Tweet thread by Harmony
Primary Source ↗Incident Details
The Horizon Bridge is a blockchain bridge allowing assets to be used across Ethereum, BNB, and Harmony blockchains. The bridge is run by the Harmony blockchain project.On June 23, someone was able to steal assets from the bridge that they then converted to more than 85,800 ETH. The stolen funds are notionally valued at almost $100 million, assuming the thief can cash them out successfully. Hours after the attack, most of the funds remained in the thief’s wallet and had not yet been laundered.A June 29 analysis by blockchain research firm Ellipsis claimed that “there are strong indications that North Korea’s Lazarus Group may be responsible for this theft”. Lazarus was also behind the $625 million bridge hack in March, targeting the Axie Infinity game.
Total loss estimated at $100,000,000.
Technical Details
- Initial Attack Vector
- Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise
- Vendor / Product
- Horizon Bridge
Timeline
- 2022-06-23 Breach occurred
- 2022-06-23 Publicly disclosed