The Kelp DAO hacker has basically completed money laundering; about $220 million in unfrozen funds is almost entirely out of the tracking scope.

Mars Finance News reported that on June 2, of the approximately $292 million in assets stolen during the April Kelp DAO cross-chain bridge attack, aside from about $71 million worth of ETH that has been frozen, the remaining approximately $220 million has essentially been fully laundered, and the attacker’s original address now holds only about $1.7 million in assets. On-chain analysis shows that the attacker completed multiple rounds of cross-chain transfers and mixing operations using privacy tools such as THORChain, Wasabi, Tornado Cash, and Umbra, causing most of the funds to become largely untraceable.

Investigative agencies previously attributed this attack to the North Korean hacker group Lazarus Group (TraderTraitor/UNC4899). One day after the attack, the hacker split approximately 75,700 ETH (then worth about $175 million) into multiple new addresses, cross-chained to the Bitcoin network via THORChain, and then used tools such as Wasabi CoinJoin and Tornado Cash to mix the funds. During this period, related fund flows at one point drove THORChain’s daily trading volume to $394 million, more than ten times the normal level.

At present, the only assets that still have a relatively high likelihood of being recovered are approximately 30,766 ETH (about $71 million) frozen by the Arbitrum Security Council. However, this portion of the assets has been pulled into a new legal dispute: the U.S. federal court for the Southern District of New York had previously issued a restraining order requiring a temporary freeze of the related funds, because some families of victims of North Korean terrorism are seeking, through legal proceedings, to apply for the forfeiture of this batch of assets in order to enforce compensation judgments.

ETH-0.57%
BTC-4.71%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 7
  • Repost
  • Share
Comment
Add a comment
Add a comment
MerkleGarden
· 4h ago
The dilemma of privacy policies: for ordinary people, it’s freedom; for hackers, it’s accomplices
View OriginalReply0
LonelyStoneUnderTheAurora
· 4h ago
1.7 million untouched, is it kept for paying gas or forgotten?
View OriginalReply0
StargazerInTheWoods
· 4h ago
Cross-chain bridges have failed again and again; how much more do users have to pay in tuition fees?
View OriginalReply0
ChecksumSmile
· 4h ago
What kind of package could North Korean hackers expect in the Web3 job market based on their operational skills?
View OriginalReply0
TreatMemesAsBeliefs
· 4h ago
THORChain + Tornado + Wasabi, a hacker's toolkit is more diverse than my wallet.
View OriginalReply0
StakingDaydream
· 4h ago
220 million washed, 71 million frozen, this ratio shows that on-chain freezing isn't completely useless either.
View OriginalReply0
MarketMakingForMoonlitDeepPool
· 4h ago
Lazarus’s efficiency leaves traditional finance silent, and makes DeFi weep
View OriginalReply0
  • Pinned