The hacker behind the $321 million Wormhole bridge assault has shifted a big chunk of stolen funds, with transaction knowledge exhibiting that $155 million value of Ether (ETH) was transferred to a decentralized alternate (DEX) on Jan 23.
The Wormhole hack was the third largest crypto hack in 2022, after the protocol’s token bridge suffered an exploit on Feb. 2 that resulted within the lack of 120,000 Wrapped ETH (wETH), value round value $321 million.
In keeping with the transaction history of the hacker’s alleged pockets tackle, the most recent exercise exhibits that 95,630 ETH was despatched to the OpenOcean DEX after which subsequently transformed into ETH-pegged property resembling Lido Finance’s staked ETH (stETH) and wrapped staked ETH (wstETH).
We’re seeing tackle 0x629e… Wormhole Community Exploiter swap 95,630 Ether (~$155M) to stETH
Keep protected! pic.twitter.com/ZR6zxlRuKX
— CertiK Alert (@CertiKAlert) January 23, 2023
Digging into the transaction historical past additional, crypto group members resembling Spreekaway additionally highlighted that the hacker went on to conduct a slew of odd-looking transactions.
For instance, the hacker used their stETH holdings as collateral to borrow 13 million value of the DAI stablecoin, earlier than swapping it out for extra stETH, wrapping it into stETH once more after which borrowing some extra DAI.
Wormhole exploiter has transformed his ETH to wstETH and goes to borrow DAI towards it it appears. pic.twitter.com/9rhERSMG5u
— Spreek (@spreekaway) January 23, 2023
Notably, the Wormhole group has taken the chance to as soon as once more supply the hacker a bounty of $10 million in the event that they return all of the funds, leaving an embedded message conveying such in a transaction.
The hacker’s hefty ETH transaction seems to have had a direct influence on the worth of stETH in response to data from Dune Analytics. The asset’s worth went from just below peg of 0.9962 ETH on Jan. 23, to as excessive as 1.0002 ETH the next day, earlier than dropping again to 0.9981 on the time of writing.
Associated: North Korea’s Lazarus Group masterminded $100M Concord hack: FBI confirms
With the Wormhole hack more likely to catch extra consideration in mild of the most recent incident, blockchain safety companies resembling Ancilia Inc. warned on Jan. 19 that looking out key phrases “Wormhole Bridge” in Google is at present exhibiting promoted advert web sites which can be really phishing operations.
The group has been warned to be diligent on what they’re clicking on regarding this time period.
#phishing alert Whenever you search “wormhole bridge” in Google, lots of the “advert” entries are literally phishing website. E.g.
hxxps://portaltoken-wormholebridge.com. Watch out about what you click on and keep protected! pic.twitter.com/C6JW2xeaUh
— Ancilia, Inc. (@AnciliaInc) January 19, 2023