Cointime

Download App
iOS & Android

White Hat v. Black Hat: What Really Happened With the FTX Hack?

Cointime Official

Bankruptcy lawyers are battling Bahamian regulators over crypto tied to former billionaire Sam Bankman-Fried’s FTX empire — raising questions about a peculiar half-billion-dollar hack on the exchange last week.

Last weekend, blockchain analytics unit Elliptic reported that $663 million in various cryptocurrencies had been drained from FTX wallets just 24 hours after 134 affiliated entities had filed for Chapter 11 bankruptcy on Nov. 11.

Elliptic at the time attributed $186 million of those outflows to FTX personnel, who’d appeared to be securing compromised funds to avoid further losses. The remaining $447 million in digital assets were said to have been siphoned in “unauthorized transfers,” with $220 million cashed out for ether and stablecoin DAI. Blockchain data shows the attacker interacting with decentralized exchanges such as Uniswap alongside aggregators 1inch and CoW Protocol.

At the time of the attack, FTX representatives in the firm’s Telegram channel characterized the situation as a hack and urged FTX users not to interact with the exchange’s website and apps for fear of malware.

FTX US general counsel Ryne Miller later shared a statement from FTX’s appointed restructurer John J. Ray III, who confirmed that “unauthorized access to certain assets has occurred.”

Fast forward to Thursday, and the Securities Commission of the Bahamas announced via Twitter it had assumed control of assets belonging to FTX Digital Markets, leading onlookers to question whether the commission was the hacker — albeit a “white hat” — all along.

“On [Nov. 12], the Commission, in the exercise of its powers as regulator acting under the authority of an Order made by the Supreme Court of the Bahamas, took the action of directing the transfer of all digital assets of FTX Digital Markets to a digital wallet controlled by the Commission, for safekeeping,” the Commission said.

It went on: “Urgent interim regulatory action was necessary to protect the interests of clients and creditors of FTX Digital Markets.”

The statement aligns with evidence provided by FTX representatives in their court filing, released shortly after the Commission’s tweet. They say government officials allegedly directed Bankman-Fried and co-founder Gary Wang — described as “effectively in the custody of Bahamas authorities” — to make the presumably unauthorized transfers.

According to FTX lawyers, the crypto is being kept with New York-based direct custody-service startup Fireblocks under control of the Bahamian government. Fireblocks declined to comment on the record.

FTX hacker could’ve been in waiting for a long time

The question remains: Was FTX actually hacked? On-chain data reviewed by Blockworks does indeed show addresses linked to an attacker draining almost half a billion dollars in various cryptocurrencies from FTX hot wallets — including FTX US — on Nov. 12.

Tokens were apparently siphoned across multiple blockchains including Ethereum, Solana and Binance Chain. Cryptocurrencies such as gold-pegged asset pax gold, tether, ether, chainlink, shiba inu and bitcoin all featured prominently in the haul, as well as aave and apecoin.

As earlier noted by Elliptic, much of the funds in question were quickly sold for MakerDAO’s decentralized stablecoin DAI and ether — assets considered uncensorable. Notably, no funds were sent to crypto mixers such as Tornado Cash.

Tether, on the other hand, quickly moved to freeze around $47 million in USDT, rendering the tokens moot and valueless.

But Tom Robinson, chief scientist at Elliptic, isn’t totally convinced the incident was a hack. In an email to Blockworks, Robinson explained that based on the information shared publicly it’s still not clear exactly what happened. But his interpretation would be that the Bahamian regulator gave instructions to convert the stablecoins and other tokens into ETH and DAI to avoid them being frozen by their issuers.

“That or whoever was directed to move the assets took it upon themselves to perform the conversion. But that’s just speculation on my part at the moment,” Robinson said.

Bankman-Fried addressed the apparent hack in recent conversations with Vox journalist Kelsey Piper, saying that the hacker was either a disgruntled employee or a bad actor who had smuggled malware onto an employees machine, leading to compromised hot wallet private keys.

Indeed, court filings recently showed just how lax FTX cybersecurity practices were. Lawyers maintain that former CEO Bankman-Fried and chief technology officer Wang used an “unsecured group email account to access confidential private keys and other critically sensitive information.”

Retrieving FTX’s stolen crypto could take years — if at all

To Nick Bax, head of research at crypto research and development startup Convex Labs, this leaves open the possibility that a company insider was phished — which could’ve directly led to the hack last week. Similar prominent thefts have been linked to the Lazarus hacking group affiliated with the North Korean government, which has cultivated vulnerabilities within crypto companies, although there has been no direct evidence or allegations made by law enforcement in this case.

Bax remained confident that the initial Ethereum wallet labeled as FTX Account Drainer on Etherscan was a black hat hacker. He described a scenario where a hacker had gotten to FTX’s unsecured email account and FTX private keys.

“Like everybody else, you think FTX has $10 billion or $20 billion — what do you do? Stay in the network and wait for your opportunity to steal it all,” Bax said.

“We do know in other cases, sophisticated or state-sponsored hackers, they had an opportunity to steal a life-changing amount of money, but they stayed and maintained their foothold in the network for months and months, waiting for the opportunity to maximize their theft. In the case of FTX, they could’ve realized that FTX was actually insolvent at the same time as everybody else, and just pulled what they could.”

Kraken Chief Security Officer Nick Percoco tweeted at the time of the attack that the exchange knew the identity of the attacker, as Kraken accounts had funded certain transaction fees for some illicit transactions. Percoco later appeared to walk those comments back, tweeting that the accounts in question may have belonged to FTX, and the cited transactions may have been part of efforts to safeguard crypto from the attack. Blockworks has reached out for comment.

