Hackers steal $8 million from crypto exchange via two blockchains

Hackers moved $8 million from a cryptocurrency exchange, routing funds across two blockchains and multiple addresses, the exchange reported this week.

A cryptocurrency exchange reported this week that hackers removed $8 million from its hot wallets and moved the funds across two separate blockchains. The loss was discovered during a routine reconciliation and prompted an immediate investigation.

Security researchers and blockchain analytics firms traced the transfers on-chain. The attackers first moved assets from the exchange’s hot wallets on one blockchain, used a cross-chain bridge to move value to a second blockchain, and then split the funds across dozens of addresses. The assets included native tokens on the first chain and wrapped versions issued on the secondary chain.

The exchange temporarily suspended withdrawals and trading while investigators followed the transactions. The operation took place over several hours and involved a sequence of smaller transfers rather than a single large withdrawal. Analysts described the pattern as consistent with tactics intended to complicate tracing and recovery, including rapid address fragmentation and multi-step bridging.

The exchange notified law enforcement and provided transaction hashes and wallet addresses to support tracing efforts. Several major services flagged and blacklisted the addresses linked to the incident to hinder simple cash-outs. Blockchain monitoring firms are sharing intelligence with investigators to map the on-chain movements and identify any points where the funds could be converted to fiat or major stablecoins.

Technical analysis shows some of the split addresses performed token swaps and transfers on decentralized exchanges and used tools commonly associated with privacy-enhancing transfers. Investigators are examining those on-chain interactions to locate any downstream services that might accept the stolen assets.

No public attribution has been made and the exchange’s name has not been widely disclosed. The company reported it is working with external forensics teams and law enforcement and advised customers to monitor their accounts for any unusual activity while the investigation continues.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author