en
Back to the list

Treasury Dept. Sanctions More North Korea-Linked ETH Wallets Over $600M Ronin Hack

source-logo  coindesk.com  + 3 more 22 April 2022 19:51, UTC

U.S. government officials are throwing a wider sanctions dragnet over alleged North Korean crypto wallets.

On Friday, the Treasury Department's Office of Foreign Asset Control (OFAC) added three Ethereum addresses to its sanctions list, joining an address listed last week that the federal government tied to the theft of around $600 million in crypto from Axie Infinity's Ronin bridge. All three addresses had received sizable inbound transfers of stolen ether (ETH) from the originally sanctioned wallet over the past week.

The operators of the Ronin exploit wallet, said by the FBI and OFAC to be North Korea's Lazarus hacking group, have been laundering funds by moving them from a sanctioned address to an intermediary address before sending the funds to Tornado Cash, a mixer designed to obfuscate the source and destination of funds moved through the service.

This pattern repeated on Friday, when funds moved from one of the newly sanctioned addresses to another intermediary before once again landing at Tornado Cash.

None of the sanctioned addresses have directly interacted with Tornado Cash.

The nature of Tornado Cash makes it difficult for the operators of the service to blacklist addresses, as OFAC requires any entities touching the U.S. financial system to do. The mixer adopted a compliance tool offered by blockchain analytics firm Chainalysis that lets it blacklist certain addresses, but only on the user-facing decentralized app that Tornado Cash's operators can influence. Individuals can still use the protocol itself to bypass this compliance tool.

Also, at least as of last week, the Chainalysis tool only listed the originally sanctioned address.

A representative for Tornado Cash previously told CoinDesk that "OFAC is the judge of what addresses need to be banned."

"It’s a guessing game so far. I assume only 1 address has been identified by OFAC that should be sanctioned relating to that event. Which means Chainalysis update[s] whatever is in sanction’s list," the representative said.

Officials have accused the Hermit Kingdom of mounting an aggressive hacking spree against the crypto economy.

This is a developing story and will be updated.

coindesk.com

Similar news (3)
Add similar news