KEY POINTS

  • Hackers of Ronin Bridge used ChipMixer and Blender Bitcoin mixers
  • Funds were withdrawn from Tornado Cash and transferred to Bitcoin network from Ethereum
  • Before transferring to Bitcoin network, hackers used Ren Protocol as well

The attackers of Ronin Bridge have successfully transferred their funds from Ethereum to the Bitcoin network, according to findings by blockchain investigator and developer ₿liteZero.

Ronin Bridge, an Ethereum sidechain built for play-to-earn game Axie Infinity, was hacked in March and over $625 million worth of USDC and ETH tokens were transferred to Ethereum-based crypto mixer Tornado Cash. This made it difficult for authorities to track the funds. The hackers were believed to be from North Korea.

In a Twitter thread, ₿liteZero explained they had been tracking the whereabouts of the funds for a long time and most of the funds were deposited in Bitcoin mixers like ChipMixer and Blender as the hackers' attempts to obscure the transactions continued.

"As of now, the vast majority of the Ronin hacker's ETH funds have been deposited to Tornado Cash, and 6,250 Ether deposited to exchanges (such as Huobi, FTX, or Cryptocom)," explained the blockchain investigator.

The U.S. Treasury sanctioned Blender in May due to its involvement with the Ronin Bridge attack stating that the DPRK [Democratic People's Republic of Korea] "has resorted to illicit activities, including cyber-enabled heists from cryptocurrency exchanges and financial institutions, to generate revenue for its unlawful weapons of mass destruction (WMD) and ballistic missile programs."

"Most Blender sanction addresses are Blender's deposit addresses used by Ronin hackers. They have deposited all their withdrawal funds to Blender after withdrawing from the exchanges," ₿liteZero revealed.

Additionally, the amount withdrawn from the exchanges is $20.72 million and this "is consistent with the 'over $20.5 million' in sanctioned releases." However, this wasn't the end as after withdrawing from Tornado Cash, "the hacker used 1inch or Uniswap to swap the funds for renBTC before finally bridging them to the bitcoin network."

renBTC is an ERC-20-based token, which is a part of the Ren Protocol project that allows the decentralized representation of Bitcoin inside Ethereum.

After withdrawing from Ren, the funds were transferred to ChipMixer and from there, half the funds were sent to Blender.

Hackers linked to North Korea are responsible for the March 2022 theft of $620 million in ethereum, a type of cryptocurrency
Hackers linked to North Korea are responsible for the March 2022 theft of $620 million in ethereum, a type of cryptocurrency AFP / INA FASSBENDER