News linked to both this project and an event.
Odaily reports, according to Lookonchain monitoring, the Bitget hacker (0xf7bC...96C3) swapped ETH for BTC via THORChain, having stolen $351.6 million.
Odaily News: According to on-chain analyst Yu Jin, over 90% of the funds swapped cross-chain through THORChain are illicit or grey-market funds. Yu Jin stated that most of the funds stolen from Bybit last year were transferred through THORChain, which collected nearly $10 million in fees within 10 days. Recently, some of the funds stolen from Bitget have also been transferred through THORChain, generating $1 million in fee revenue.
Slow Mist's Cosine posted on X platform, stating that the Bitget hack incident has spread widely, involves a huge amount of funds, and the related funds were quickly linked to North Korean hackers. Institutions such as Circle and Tether promptly assisted in freezing the related funds, with Circle freezing the USDC held by the hackers.Regarding THORChain, Cosine pointed out that when THORChain itself previously suffered a hack, it also quickly intervened in its so-called "decentralized" platform; but this time, when facing a major industry security incident, it responded on the grounds of being "decentralized and having no right to interfere," likened itself to Bitcoin and Ethereum, and continued to earn fees from the hackers' large cross-chain transactions.He stated that decentralization should not just be a slogan. After major security incidents occur, the key is to distinguish which issues need to be solved jointly by the industry. He also believes that platforms such as THORChain should not be easily mentioned in the same breath as Bitcoin and Ethereum, as there are clear differences in the degree of decentralization and mechanisms among different systems.
MistTrack (@MistTrack_io) disclosed that, following the transfer of nearly $1.2 billion in stolen funds from last year's $1.46 billion Bybit hack via THORChain, Bitget has recently suffered another major security breach, with stolen funds suspected of again flowing through THORChain. In response, the official THORChain team stated that its protocol is a decentralized, permissionless network, just like Bitcoin, Ethereum, and BNB Chain.
Odaily News: Today, THORChain officially posted on X platform stating, "We have noticed the recent Bitget hack and are deeply saddened by it. We can imagine this is a difficult time for everyone in the industry. (However,) THORChain is as decentralized and permissionless as Bitcoin, Ethereum, and BNB Chain. When dealing with known stolen funds, what responsibility should Bitcoin, Ethereum, and BNB Chain bear?" Subsequently, it called out OKX CEO Star and Bitget CEO Gracy.However, crypto community members in the comments pointed out that when THORChain previously suffered an attack, it once suspended services for 39 days, and they are deeply ashamed of the differentiated treatment between the two situations.
Odaily News: OKX Star posted on X in response to THORChain, stating that he does not believe THORChain's TSS + validator model represents true decentralization. THORChain's validators collectively control the underlying assets in the TSS vault, and funds can be moved once the signature threshold is reached. Therefore, from a custody perspective, it cannot be compared to the underlying consensus mechanisms of Bitcoin and Ethereum, but instead acts as an intermediary between users and native chains. "TSS distributes control among multiple participants, but decentralizing an intermediary does not eliminate the intermediary itself."Previously, discussions arose after some stolen Bitget funds were transferred through THORChain. THORChain responded that it is decentralized and permissionless, just like Bitcoin, Ethereum, and BNB Chain, and stated that if stolen funds were known to flow through Bitcoin, Ethereum, or BNB Chain, what responsibility should those networks bear?
According to AMLBot monitoring, some of the stolen funds from the Bitget hack have reportedly begun being mixed through Wasabi CoinJoin. The related funds originally came from a TRON wallet on Bitget. The attacker swapped TRX for USDT, then bridged via USDT0 to Ethereum and exchanged it for approximately 145 ETH, which was subsequently swapped through THORChain into approximately 4.59 BTC. These BTC were then split and pre-processed before entering CoinJoin.
OKX founder Star posted on X platform regarding the Bitget hack incident, stating that THORChain is a "very unique" part of the crypto industry. After Bitget was attacked, both the OKX exchange and OKX Wallet immediately took action and stood ready to assist in identifying and tracing the flow of stolen funds, and to block the transfer of stolen funds where possible. Star stated that resilience is an important quality that every crypto company should possess; when security incidents occur, the industry needs to respond quickly, share information, and cooperate to protect users and prevent similar attacks from happening again. He emphasized: "Security is not a competition, but a shared responsibility."
