Over the weekend, the Singapore-based cryptocurrency exchange KuCoin reported a hack… Unknown attackers devastated the resource's hot wallets containing Bitcoin, ERC-20 tokens, and so on. KuCoin's total losses are estimated at approximately $ 150,000,000.
The hack was discovered on September 26, 2020, when exchange employees noticed large withdrawal transactions from hot wallets. The audit revealed a cyber attack and a lack of funds. The company said in a statement that the incident did not affect the cold wallets, and they promise to cover all the damage from the exchange's insurance fund.
KuCoin CEO Johnny Lyu reportedthat the company had already turned to law enforcement agencies for help, and also stated that the attack was most likely the work of one of the exchange's employees or partners, since the attacker somehow got hold of the private keys from hot wallets.
KuCoin representatives published a list of wallets to which the stolen funds were transferred (the list continues to be updated). Tether, Bitfinex and several other large cryptocurrency exchanges have already blacklisted the attackers' wallet addresses and froze part of the funds on the EOS blockchain and on one of the Ethereum addresses.
Experts Under The Breach note that hackers use the Uniswap decentralized exchange to convert stolen altcoins to Ethereum.
Kucoins hacker begins laundering his $ 150,000,000.
He started swapping his $ OCEAN for ETH via Uniswap.
He already dragged the price down by around 4% in less than an hour and doesn't seem to be slowing down.
Due to low liquidity for this token, he is going to crash it hard. pic.twitter.com/gKcsgpUe3a
– Alon Gal (Under the Breach) (@UnderTheBreach) September 27, 2020
In turn, the Whale Alert experts write that the hackers brought almost $ 530,000 in LINK tokens to an unknown address and exchange them for Ethereum through the Kyber Network decentralized exchange.
⚠ 50,000 #LINK (529.962 USD) of stolen funds transferred from Kucoin Hack 2020 to unknown wallet
– Whale Alert (@whale_alert) September 28, 2020