GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

ZachXBT Goes Undercover in Lazarus Group-Linked Money Laundering Ring: Invested Nearly $3.5 Million in OTC Trades with Counterparty Using the Alias Jimmy Green

Odaily News: On-chain detective ZachXBT posted on X that he once posed as a client to infiltrate a criminal group suspected of laundering money for the North Korea-backed hacker organization Lazarus Group, and assisted in freezing funds related to the 2025 Bybit attack.ZachXBT stated that after Bybit suffered a $1.5 billion attack in February 2025, he discovered that more than 15 accounts in public Telegram and Discord groups were seeking help processing transactions related to the stolen funds. He subsequently contacted one of the Telegram users using the alias "Jimmy Green" and built trust through multiple transactions. According to his disclosure, on March 6, 2025, he transferred $3.497 million in USDC to an Ethereum address for a USDC-to-TRON-chain USDT exchange transaction with the counterparty. The source of gas funds for that address can be traced back to the Bybit attack funds and was publicly flagged as a Bybit attack blacklisted address.ZachXBT said that in subsequent communications, the counterparty revealed that their team had been involved in processing the stolen Bybit funds and disclosed in advance that the funds would be moved across chains including Solana. By matching transaction timing, amounts, and on-chain data, he identified a wallet cluster involving more than $12 million in Bybit attack funds, with fund paths spanning multiple networks including BTC→ETH→SOL→TRON. Approximately 442,000 USDT was frozen by Tether, and the group also attempted to launder money through Uniswap liquidity pools and low-liquidity tokens. Additionally, the counterparty disclosed having helped other clients process approximately $3 million in fraudulent proceeds, and ZachXBT traced the related funds to wallets associated with the sanctioned Huione Guarantee.ZachXBT revealed that in this investigation, he initially invested $3.497 million and bore a loss risk of approximately 5% per transaction. The intelligence ultimately obtained was provided to relevant investigative agencies and law enforcement authorities at the earliest opportunity. Since 2022, he has assisted in freezing over $75 million in funds related to North Korea-linked incidents.

Safe early investor Greenfield has filed a complaint with Swiss regulators, alleging that a foundation director used tokens to threaten and exert pressure.

Greenfield Capital has filed a complaint with the Swiss federal foundation regulator ESA regarding governance issues at the Safe Ecosystem Foundation, alleging that Safe Foundation directors instructed personnel to hand over a substantial amount of SAFE tokens following the Bybit hack, and threatened to force Gnosis to sell its holdings—which account for approximately 10% of the total SAFE supply—and sever ties with Safe.

About $295 million in user assets stolen, Drift Foundation says 107,200 ETH still not moved

Odaily News — According to monitoring by the Drift Foundation, the Drift Foundation has released an update on fund recovery progress related to the April 1 security incident: approximately $295 million in user assets were stolen. The foundation has engaged Mandiant, zeroShadow, and SEAL 911 to conduct the investigation and trace the funds, with Mandiant identifying the attacker as the North Korean threat group UNC6862.The stolen funds were subsequently bridged to Ethereum, with approximately 130,300 ETH distributed across 4 wallets. Three of these wallets have seen no transfers to date, collectively holding 107,200 ETH; the other wallet transferred approximately 23,100 ETH to Tornado Cash on July 23.Currently, approximately $9.2 million in stolen funds has been frozen. The relevant funds had previously been transferred through Tornado Cash in August, and unfreezing and return still require cooperation with legal procedures. The Drift Foundation will transfer all assets recovered through freezing, bounties, or law enforcement channels into the DFX recovery pool, and is evaluating the subsequent path of the DRIFT token within the broader ecosystem. In addition, the foundation has partnered with Bybit to launch a public bounty program, offering a 10% bounty on successfully recovered funds.

$388 Million in Crypto Assets Stolen, Bitget CEO Says Full Recovery Unlikely

Odaily News — Gracy Chen, CEO of cryptocurrency exchange Bitget, said the company is not optimistic about recovering the $388 million in crypto assets lost in last week's security incident. Citing the Bybit hack in 2025 as a reference, she noted that approximately one year after that incident, only about 3.5% of the stolen funds had been frozen, and that this does not equate to a completed recovery.Bitget has set up a bounty program offering 5% rewards for frozen funds and recovered funds respectively. The NEAR Intents team said it has intercepted over $50 million in assets related to the attack and frozen approximately $500,000. Tether and Circle have blacklisted the relevant wallets, freezing $318,000 worth of USDT and USDC.Gracy Chen stated that preliminary investigations indicate the attack may match VPN addresses used by North Korea-linked groups, but Bitget has not yet fully ruled out the possibility of an insider job. Bitget has resumed withdrawals in phases, starting with Bitcoin transactions on Monday and continuing with ETH transactions on Tuesday. (Cointelegraph)

THORChain Earns Nearly $10 Million in Fees in 10 Days, Accused of Funneling Most of Bybit's Stolen Funds

Odaily News: According to on-chain analyst Yu Jin, over 90% of the funds swapped cross-chain through THORChain are illicit or grey-market funds. Yu Jin stated that most of the funds stolen from Bybit last year were transferred through THORChain, which collected nearly $10 million in fees within 10 days. Recently, some of the funds stolen from Bitget have also been transferred through THORChain, generating $1 million in fee revenue.