Odaily News: According to monitoring by the Bitget CEO, the attacker's addresses have been publicly listed and are being continuously tracked. Bitget has formally demanded that THORChain refuse to provide services to these addresses. Decentralization is a design principle and should not serve as a protective shield that facilitates the handling of known stolen funds.
according to Bitcoin News monitoring, the Coldcard thief is prioritizing emptying the largest portion of the third wave of vaults. Galaxy Research stated that these wallets have transferred out 97.09 BTC, worth approximately $7.7 million, accounting for about 45% of the assets in this batch. The attacker created 293 2/2 vaults themselves and previously moved some tokens via THORChain on September 2, followed by multiple rounds of CoinJoin over the weekend. The vulnerability stems from a 2021 firmware flaw that reduced seed entropy to a minimum of 40 bits. Of the tokens stolen in this exploit, approximately 82% remain unmoved.
According to Galaxy Research, in the Coldcard wallet attack incident, the Wave 3 attacker has transferred approximately 45% of the stolen Bitcoin, with the related funds routed to Ethereum via THORChain or entering CoinJoin transactions to increase tracking difficulty. Galaxy stated that the attacker previously created 293 2-of-2 multisig vaults to hold victim funds, draining them from largest to smallest amount, and the funds in the 11 largest vaults have now been fully transferred out.
Odaily News: The attacker behind the Coldcard "Wave 3" exploit continues to move stolen funds. In this phase, the attacker created 293 separate 2-of-2 multisig vaults for each victim's assets. On September 2, the first batch of funds was bridged to Ethereum via THORChain; the latest round of transfers has begun entering the CoinJoin mixing process.Currently, the Wave 3 attacker is processing the largest holdings in descending order by stolen amount, having already transferred vaults ranked 1 through 11 in sequence. The next 10 vaults yet to be transferred collectively hold 30.81 BTC, while vaults ranked 61 through 293 collectively hold 33.77 BTC.To date, the attacker has moved approximately 45% of the assets stolen in this exploit, with funds either flowing to Ethereum or entering CoinJoin mixing transactions. This latest transfer activity has also revealed a previously unknown vault: 58 addresses jointly spent funds via a 2-of-2 multisig setup in the same format as Wave 3, with the Wave 3 attacker subsequently routing them to a jump address that funds CoinJoin transactions.This vault is currently marked with "cause = open," but it is highly likely to belong to Coldcard victims as well, which could bring the total number of vaults involved in Wave 3 to 294 and push the previously disclosed total stolen in the Coldcard exploit to approximately 1,806 BTC. At present, roughly 82% of the stolen BTC remains in addresses initially controlled by the attacker, while approximately 18% has been moved, with fund flows suggesting it may be undergoing laundering.
Odaily News – According to Bitcoin News monitoring, hackers linked to the third wave of Coldcard wallet thefts have begun moving stolen funds for the first time, converting Bitcoin into ETH via THORChain. Galaxy Research's Alex Thorn stated that approximately 10% of the stolen BTC has been moved, while the remaining 90% remains untouched. The attacker reportedly encountered difficulties during the fund conversion, with multiple THORChain transactions being returned and retried. Researchers have traced the related swap activity to a new Ethereum address, which Alex Thorn noted has been shared with relevant authorities and cryptocurrency companies. Galaxy Research indicated that the broader Coldcard exploit has resulted in losses of at least 1,789 BTC across 8,865 addresses, valued at approximately $115 million based on prices at the time of the theft.
Odaily News: According to monitoring by Galaxy's Head of Research, the COLDCARD Wave 3 attacker has moved stolen funds for the first time, exchanging them for ETH via the THORChain cross-chain DEX. This marks the first on-chain transfer of funds from the original hacker address across Waves 1, 2, or 3.
