One of the wallets linked to Uranium Finance’s $50 million exploit in April 2021 appears to have woken up after 647 days of dormancy, with funds flowing towards crypto mixer Tornado Cash.
The sudden move was highlighted on March 7 by cybersecurity firms PeckShield and CertiK on their respective Twitter alert accounts.
According to data from Etherscan, the hacker moved the 2,250 ether (ETH) worth $3.35 million over a seven-hour period in transactions ranging from 1 ETH to 100 ETH — with all funds going to Tornado Cash.
However, this is just one of the wallets associated with the hacker. Another Ethereum wallet linked to the hacker shows it was last active 159 days ago, with 5 ETH sent to privacy-focused Ethereum zk-rollup on Aztec.
This is another occasion in 2023 when a hacker’s wallet has awakened from dormancy after a long hiatus. In January, the Wormhole hacker moved around $155 million worth of ETH for almost a year after exploiting the Wormhole bridge for $321 million in early 2022.
In the same month, a notorious hacker dubbed a “blockchain bandit” also moved around $90 million after a six-year slumber.
In February, the wormhole hacker moved another $46 million worth of stolen funds, while popular blockchain snoop dog ZachXBT highlighted via Twitter on Feb. 23 that “dormant funds remained” from the $230 million gate .io exchange hack by “North Korea” in April 2018 after over 4.5 years to move.”
Binance Smart Chain based automated market maker Uranium Finance was exploited on April 28, 2021. The hack itself was reportedly the result of a coding vulnerability that allowed the hacker to siphon off $50 million during the launch of Uranium’s v2.1 protocol and token migration event.
The platform was apparently shut down shortly after the hack, with its last tweet being posted on April 30, 2021, urging users to remove funds from its various liquidity pools.
Unanswered questions
It’s also worth noting that on April 28, 2021, someone claiming to be a member of the project’s development team hinted on the Uranium Discord channel that the hack may have been an inside job.
Noting that few team members knew about the vulnerability before the v2.1 protocol was launched, they questioned the suspicious timing of the hack, which was just two hours before launch.
Since then, reports of the project and its victims have gone cold. However, posts on Binance forums last October suggest that users have been left out in the cold.
Related: 7 February DeFi Protocol Hacks Lead to $21 Million in Stolen Funds: DefiLlama
On October 26, user “RecoveryMad” published a post asking for a follow-up to the hack, noting that the person representing the Uranium team on Community Telegram had “disappeared.”
In response, the user “nofiatnolie” claimed that “no investigation was conducted. It was swept under the rug. There are still victim groups with no answers and crowd-sourced investigations [are] He points to the developers of uranium and others as suspects.”
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers
Comments are closed.