THORChain addresses questions regarding the Bitget security incident, emphasizing the permissionless nature of decentralized protocols.

MistTrack (@MistTrack_io) disclosed that, following the transfer of nearly $1.2 billion in stolen funds from last year's $1.46 billion Bybit hack via THORChain, Bitget has recently suffered another major security breach, with stolen funds suspected of again flowing through THORChain. In response, the official THORChain team stated that its protocol is a decentralized, permissionless network, just like Bitcoin, Ethereum, and BNB Chain.

Xie Jiaxin: The method of theft in this security incident differs from last year's Bybit incident, so different withdrawal recovery arrangements are being adopted

Odaily reports: Xie Jiaxin posted on X stating that this Bitget security incident involved multiple non-EVM chains and 10 tokens, and due to the different method of asset theft, different approaches to handling and restoring withdrawals were taken compared to last year's Bybit security incident in order to thoroughly eliminate potential risks.Additionally, Xie Jiaxin stated that he and Bitget CEO Gracy Chen will host a community livestream 30 minutes before withdrawals resume on Monday to discuss this security incident and answer community questions.Bitget announced on X that it will restore withdrawals in phases: Bitcoin network withdrawals will resume on September 28 at 8:00 (UTC); ETH withdrawals on Ethereum, BSC, Arbitrum, Base, and Optimism networks will resume on September 29 at 8:00 (UTC); USDT withdrawals on Ethereum, BSC, Solana, and Tron networks will resume on September 30 at 8:00 (UTC); other tokens, fiat, and P2P withdrawals will resume on October 2 at 8:00 (UTC). Trading and deposit services continue to operate normally, and users do not need to take any action in advance.

Bitget CEO: Stolen Funds Revised to $387.5 Million, Withdrawal Plan to Be Announced on September 26

Bitget CEO Gray Chen posted on X platform that following the security incident, on-chain tracking confirmed the attacker's address received a total of $387.5 million in assets, revised upward from the previously disclosed $351.6 million.Gray Chen stated that the revised amount incorporates Zcash and TRON assets that were not fully accounted for previously, and does not represent newly stolen funds. No unauthorized transfers have occurred since the incident, and the situation remains under control. Bitget has launched a Recovery Bounty Program, offering a 5% bounty to each party that voluntarily assists in freezing the attacker's funds or recovering the funds. The exchange has also launched a real-time tracking dashboard, an information submission portal, and an attacker address API, while supporting reports submitted through Bybit's Lazarus Bounty platform. Bitget is currently making full preparations to resume withdrawals, with a specific withdrawal plan to be announced before 4:00 AM (UTC) on September 26.

Bybit CEO: The team stands ready to assist Bitget and will help track the relevant funds.

Bybit co-founder and CEO Ben Zhou announced in a post that the Bybit team stands ready to assist in any capacity with the recent hacking incident targeting Bitget. Previously, when Bybit was compromised, Bitget provided support. Ben Zhou stated that Bybit is currently updating the LazarusBounty platform to help Bitget track the flow of the associated funds.

Bybit CEO: Will Assist Bitget in Tracking and Recovering Stolen Funds

Odaily News: Bybit co-founder and CEO Ben Zhou posted that the Bybit team stands ready to assist Bitget in any way possible, noting that Bitget had previously offered assistance when Bybit suffered a hack attack.Ben Zhou stated that Bybit is updating the LazarusBounty platform to help Bitget track the flow of stolen funds and assist in recovering the related assets.

