{"id":20051,"date":"2024-12-31T11:35:34","date_gmt":"2024-12-31T09:35:34","guid":{"rendered":"https:\/\/forklog.com\/en\/blockchain-bandit-resurfaces-after-two-year-hiatus\/"},"modified":"2024-12-31T11:35:34","modified_gmt":"2024-12-31T09:35:34","slug":"blockchain-bandit-resurfaces-after-two-year-hiatus","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/blockchain-bandit-resurfaces-after-two-year-hiatus\/","title":{"rendered":"&#8216;Blockchain Bandit&#8217; Resurfaces After Two-Year Hiatus"},"content":{"rendered":"<p>The perpetrator behind one of the largest ETH heists in history has moved the stolen funds for the first time in two years, according to on-chain detective <a href=\"https:\/\/t.me\/investigations\/194\">ZachXBT<\/a>.<\/p>\n<figure class=\"wp-block-image is-resized\"><img decoding=\"async\" src=\"https:\/\/lh7-qw.googleusercontent.com\/docsz\/AD_4nXdiyuugDmdYYcPx0tcsUdVlsBWlKHyLzHr5taWCPSLOx_ENNq_db1dfXxaMIlDRLwLRjaHtT2QPlz53SGACBIDdMRGNjHBOErBi3KqctmoJQr5FU701TPDmpgL9g9IWDoAWZKXy?key=hjmr_PhuniRlmJMxIvto2Tq0\" alt=\"'Blockchain Bandit' Resurfaces After Two-Year Hiatus\" style=\"width:607px;height:auto\"\/><figcaption class=\"wp-element-caption\">Funds distribution scheme of the &#8216;Blockchain Bandit&#8217;. Data: ZachXBT.<\/figcaption><\/figure>\n<p>According to the analyst, the hacker transferred 51,000 ETH ($170.9 million) in batches of 5,000 coins from 10 wallets to a single multisig address. The entire procedure took 24 minutes.<\/p>\n<p>The &#8216;Blockchain Bandit&#8217; earned his moniker between 2016 and 2018 through a series of attacks targeting wallets with &#8216;weak private keys&#8217;.<\/p>\n<p>Flaws in the pseudorandom number generation mechanism and other issues in the early version of the Ethereum protocol allowed him to systematically &#8216;guess&#8217; secret combinations.<\/p>\n<p>The hacker automated this process and breached 732 addresses, extracting approximately 45,000 ETH through 49,060 transactions.<\/p>\n<p>According to Adrian Bednarek, senior security analyst at Independent Security Evaluators, the perpetrator <a href=\"https:\/\/www.ise.io\/casestudies\/ethercombing\/\">may be linked<\/a> to North Korean hacking groups, although no evidence has been found yet.<\/p>\n<p>The &#8216;Blockchain Bandit&#8217;s&#8217; funds had remained dormant since January 21, 2023.<\/p>\n<p>Earlier, the threat of attacks from North Korean hackers triggered a net outflow of $249 million from the Hyperliquid protocol.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The perpetrator behind one of the largest ETH heists in history has moved the stolen funds for the first time in two years, according to on-chain detective ZachXBT. Funds distribution scheme of the &#8216;Blockchain Bandit&#8217;. Data: ZachXBT. According to the analyst, the hacker transferred 51,000 ETH ($170.9 million) in batches of 5,000 coins from 10 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":20050,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"","news_style_id":"","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1142,1111,46],"class_list":["post-20051","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-cryptography","tag-cybersecurity","tag-ethereum"],"aioseo_notices":[],"amp_enabled":true,"views":"21","promo_type":"","layout_type":"","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/20051","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=20051"}],"version-history":[{"count":0,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/20051\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/20050"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=20051"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=20051"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=20051"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}