{"id":20609,"date":"2025-01-24T12:34:13","date_gmt":"2025-01-24T10:34:13","guid":{"rendered":"https:\/\/forklog.com\/en\/phemex-exchange-hack-losses-exceed-70-million-north-korean-hackers-suspected\/"},"modified":"2025-01-24T12:34:13","modified_gmt":"2025-01-24T10:34:13","slug":"phemex-exchange-hack-losses-exceed-70-million-north-korean-hackers-suspected","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/phemex-exchange-hack-losses-exceed-70-million-north-korean-hackers-suspected\/","title":{"rendered":"Phemex Exchange Hack Losses Exceed $70 Million; North Korean Hackers Suspected"},"content":{"rendered":"<p>North Korean hackers are suspected to be behind the breach of the Singapore-based cryptocurrency exchange Phemex, according to several experts cited by <a href=\"https:\/\/www.theblock.co\/post\/336754\/north-korea-hack-group-possibly-behind-70-million-phemex-exploit-experts-say\">The Block.<\/a><\/p>\n<p>MetaMask&#8217;s chief security researcher, Taylor Monahan, noted that the attack involved the simultaneous withdrawal of &#8220;a huge amount of various assets&#8221; from multiple networks.<\/p>\n<p>Initially, the perpetrators stole funds in Bitcoin, Ethereum, Solana, and stablecoins, then shifted to less popular coins. Millions of stolen USDC and USDT were rapidly exchanged for ETH to avoid freezing.<\/p>\n<p>According to Etherscan, at least 275 transactions are linked to EVM networks, including Arbitrum, Base, Polygon, Optimism, and zkSync.<\/p>\n<p>Analysts from Arkham <a href=\"https:\/\/intel.arkm.com\/explorer\/entity\/phemex\">reported<\/a> that the hackers almost completely drained the exchange&#8217;s hot wallets, leaving only small amounts in lesser-known altcoins.<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cAll this activity occurred simultaneously, but not via scripts. Assets were manually exchanged and then transferred to a fresh address,\u201d Monahan added.<\/p>\n<\/blockquote>\n<p>Considering the number of transactions and the wide range of targeted blockchains, she believes the hack was carried out by &#8220;a group of perpetrators who have done this many times before.&#8221;<\/p>\n<p>An anonymous crypto threat researcher, SomaXBT.eth, suggested the involvement of North Korean-linked hackers based on the attack vector. Another expert was reminded of the <a href=\"https:\/\/forklog.com\/en\/news\/cybersecurity-highlights-phishing-scams-north-korean-hackers-and-whatsapp-concerns-in-russia\">TraderTraitor<\/a> group, responsible for the $308 million hack of the Japanese exchange DMM Bitcoin.<\/p>\n<p>The main wallet of the Phemex hackers processed at least $44 million. Various blockchain researchers report that at least $16 million in SOL, $12 million in XRP, and $5 million in Bitcoin were stolen. The total damage has now exceeded $70 million.<\/p>\n<p>Phemex still holds about $1.8 billion in crypto assets. The majority of this amount\u2014$1.1 billion\u2014is in the native token PT. The next largest balances are $355 million in Bitcoin and $209 million in USDT.<\/p>\n<p>The platform&#8217;s CEO, Federico Variola, announced plans to resume USDT and USDC withdrawals in the coming hours.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Hello all, we estimate to resume USDT and USDC withdrawals in approximately 6 hours from now, securing the hot wallets architecture remains the main priority, thank you for the understanding.<br \/>Other services like MemeX will also reprise around that time, and as usual PoR is\u2026<\/p>\n<p>\u2014 Federico0x @Phemex (@Federico0x) <a href=\"https:\/\/twitter.com\/Federico0x\/status\/1882700089807765668?ref_src=twsrc%5Etfw\">January 24, 2025<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>On January 23, Phemex suspended withdrawals after receiving alerts about suspicious activity from several blockchain security firms.<\/p>\n<p>The exchange continues its investigation and is &#8220;working on a compensation plan&#8221; for those affected.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>North Korean hackers are suspected to be behind the breach of the Singapore-based cryptocurrency exchange Phemex, according to several experts cited by The Block. MetaMask&#8217;s chief security researcher, Taylor Monahan, noted that the attack involved the simultaneous withdrawal of &#8220;a huge amount of various assets&#8221; from multiple networks. Initially, the perpetrators stole funds in Bitcoin, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":20608,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"","news_style_id":"","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1166,44,1202],"class_list":["post-20609","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-centralized-exchanges-cex","tag-cybercrime","tag-north-korea-dprk"],"aioseo_notices":[],"amp_enabled":true,"views":"22","promo_type":"","layout_type":"","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/20609","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=20609"}],"version-history":[{"count":0,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/20609\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/20608"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=20609"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=20609"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=20609"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}