Bybit Releases H1 2026 Security Report: Intercepts Over $700M in Potential Losses, Achieves 100% On-Chain Monitoring

Odaily News  Bybit today released its H1 2026 Risk and Security Report. Following the security incident in February 2025, Bybit has comprehensively upgraded its security architecture, transitioning toward a new defense model characterized by earlier detection, faster response, and continuous adaptation. Key highlights from the report are as follows:User Fund Protection: In H1, over 30,000 suspicious withdrawals were intercepted, protecting nearly 20,000 users from potential losses exceeding $700 million. The average initial review time was just 4.7 minutes (with 95% completed within 10 minutes).100% On-Chain Monitoring: Monitoring covers all business-related on-chain activities (including listed tokens, ecosystem contracts, and hot/cold wallets). In H1, 10 security incidents involving listed token projects were handled with zero platform losses; of these, responses to 8 incidents were faster than other major exchanges, and 2 attacks were detected before the project teams themselves. Additionally, approximately $212 million in potentially fraudulent on-chain funds was identified, and over 10,000 malicious addresses were blacklisted.AI-Driven Security Operations: More than 100,000 security alerts were processed. AI-assisted audits identified critical vulnerabilities at an efficiency 3-5 times that of manual efforts; the automated red team platform reduced the time from asset discovery to initial testing to within 24 hours (compared to weeks with traditional manual methods), and the cycle from security assessment to testing was shortened from two weeks to two hours.Accountability and Asset Recovery: In collaboration with law enforcement agencies and blockchain intelligence firms, stolen assets are being traced, and legal action has been taken against North Korea and the Lazarus Group to hold them accountable and recover funds.David Zong, Head of Risk Control and Security at Bybit Group, stated: "The cybersecurity arms race has entered the era of 'minute-level' response. Leveraging AI to strengthen risk control capabilities and ensuring the security of AI systems themselves is our top priority, but critical security decisions remain centered on human judgment."

North Korea has stolen at least $2.8 billion in cryptocurrency between January 2024 and September 2025, laundering it through existing criminal networks

Odaily News: The North Korean regime stole at least $2.8 billion in crypto assets between January 2024 and September 2025, increasingly laundering them through established criminal networks. According to a report by the Royal United Services Institute (RUSI), a UK-based defense and security think tank, the funds are believed to support its weapons programs. Stolen tokens frequently change ownership before being converted into cash, with third parties sometimes purchasing them at a discount or mixing them with proceeds from investment scams such as "pig butchering" schemes. Cashing out primarily relies on "money mules" recruited in the Philippines, Indonesia, and China, where stablecoins are typically split up and sold through peer-to-peer markets. After the Bybit hack, ZeroShadow found that TraderTraitor moved funds through over-the-counter (OTC) desks, peer-to-peer traders, and Chinese organized crime syndicates. Bybit has recovered $48.4 million and frozen $30.5 million in assets, accounting for roughly 5% of the stolen amount in total. (Decrypt)

Bybit officially sues North Korea and hacker group Lazarus Group, successfully obtains preliminary injunction to freeze stolen assets

Odaily News, Bybit announced today that it has officially filed a civil lawsuit in the U.S. District Court for the District of Columbia against North Korea (DPRK), its Reconnaissance General Bureau (RGB), and the Lazarus Group, holding the organization legally accountable for the大规模 cyberattack launched against Bybit in February 2025.It is reported that Bybit has successfully obtained a preliminary injunction from the court, freezing identified stolen digital assets held or transferred by unidentified individuals and entities (i.e., "John Doe" defendants). In approving the preliminary temporary restraining order, the court described the incident as "one of the largest cryptocurrency thefts in history" and determined that Bybit has a "likelihood of success on the merits" of the case. This civil lawsuit is independent of criminal investigations by U.S. law enforcement and aims to provide an additional legal avenue for asset recovery.In terms of asset recovery and global collaboration, Bybit has achieved notable results in partnership with blockchain analytics firms, multiple exchanges, custodial institutions, and international law enforcement agencies. To date:Approximately $48.4 million in stolen assets have been successfully recovered;Approximately $30.5 million in involved assets have been successfully frozen (distributed across more than 28 exchanges and custodial institutions).These efforts have also supported broader law enforcement actions targeting key infrastructure allegedly used to launder stolen funds: German authorities have dismantled cryptocurrency exchange eXch; German and Swiss authorities subsequently jointly shut down mixing platform Cryptomixer.io, cutting off critical channels for transferring illicit proceeds. These actions collectively demonstrate the effectiveness of collaboration between the private sector and law enforcement agencies in combating transnational cybercrime.Ben Zhou, co-founder and CEO of Bybit, stated: "Our core goal has never changed: prioritizing user protection, making every effort to recover assets, and ensuring those behind this are held accountable under the law. The Lazarus attack was not only directed at Bybit, but also a challenge to the trust foundation of the entire crypto industry. We will continue to deepen cooperation with law enforcement agencies, regulatory authorities, and courts to make the crypto world a place where criminals find it difficult to hide."Bybit emphasized that it will continue to invest in advanced blockchain tracking technology, utilize all available legal means to combat state-sponsored hacker groups, and drive the establishment of a more resilient digital asset ecosystem. The civil lawsuit is currently ongoing.

