Thursday, May 22, 2025

Coinbase hacker trolls ZachXBT onchain after $42.5M THORChain swap

The hacker behind the info breach focusing on Coinbase customers mocked blockchain investigator ZachXBT with an onchain message following a significant crypto swap.

On Might 21, the hacker used Ethereum transaction enter information to jot down “L bozo,” adopted by a meme video of NBA participant James Worthy smoking a cigar.

The message got here after the attacker swapped about $42.5 million from Bitcoin (BTC) to Ether (ETH) through THORChain.

ZachXBT flagged the message on his Telegram channel, linking it to the identical entity liable for the Coinbase information breach affecting a minimum of 69,400 customers.

Coinbase hacker trolling ZachXBT. Supply: ZachXBT.

On Might 22, blockchain safety agency PeckShield reported that the hacker had continued to maneuver funds, swapping 8,697 ETH for 22 million Dai (DAI). A separate however carefully linked deal with, which obtained 9,081 ETH through THORChain, additionally transformed the property into 23 million DAI.

Associated: DOJ is investigating Coinbase information breach— Report

Coinbase hit with lawsuits after breach

The Coinbase breach, first reported in a submitting with the Maine Lawyer Basic’s workplace, occurred in December 2024 and was found on Might 11. The stolen information contains names, house addresses and different private data.

Following the disclosure, the attackers demanded a $20 million ransom in Bitcoin to stop the discharge of the stolen information. Coinbase refused and as an alternative provided a $20 million bounty for data resulting in the identification of the hackers.

The corporate estimates a possible monetary impression between $180 million and $400 million as a consequence of remediation prices and buyer compensation.

Coinbase has additionally confronted a wave of lawsuits following the revelation. A minimum of six authorized complaints have been filed on Might 15 and 16, with plaintiffs accusing the change of failing to implement sufficient safety measures and mishandling its response to the breach.

Associated: Coinbase information leak may put customers in bodily hazard: TechCrunch founder

THORChain beneath scrutiny for felony use

The Coinbase hacker’s use of THORChain to swap $42.5 million value of Bitcoin into Ether comes because the protocol faces rising scrutiny over its function in facilitating illicit transactions.

In March, the platform got here beneath hearth after its swap quantity surged following the $1.4 billion Bybit hack. The protocol generated over $5 million in income after processing $5.4 billion in swap quantity, with over $1 billion moved in a single day.

Blockchain safety corporations recognized North Korea’s Lazarus Group as the primary suspect, utilizing THORChain to launder a good portion of the stolen funds.

Supply: Lookonchain

The controversy intensified when a THORChain developer, generally known as “Pluto,” resigned after a vote to dam transactions linked to Lazarus was overturned.

Journal: TradFi is constructing Ethereum L2s to tokenize trillions in RWAs: Inside story