Slow Fog: CoinEx hacker may be linked to North Korean hacker group Lazarus Group, which has been associated with other attack incidents

2023-09-13 18:40:08
Collection

ChainCatcher message, SlowMist found during the analysis of the CoinEx attack incident that the CoinEx hacker may be associated with the North Korean hacker group Lazarus Group, with specific connections as follows:

  1. The known Alphapo Exploiter (TDrs…WVjr) exchanged TRX for ETH through TransitSwap and cross-chained to the address (0x22be3b0a943b1bc0ea3aec2cb3ef511f3920a98d), thus this address is also marked as Alphapo Exploiter on Ethereum;

  2. The hacker address 0x22be3b0a943b1bc0ea3aec2cb3ef511f3920a98d is marked as Alphapo Exploiter on Ethereum and as Stake.com Exploiter on BNB Chain, indicating that this address is a shared address;

  3. 0x75497999432B8701330fB68058bd21918C02Ac59 is marked as CoinEx Exploiter on Arbitrum and OP Mainnet, and as Stake.com Exploiter on Polygon, indicating that this address is a shared address.

Since the Stake.com Exploiter has been linked by the FBI to the North Korean hacker group Lazarus Group, it is possible that the Alphapo Exploiter, Stake.com Exploiter, and CoinEx Exploiter are all part of the North Korean hacker group Lazarus Group.

ChainCatcher reminds readers to view blockchain rationally, enhance risk awareness, and be cautious of various virtual token issuances and speculations. All content on this site is solely market information or related party opinions, and does not constitute any form of investment advice. If you find sensitive information in the content, please click "Report", and we will handle it promptly.
banner
ChainCatcher Building the Web3 world with innovators