Bybit sues North Korea and Lazarus Group over $1.5 billion hack, obtains asset freeze order

Odaily News: Cryptocurrency exchange Bybit has filed a civil lawsuit against the Democratic People's Republic of Korea, its intelligence agency Reconnaissance General Bureau (RGB), and the state-sanctioned hacker group Lazarus Group over a $1.5 billion hacking incident. A U.S. federal court has issued a preliminary injunction prohibiting the transfer or dissipation of identified assets related to the case during the litigation.

Cryptocurrency Hacks Set Record in First Half of 2026, Losses Exceed $1 Billion

In the first half of 2026, losses from hacker attacks on cryptocurrency projects have exceeded $1 billion, with the number of verified attack incidents reaching a record high for the same period in history, described as "the half-year with the most hacker attacks on record." However, in terms of value, overall losses remain lower than the same period last year, mainly because a $1.5 billion attack incident occurred at Bybit in 2025, raising the baseline.

Drift hacker transferred 23,000 ETH into Tornado Cash, worth approximately $44.4 million

According to on-chain analyst PeckShield (@PeckShieldAlert), the address labeled "Drift Exploiter" has deposited 23,095.1 ETH (approximately $44.4 million) into Tornado Cash for mixing, and additionally transferred 0.85 ETH to Bybit.

Midnight Foundation: Wanchain Cardano<>BNB Bridge Attacked, Multiple Exchanges Jointly Freeze Related Assets

According to an official post from Midnight Foundation (@midnightfdn), the Wanchain Cardano<>BNB cross-chain bridge suffered a security attack. Currently, multiple major exchanges including KuCoin, Kraken, Binance, Bybit, OKX, and MEXC have responded rapidly, taking preventive measures to restrict the flow of stolen assets, including freezing relevant accounts and addresses, blacklisting the attacker's wallets, and suspending NIGHT token deposit and withdrawal services. The exchanges confirmed that this incident is an isolated third-party bridge vulnerability and is unrelated to the Midnight Network mainnet and the NIGHT asset itself.

Midnight:Multiple Exchanges Including Binance Freeze Funds Involved in Cross-Chain Bridge Attack

the Midnight Foundation has provided an update on the handling of the cross-chain bridge attack event involving Wanchain Cardano and BNB. Multiple exchanges including KuCoin, Kraken, Binance, Bybit, OKX, Gate, and MEXC have coordinated risk control actions, temporarily freezing the involved accounts and associated addresses, adding the hacker wallet to a blacklist, and pausing NIGHT token deposits and withdrawals as needed to curb the transfer and cashing out of stolen assets.The Foundation specifically noted that this security incident is an isolated incident related to a third-party cross-chain bridge, and the Midnight mainnet and native NIGHT assets have not been affected. The project team continues to collaborate with major exchanges and ecosystem partners to advance traceability investigations, reminding the community to rely on official disclosures for information and to be cautious of misinformation.

Ostium OLP Vault Attacked, Approximately $24 Million USDC Stolen and Transferred to Tornado Cash

According to monitoring by on-chain analyst PeckShield (@PeckShieldAlert), the public OLP vault of decentralized perpetual contract protocol Ostium (@Ostium) was attacked, with approximately 24 million USDC stolen. The attacker subsequently swapped the stolen funds for 12,080 ETH and has transferred 10,540 ETH into the mixer Tornado Cash to obscure the fund flow. On-chain tracing shows that the attacker's initial funds originated from ChangeNow and Bybit, with 1 ETH transferred from each to the attacker's wallet (0x321D...8bfD9).

Dragonfly Partner: DeFi "Hacker Doomsday" Warning Failed to Materialize, AI Hardening Significantly Improves Security of Major Protocols

Dragonfly 管理合伙人 Haseeb Qureshi(@hosseeb)在 X 平台发文,距 OpenZeppelin 创始人 Manuel Aráoz 发出"DeFi 全面不安全"警告已过去两个月,数据显示所谓"黑客末日"并未成真。 数据显示,2026年 DeFi 被盗金额年化值低于 2025 年全年,即便剔除异常月份(如 Bybit 黑客事件、Drift 及 KelpDAO 事件)后对比,2026 年每月被盗金额仍低于 2025 年;按 TVL 标准化后,2026年 DeFi 资金被盗比例同样略低于 2025 年。 Haseeb 指出,当前呈现出"攻击次数上升、单次规模下降"的结构性特征——攻击者主要针对无力承担 AI 安全加固成本的小型协议和废弃项目,而已完成 AI 代码加固的大型协议安全性实际上有所提升。他总结称,"DeFi 中平均每一美元的安全性与一年前持平,将资金存放于大型协议大概率是安全的。"