arrow_backBack to Radio
News

Chainalysis: THORChain attacker demonstrates sophisticated money laundering capabilities, moving funds cross-chain for weeks before attack

en
Chainalysis posted on X platform disclosing the tracking of the THORChain attack source. They stated that the suspected attacker's wallets had been transferring funds through Monero, Hyperliquid, and THORChain for several weeks before carrying out the THORChain attack. The attacker's associated wallets had deposited funds into Hyperliquid positions via Hyperliquid and Monero privacy bridges as early as late April. The funds were then exchanged for USDC and transferred to Arbitrum, then bridged to Ethereum. Some ETH was subsequently transferred to THORChain to stake RUNE for a newly joined node, which is believed to be the attack source. Afterward, the attacker bridged some RUNE back to Ethereum and split it into four channels. One channel led directly to the attacker. After transferring through an intermediate wallet, 8 ETH was transferred to the wallet that ultimately received the stolen funds 43 minutes before the attack. Funds in the other three channels flowed in reverse. From May 14th to 15th, these wallets bridged ETH back to Arbitrum again, deposited it into Hyperliquid, and transferred it into Monero through the same privacy bridge. The last transaction occurred less than 5 hours before the attack began. As of Friday afternoon, the stolen funds have not been moved, but the attacker has demonstrated their sophisticated cross-chain money laundering capabilities. The Hyperliquid to Monero path may be the next move.
Share