Chain Of Exploits? Investigator Unveils Connection Between Multiple Crypto Hacks

Over the past few years, crypto attacks have grown in complexity and frequency. In the year 2024 alone, the community has witnessed a staggering loss of hundreds of millions of dollars due to exploits and scams, leaving investors dismayed with nothing to show for their investments.

In some cases, individuals who successfully exploit a project’s vulnerabilities may give back the stolen funds and share their findings to enhance security for future prevention. But usually, hackers keep the ill-gotten gains and disappear after carrying out an attack.

Investigator ZachXBT recently revealed a possible connection between a series of hacks, with the individual behind the Prisma Finance heist that stole $12 million last month being identified as a white hat hacker under suspicion.

Stained Whitehat Hacker

On March 28, the Ethereum Decentralized Lending Protocol, Prisma Finance, experienced a hack resulting in the theft of 3,479.24 ETH. Noticing and suspecting unusual behavior, Prisma’s team swiftly notified the community.

In the past, a hacker reached out to Prisma via an on-chain message, identifying themselves as a “ethical hacker” or “Whitehat.” During their interaction, this individual expressed their intention to “improve safety measures for users” and emphasized the significance of thorough contract audits and Decentralized Finance (DeFi) usage.

The next day, the lending protocol published a thorough explanation of the recent incident. This account apparently irritated the hacker, who asked the team to replace accusative words such as “exploit” and “hacker” with more neutral terms.

The messages sounded warnings about the possibility of the funds being refunded. Unhappy with the Prisma team’s willingness to revise their post-mortem report, the hacker demanded a reward of $3.8 million, which represented 34% of the total funds.

A look into the claims that Trung, identified as 0x77 on PrismaFi, allegedly orchestrated the $11.1M exploit, along with other reported exploits they’re linked to.

— ZachXBT (@zachxbt) April 16, 2024

The requested sum was three times higher than the usual industry benchmark of 10%. In the crypto world’s vernacular, the perpetrator was “effectively shaking down the team” since the treasury lacked sufficient resources to compensate the affected parties.

Although the Whitehat asserted otherwise and seemed uneasy about it, the hacker’s actions spoke differently as they transferred funds to Tornado Cash. Subsequent probe by the crypto sleuth uncovered a history of questionable activities for this Whitehat.

Prisma’s Exploiter Connected To Several Crypto Hacks

During an in-depth examination of related transactions by ZachXBT, it was uncovered that there were associated activities on the Tron network. One particular address, TGviNZ, was found to be involved in multiple exploits.

According to the probe, TGviNZ received financing from the Arcade_xyz hack starting in March 2023. At that time, the hacker demanded extra funds from the initiative through Telegram.

In a similar fashion, the address was linked to the Pine Protocol breach reported in February 2024. On this occasion, the hacker demanded half of the funds and reportedly made further unjustified demands via email.

Chain Of Exploits? Investigator Unveils Connection Between Multiple Crypto Hacks

After examining the clues, the cryptocurrency detective found out that TGviNZ is connected to the creator of Modulus protocol, a “decentralized, non-custodial system.” Through further exploration, it was uncovered that user X, with the identifier “0x77,” was one of the few supporters of this platform.

Examining the evidence closely, we discovered that “0x77” was a significant alias used by the Arcade exploiter on Telegram. Further investigation of the associated phone numbers, email addresses, and other details revealed the same individual as the likely perpetrator of these exploits.

The suspected exploiter’s specifics have been obtained by Prisma for examination, as they decide whether to initiate lawsuits against this person in Vietnam and Australia.

Chain Of Exploits? Investigator Unveils Connection Between Multiple Crypto Hacks

Read More

2024-04-18 05:11