visit
AXIE INFINITY-RONIN BRIDGE HACK
Axie Infinity is a decentralized blockchain game built on the Ethereum network. The game was built by a team called Sky Mavis and it rewards its players with cryptocurrencies and NFTs.Ronin bridge is an Ethereum sidechain built for Axie Infinity, it enables users to transfer assets between the sidechain and the Ethereum mainnet.
On March 23, 2022, a hacker had carted away with Ethereum and USDC which amounted to a whopping sum of $620M from Axie Infinity's Ronin Bridge, making it the biggest crypto heist of all time to date. The attack was later discovered on the 29th of March after which the attacker had already moved a bulk of the stolen assets to tornado cash for ease of passage for laundering.The hacker stole and tokens from the bridge exploit; with the bear market rocking the crypto space today, those coins are now worth $297M.On April 14, 2022, the FBI released a report the attack to two North Korean hacking groups, The Lazarus group and BlueNorOff (aka APT38). A month after that, The Block also released a from an exclusive interview they had with two staff of Sky Mavis. According to one of the staff, "the attack started as a fake job offer in which a senior engineer at Sky Mavis showed interest. During one of the interviews between the Engineer and the hacker, the Engineer received a PDF file containing the job details, which he downloaded and then opened on the company's computer system". This simple approach paved the way for the hacker to penetrate the Ronin system.Good news
HARMONY HACK
On June 23, 2022, A hacker took over Harmony's Layer-1 Blockchain Bridge and stole Cryptos worth $100M.The hacker stole Wrapped Ethereum (WETH), AAVE, SUSHI, DAI, USDT and USDC, and then swapped them all for ETH.Three days after the hack, the Harmony team for the stolen funds (a bounty many considered to be an insult to the hacker). The hacker refused the offer and on the following day, Peckshield that the hacker had started moving the funds to Tornado Cash in batches.TRANSIT SWAP
Transit Swap is a Cross-Bridge Decentralise Finance (Defi) Platform.On October 1, 2022, the Transit Swap Finance team announced that a hacker had attacked Transit swap and that the team had also halted services immediately to curb further damages. The following day the team came out with a detailed report on the attack一 that the hacker took advantage of a bug in the code. The vulnerability of in code allowed the attacker to drain over $21 Million from the wallets of users who had approved the protocol swap contracts.The team also noted that they had gotten some information leading to the IP address of the hacker and also highlighted that the discovery of the information of the hacker was due to the joint efforts of the, the, the security team, the team, and the team.TEMPLE DAO EXPLOIT:
On October 11, 2022, a Twitter user was the the TempleDAO exploit, and 23 minutes later, Blockchain Security Firm, Peckshield, also quoted the tweet—stating that the DAO was exploited. , the user had already moved the stolen funds of 1,831 $ETH which amounted to $2.34 Million, to a new wallet. The stolen funds amounted to 4% of the total assets of TempleDAO.
Later that day, STAX, a DEX powered by TempleDAO on Twitter recounting what had happened to the Defi company. They also warned users not to deposit in any of its contracts until further notice and promised the affected users remediation in due time.On October 16, 2022, Peckshield made of the hack on Twitter; apparently, the hacker ignored the white hat hack that was put out by the devs of TempleDAO, and instead they started moving the stolen assets to Tornado Cash in a bid to white-wash them.BITKEEP HACK
On October 18, 2022, The official account of BitKeep on Twitter, stating that the BitKeep Swap feature was hacked and that the attack which saw a loss of $1 million, occurred on the BNB Chain.PeckShield, being the first to , stated that the $1 Million BNB Coins were later moved through Tornado Cash.The hacker carried out a simultaneous attack on the Polygon and Binance Smart Chain Networks. All the stolen ERC-20 tokens were converted to Stablecoins and bridged to BSC Network. The hacker then purchased BNB with the bridged Stablecoins and deposited all the BNBs in Tornado Cash.Good news
BitKeep gave assurances to the affected users on a full compensation plan, and on the 21st of October, the was rolled out—stating step-by-step instructions on what users needed to do for them to get refunded.In conclusion
On August 8th, Tornado Cash was by the U.S. Treasury’s Office of Foreign Assets Control (OFAC) for its role in laundering over $455 million worth of cryptocurrency stolen by the North Korean hacking organization Lazarus Group.It is estimated that so far in 2022, North Korea-linked groups have stolen approximately $1 billion of cryptocurrency from Defi protocols.Although Tornado cash has been sanctioned, its compliance is rather complicated and that is due to its non-custodial nature, its encoded smart contract design, and its decentralized development team—all these coupled together are the forces still driving Tornado Cash even after its sanctions.