North Korean Hackers Return to Tornado Cash Despite Sanctions
2024-03-14 • Elliptic •
https://www.elliptic.co/blog/north-korean-hackers-return-to-tornado-cash-despite-sanctions
Elliptic reports that more than $12 million in ETH from the November 2023 HTX and HECO Bridge theft moved through Tornado Cash on March 13 and 14, 2024, across more than 40 transactions. Elliptic and others attribute the $100 million theft to Lazarus Group based on the hack characteristics and subsequent fund movement. Lazarus had shifted to Sinbad.io after U.S. sanctions against Tornado Cash, but Sinbad was seized in November 2023. The renewed Tornado Cash use shows Lazarus continuing large scale laundering through decentralized mixer infrastructure despite sanctions and mixer takedowns.