Cryptocurrency [loss] $100M+

Tweet thread by Harmony

2022-06-23 [vendor] Horizon Bridge [chain] bsc, ethereum
Primary Source ↗
Financial Loss $100.0M (100,000,000 USD)
Blockchain(s) Bsc, Ethereum

Incident Details

The Horizon Bridge is a blockchain bridge allowing assets to be used across Ethereum, BNB, and Harmony blockchains. The bridge is run by the Harmony blockchain project.On June 23, someone was able to steal assets from the bridge that they then converted to more than 85,800 ETH. The stolen funds are notionally valued at almost $100 million, assuming the thief can cash them out successfully. Hours after the attack, most of the funds remained in the thief’s wallet and had not yet been laundered.A June 29 analysis by blockchain research firm Ellipsis claimed that “there are strong indications that North Korea’s Lazarus Group may be responsible for this theft”. Lazarus was also behind the $625 million bridge hack in March, targeting the Axie Infinity game.

Total loss estimated at $100,000,000.

Technical Details

Initial Attack Vector
Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise
Vendor / Product
Horizon Bridge

Timeline

  1. 2022-06-23 Breach occurred
  2. 2022-06-23 Publicly disclosed