The hacker behind the March 2024 Unizen exploit laundered over $2 million through the Tornado Cash mixer. Cybersecurity firm Peckshield Alerts reported that the attacker laundered 865.4 ETH, which equates to approximately $2.16 million obtained from the exploit wallet.
This activity took place 151 days after the initial attack, which resulted in a loss of $2.1 million due to an ‘approve issue’ that occurred on Unizen’s platform. Also, all attempts to get the money back from the hacker have been in vain, as the latter has not responded to the team.
The laundering process began with the movement of 2,179,859 DAI from the exploit wallet to another punk wallet that is unknown, addressed as “0X866. . . 84d7.” The laundered DAI was then swapped for ETH in uniswap as it continued its journey through Tornado Cash in 26 transactions. This was able to empty both the operator’s pockets, while the winners kept theirs lined.
The March 2024 Attack
The attack took place on March 9, 2024, by exploiting the “approve issue” vulnerability in Unizen’s platform, and the company lost $2.1 million worth of USDT, which was subsequently exchanged for DAI. PeckShield had discovered the vulnerability and alerted Unizen, but by the time the latter received the alert, the damage had already been done.
Unizen attempted to contact the hacker and ask him to return all stolen assets and promised to increase the bounty amount to 20% for the returned assets, but the hacker never responded. This team attempted to contact the hacker via on-chain messages in an attempt to beg the hacker to return the stolen funds in exchange for a bounty.
The hack that took place on the Unizen platform is similar to the Nomad Bridge hack to show that no platform is immune to cyberattacks. The Nomad Bridge was attacked in August 2022 for around $200 million after a similar lack of vigilance, highlighting the need to constantly update and improve security measures. The hacker was smart enough to buy the dip and bought thousands of ETH by exchanging the stolen DAI.
Also Watch: WazirX Hack Update: CoinDCX Unveils Rs 50 Crore Investor Protection Fund!