Skip to content

Latest commit

 

History

History
83 lines (43 loc) · 3.68 KB

File metadata and controls

83 lines (43 loc) · 3.68 KB

Coinberry

Date:: August 24th, 2020

Amount Stolen: $200,000


Details

"On August 24th, 2020, "there were no withdrawals processed from Coinberry's hot wallet for about 17 hours." It "[h]asn't been publicly reported yet. 8.33 BTC stolen from Coinberry's hot wallet & sent to 1KcTk7kJMjYaCV3FXo5bzpjaZs2aK18ntz. I guess they can't say they've never been hacked anymore."

"So another Canadian exchange appears to have been hacked a couple months ago. Hasn't been publicly reported yet. 8.33 BTC stolen from Coinberry's hot wallet & sent to 1KcTk7kJMjYaCV3FXo5bzpjaZs2aK18ntz. I guess they can't say they've never been hacked anymore #coinberry #quadriga"

CipherBlade, Oct 29, 2020

On-Chain

  • 0xA06957c9C8871ff248326A1DA552213AB26A11AE - Primary Theft

  • 1KcTk7kJMjYaCV3FXo5bzpjaZs2aK18ntz - Primary Theft

BTC

  • bc1qffjuzkld2jp2hf5apg9trz3ucpqt4rzj5rvvwv

  • 37iW4CUhBXwUkoxNDgG6Ta4LdQmibb4KqS

  • 38AhhMN9Sg9hnKT4gps8hrJPMyfgMY3nZ5

  • 1GcHyFLYSMvr4XSySYdZUWB2LLGvu4QjVr

  • 1DTjz8QWughcPekZaFdTdrrNxp9TEkZFWN - Attributed Lazarus Group

  • 15K6ZmcnkqEXJpVpfqnk18fYGxRbDXAZr4 - Receives from multiple known DPRK victims

  • Laundry @ 0xbc8d089824461048a06d300dff88bb7357d88b3b (Connects Coinberry, Coinmetro, Fetch.ai, Unibright, LEAD, Nexus Mutual, EasyFi)

0x94cf84daa641b499cf518ad49f8463fd39f4e579

- 0xa06957c9c8871ff248326a1da552213ab26a11ae receives 143 ETH (~$60k) from Coinberry on Aug 24, 2020

- 0xa06957c9c8871ff248326a1da552213ab26a11ae sends ~$60k to 0x94cf84daa641b499cf518ad49f8463fd39f4e579 on Aug 24, 2020

- 0x94cf84daa641b499cf518ad49f8463fd39f4e579 sends ~$60k to 0xbfc560a48619e2ff496adcd76f5974a5d4236f6b on Aug 24, 2020

- 0xbfc560a48619e2ff496adcd76f5974a5d4236f6b sends ~$60k to 0x94cf84daa641b499cf518ad49f8463fd39f4e579 on Aug 31, 2020

- 0x94cf84daa641b499cf518ad49f8463fd39f4e579 sends ~$663k to 0x99739fa525c0a98384430235d278fd08938997f9 on Aug 31, 2020

38AhhMN9Sg9hnKT4gps8hrJPMyfgMY3nZ5

- 0xe1cfc33ed7efc7e432a2214276fff6b71f09d493 via Ren Bridge

    - txn: e6fc336da02fa2de878bc90f466407bee6fc186df66e636b1adb0da4f1f81cde

    - txn: 0xa23f39446a7d7378755a06f460b5cd456feef4ca8e1c319e4b46a333277f2e97

- 0xe1c receives 0x990924d51c6ea6e212cce6e811b380ffd44ac350 (Coinmetro + L2 Theft)

- 0xe1c also sends to September 2023 Dust Collector 0x99739fa525c0a98384430235d278fd08938997f9

- 0xe1c also sends $5.8m to 0x7026b25422821473f7856ec03b0a3d58fee10100 which sends to 0x31499e03303dd75851a1738e88972cd998337403 (direct and via a back-and-forth Ren Bridge) which interacts with EasyFi exploiter 0x83a2eb63b6cc296529468afa85dbde4a469d8b37

URLs