CertiK 表示,其监测系统发现两笔各 200 ETH 的交易转入 Tornado Cash,相关资金与正在进行的 Coldcard Wallet 攻击事件有关。上述资金此前通过 THORChain 由 BTC 跨链转入以太坊地址,随后再被转入 Tornado Cash。
Odaily News, January 10 - A Bitcoin and Litecoin holder provided a 12-word recovery phrase to attackers impersonating Trezor support personnel, resulting in the theft of approximately $282 million in assets, including about $139 million in Bitcoin and $153 million in Litecoin. Blockchain forensics firm ZeroShadow stated that the incident stemmed from a social engineering attack, not a compromise of wallet software or private key infrastructure. The stolen funds were split via the THORChain cross-chain bridge within minutes and converted into Monero through instant exchange services. ZeroShadow's monitoring team flagged and froze approximately $700,000 in funds within 20 minutes. Under the BIP39 standard, a 12-word recovery phrase contains approximately 128 bits of entropy, while a 24-word phrase contains 256 bits of entropy. Chainalysis estimates that up to 23% of all mined Bitcoin is permanently inaccessible due to lost keys, involving millions of BTC, with causes including forgotten recovery phrases, damaged backups, and a lack of inheritance planning.
Odaily News: According to monitoring by Galaxy's Head of Research, a victim's Coldcard wallet was compromised in a hacker attack involving nearly 30 BTC, of which 17 BTC were swapped for ETH via THORChain and subsequently deposited into Duel.comcasino. The victim and a researcher have sent emails to all known addresses associated with Duel.comcasino, requesting that the relevant funds be frozen, and provided all transaction and deposit information. The hacker deposited 229.72497255 ETH, valued at $445,000, into Duel.comcasino—funds originating from the Coldcard attack involving approximately 30 BTC. The victim stated that Duel.comcasino responded by saying that the police would need to contact their team. Duel.comcasino's anti-money laundering policy claims it enforces Know Your Customer (KYC) procedures and complies with all applicable laws. Duel.comcasino was notified within minutes of the deposit being completed. To date, Duel.comcasino has not frozen the relevant funds. Since most of the Western world had already passed midnight at the time of the incident, police reports cannot be filed until at least Monday. If Duel.comcasino fails to freeze the funds, the victim will pursue legal action against them. Duel.comcasino's X account has been suspended, and Galaxy's Head of Research has also flagged individuals on X suspected of being associated with the platform, including team members and dealers: @korraflow, @atrois7, @MiaMalkova.
decentralized privacy protocol hinkal has released an update on a security incident, confirming that an attacker extracted approximately 797,000 USDC from its Ethereum contract through a series of transactions and exchanged it for about 454 ETH. Of this, roughly 410 ETH was subsequently transferred to Tornado Cash, while the remaining approximately 44.67 ETH was bridged to the Bitcoin network via THORChain. hinkal is currently collaborating with an external security team to trace the flow of funds.hinkal stated that the impact of this security incident is limited to the relevant fund pools on the Ethereum chain, and contracts on other chains remain unaffected. However, all contracts have been temporarily suspended for fixes and security verification. All affected users will be fully compensated at a 1:1 ratio, with specific compensation procedures and timelines to be announced in a subsequent update.
Odaily, the decentralized cross-chain liquidity protocol THORChain has resumed trading after being down for over five weeks following a May attack. Signing, swapping, liquidity provider operations, and redemptions have all been restored.On May 15, blockchain investigator ZachXBT and security firm PeckShield identified that the protocol had likely been exploited, prompting THORChain to halt trading. The vulnerability resulted in a loss of approximately $10.7 million from one of its six Asgard vaults, while the other five vaults were unaffected.THORChain stated that each vault has now been verified, and every key share has been cross-checked. Native Monero swaps are currently undergoing end-to-end testing and will be launched subsequently. (The Block)
on-chain security researcher Specter posted on X, stating that THORChain has not resumed normal operations for over a month after suspending all transactions due to a security vulnerability incident. The protocol previously did not choose to suspend transactions during other security incidents or suspicious fund flows; it even continued operating simple ETH-BTC paths. However, after becoming the affected party this time, it completely halted cross-chain transactions, sparking community discussion about the consistency of its risk management. Currently, THORChain on-chain trading remains completely stagnant, with almost no transactions on the entire chain. The recovery timeline remains unclear, and Specter reminds community users to "stay alert."