But whether it was a disgruntled employee, North Korean hackers or someone else, the matter of whether the funds could eventually be retrieved and returned to FTX creditors is unclear.

Bax, who has worked extensively in cryptoasset recovery on behalf of hacking victims, explained that retrieving the funds begins with identifying the hacker.

“There’s been several large recoveries from the Silk Road hack and those took years. There’s been a partial recovery from the North Korean hacks of the Ronin network, but they only got around 20% back,” Bax said.

“It really depends on who it is, if it’s an insider — it’s not that hard. If it’s the North Koreans who hacked the insider, then good luck.”

(By DAVID CANELLIS& SEBASTIAN SINCLAIR)

https://blockworks.co/news/what-happened-ftx-hack

Comments

All Comments

Recommended for you

  • Uniswap’s market share in DEX has dropped to 36%

    The DEX landscape is undergoing changes, with the market share of the veteran decentralized exchange Uniswap dropping from over 50% in October 2023 to the current 36%.

  • Exowatt completes $20 million financing, a16z participates in the investment

    Startup company Exowatt announced that it is addressing the energy needs of data centers through its ceramic battery technology. The company claims that its technology can store solar energy for months, helping to cope with the rapid growth of power consumption in data centers. The company has received $20 million in seed funding, with investors including a16z and Altman. According to reports, Exowatt has accumulated 1.2 gigawatts of orders, mainly focused on data centers and cryptocurrency mining projects in the United States.

  • Singapore police investigate Worldcoin account transactions, arrest five people

    On September 10th, Singapore's Deputy Prime Minister Heng Swee Keat announced that Singaporean police are investigating seven individuals suspected of providing Worldcoin account and token trading services. This investigation involves possible violations of the Payment Services Act of 2019, and the police have arrested five people.

  • Putin: Russia "supports" Harris, calls her smile "contagious"

    According to foreign media such as TASS and Russia's Sputnik News, Jinse Finance reported that on the afternoon of September 5th local time, Russian President Putin said at the plenary session of the Eastern Economic Forum 2024 that Russia will "support" the US Democratic Party presidential candidate and vice president Harris as recommended by the US President Biden in the upcoming US presidential election. When asked how he viewed the 2024 US election, Putin said it was the choice of the American people. The new US president will be elected by the American people, and Russia will respect the choice of the American people. Putin also said that just as Biden suggested his supporters to support Harris, "we will do the same, we will support her." The report said that Putin also joked that Harris' laughter is "expressive and infectious," which shows that "she is doing everything well." He added that this may mean that she will avoid further sanctions against Russia.

  • An ETH whale repurchased 5,153 ETH with 12.23 million USDT 20 minutes ago

    A certain high-frequency trading ETH whale monitored by on-chain analyst Yu Jin bought 5,153 ETH with 12.23 million USDT 20 minutes ago.

  • CFTC: Uniswap Labs has actively cooperated with the investigation and only needs to pay a fine of US$175,000

    The CFTC has filed a lawsuit against Uniswap Labs and reached a settlement. It was found that Uniswap Labs illegally provided leveraged or margined retail commodity transactions of digital assets through a decentralized digital asset trading protocol. Uniswap Labs was required to pay a civil penalty of $175,000 and cease violations of the Commodity Exchange Act (CEA). The CFTC acknowledged that Uniswap Labs actively cooperated with law enforcement agencies in the investigation and reduced the civil penalty.

  • Federal Reserve Beige Book: Respondents generally expect economic activity to remain stable or improve

    The Federal Reserve's Beige Book pointed out that economic activity in three regions has slightly increased, while the number of regions reporting flat or declining economic activity has increased from five in the previous quarter to nine in this quarter. Overall employment levels remain stable, although some reports indicate that companies are only filling necessary positions, reducing working hours and shifts, or reducing overall employment levels through natural attrition. However, reports of layoffs are still rare. Generally speaking, wage growth is moderate, and the growth rate of labor input costs and sales prices ranges from slight to moderate. Consumer spending has declined in most regions, while in the previous reporting period, consumer spending remained stable overall.

  • Puffpaw Completes $6 Million Seed Round with Lemniscap Ventures as Participant

    Puffpaw has announced the completion of a $6 million seed round of financing, with participation from Lemniscap Ventures. The Puffpaw project plans to launch a blockchain-enabled electronic cigarette aimed at helping users reduce nicotine intake through token incentives. The project encourages users to quit smoking by recording their smoking habits and rewarding them with tokens. Puffpaw's token economics aims to cover 30% of the cost of users' first month of using their product and provide social rewards. The project also considers possible system abuse, but the issue of users potentially reporting smoking habits dishonestly is not yet clear.

  • Affected by Ethervista and others, Ethereum Gas temporarily rose to 33gwei

    According to Etherscan, due to the influence of contracts such as Ethervista, Ethereum Gas has temporarily risen to 33gwei, with the top three being EthervistaRouter, UniswapRouter, and BananaGun.

  • The probability of the Fed cutting interest rates by 25 basis points in September is 55%.

    The probability of the Federal Reserve cutting interest rates by 25 basis points in September is 55.0%, while the probability of a 50 basis point cut is 45.0%. The probability of the Federal Reserve cutting interest rates by a cumulative 50 basis points by November is 32.1%, by 75 basis points is 49.2%, and by 100 basis points is 18.8%.