个月内从社区和流动性地址累计转出7613.2万枚MELANIA代币。通过添加单边流动性和DCA形式出售,换取了24.4万枚SOL,价值约3521.8万美元,平均售价约0.46美元。项目方随后将SOL陆续卖出换成USDC或转入中心化交易所。在此期间,MELANIA价格从0.7美元下跌至0.25美元。
01:42 2025-06-19
美国现货比特币ETF昨日净流入3.887亿美元
据TraderT监测,美国现货比特币ETF昨日净流入3.887亿美元。
01:33 2025-06-19
Pyth 宣布支持英国 FTSE 100 指数实时价格数据
去中心化预言机解决方案 Pyth Network 宣布支持英国 FTSE 100 指数实时价格数据,该指数涵盖伦敦证券交易所市值排名前 100 的公司,任何人都可以轻松访问这些公司的链上价格数据,包括全球银行和保险公司、能源巨头和工业企业、家喻户晓的零售商和制造商等。 这些数...
01:33 2025-06-19
路透社:Circle收盘涨33.8%,若特朗普签署Genius法案稳定币市场将获新增长
据路透社披露,或因罕见美国两党支持推动稳定币法案在参议院通过,美股加密板块大幅上涨,其中Circle收盘上涨33.8%,Coinbase 收盘上涨16%,提供加密货币交易服务的免佣金券商Robinhood上涨4.5%。伯恩斯坦分析师指出,一旦Genius法案通过成为法律(可能在夏季末),预计稳定币将从加密货币的货币轨道演变为互联网的货币轨道。...
01:27 2025-06-19
TRUMP团队关联钱包3小时前向Coinbase转入约170万美元TRUMP
据Onchain Lens监测,TRUMP团队关联钱包于3小时前向Coinbase存入了182,068枚TRUMP,价值约170万美元。在过去的36小时内,该钱包已向Coinbase、OKX和Bitstamp共计转入254,720枚TRUMP,价值约240万美元。
01:24 2025-06-19
昨日FBTC净流入1.044亿美元
据Farside Investors监测数据,昨日FBTC净流入1.044亿美元。
01:17 2025-06-19
Solana政策研究所联合行业参与者向SEC提交合规代币化证券框架
Solana政策研究所(SPI)与Phantom、Orca和Superstate等行业领导者于2025年6月18日向SEC加密工作组提交了"合规代币化证券"框架提案。该框架建议将股票、债券等传统资产上链,并为非托管区块链协议提供监管豁免。SPI称其Project Open计划有望实现资本市场现代化,使传统资产能够全天候交易、即时结算,同时降低成本并提高透明度。该框架强调去中心化协议与传统...