$1.5 billion ETH stolen, the industry faces severe security challenges.

robot
Abstract generation in progress

Major Hacker Incidents Reveal Security Challenges Facing the Crypto Assets Industry

On February 21, 2025, a shocking security incident occurred at a well-known Crypto Assets trading platform, resulting in the theft of approximately $1.5 billion in assets from its Ethereum cold wallet. This incident is considered the largest single theft in the history of Crypto Assets, far exceeding other major security events that occurred previously, and has caused a tremendous impact on the entire industry.

This article will provide a detailed account of the hacker incident and the methods of fund laundering, while reminding readers that over the next few months, over-the-counter trading groups and crypto payment companies may face a large-scale risk of fund freezing.

Details of the Theft Incident

According to the description from the executives of the trading platform and the preliminary investigation by the blockchain analysis company, the process of this theft incident is as follows:

  1. Attack Preparation: The hacker deployed a malicious smart contract at least three days prior to the incident, laying the groundwork for the subsequent attack.

  2. Invasion of Multi-Signature System: The Ethereum cold wallet of the victim platform employs a multi-signature mechanism. The Hacker infiltrated the computer managing the multi-signature wallet through unknown means, possibly using a disguised interface or malware.

  3. Cloaked Transactions: Hackers take advantage of the timing of normal fund transfers on the platform, disguising the transaction interface as a routine operation, and inducing signers to confirm a seemingly legitimate instruction that actually alters the logic of the cold wallet smart contract.

  4. Fund Transfer: After the instruction took effect, the Hacker swiftly took control of the cold wallet, transferring approximately $1.5 billion worth of ETH and ETH staking certificates to an unknown address. Subsequently, the funds were dispersed to multiple wallets and began the money laundering process.

Bybit hacked 1.5 billion USD triggered "butterfly effect": OTC groups will face a freezing wave

Money Laundering Techniques

The money laundering process of a Hacker mainly consists of two stages:

The first phase is the early capital split. The attacker quickly exchanged the ETH staking certificate for ETH, rather than opting for stablecoins that could potentially be frozen. The ETH is then strictly split and transferred to subordinate addresses in preparation for laundering.

It is worth noting that at this stage, the attacker's attempt to exchange 15,000 mETH for ETH was promptly halted, preventing greater losses for the industry.

The second phase is the specific money laundering work. The attacker uses centralized and decentralized industry infrastructure for fund transfers, including various cross-chain protocols and decentralized exchanges. Some protocols are used for currency exchange, while others are used for cross-chain transfers.

As of now, a large amount of stolen funds has been converted into mainstream Crypto Assets such as BTC, DOGE, and SOL for transfer, and some of the funds have even been used to issue meme coins or transferred to exchange addresses for obfuscation.

Blockchain analysis companies are monitoring and tracking relevant addresses, and related threat information will be synchronized and pushed on their professional platform to prevent users from mistakenly receiving stolen funds.

The "butterfly effect" caused by the theft of 1.5 billion USD from Bybit: The OTC community will face a wave of freezes

Hacker Organization Background Analysis

By analyzing the flow of funds, researchers found a connection between this incident and two exchange hacking events that occurred in October 2024 and January 2025, indicating that these three attacks may have been orchestrated by the same entity.

Considering its highly industrialized money laundering techniques and attack methods, some blockchain security experts attribute this incident to a notorious Hacker organization. This organization has launched cyber attacks on institutions and infrastructure in the crypto assets industry multiple times over the past few years, illegally obtaining crypto assets worth billions of dollars.

Potential Freezing Risk

Security researchers have found in investigations over the past few years that, in addition to using decentralized platforms for money laundering, the hacker organization has also heavily utilized centralized platforms for cashing out funds. This has directly led to many exchange users' accounts, which inadvertently received illicit funds, being flagged for risk control, and the business addresses of over-the-counter traders and payment institutions being frozen.

For example, in 2024, a Japanese crypto assets exchange was attacked, and $600 million worth of Bitcoin was stolen. Some of the funds were transferred to crypto payment institutions in Southeast Asia, resulting in the freezing of the institution's hot wallet address, with nearly $30 million in funds locked.

In 2023, another trading platform was attacked by a suspected hacker organization, and over $100 million in funds was stolen. Some of the stolen funds were laundered through over-the-counter trading, resulting in the freezing of business addresses of a large number of over-the-counter traders, or their exchange accounts being subject to risk control, severely impacting normal business activities.

Conclusion

Frequent hacker attacks not only cause huge losses to the industry, but the subsequent money laundering activities also pollute the addresses of more innocent individuals and institutions. For these potential victims, it is crucial to closely monitor these threat funds in their daily operations to prevent their own interests from being affected. The crypto assets industry needs to further strengthen security measures, raise awareness, and jointly address the increasingly complex challenges of cybersecurity.

ETH-3.25%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 7
  • Repost
  • Share
Comment
0/400
FortuneTeller42vip
· 6h ago
Eating cabbage again.
View OriginalReply0
AltcoinAnalystvip
· 08-17 05:29
TVL tests the community's immunity with a second bottom.
View OriginalReply0
BearMarketLightningvip
· 08-17 05:23
Seeing through without mentioning it, here comes another Rug Pull.
View OriginalReply0
LightningAllInHerovip
· 08-17 05:13
What a gamble, really!
View OriginalReply0
OldLeekNewSicklevip
· 08-17 05:13
Laughing to death, the suckers have finally been played for suckers.
View OriginalReply0
TokenUnlockervip
· 08-17 05:09
I thought DEX was safe.
View OriginalReply0
ColdWalletGuardianvip
· 08-17 05:06
Yo, the biggest incident of the year has arrived.
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)