Cryptocurrency

Tweet thread by zachxbt

2023-12-07 [vendor] Uranium Finance [chain] bsc
Primary Source ↗
Blockchain(s) Bsc

Incident Details

In April 2021, an attacker stole $50 million from the defi exchange Uranium Finance. Blockchain investigator zachxbt now says that he believes this attacker has been able to cash out his ill-gotten funds… in an unusual way.After tracing the attacker’s attempts to launder the money through Tornado Cash and then obfuscate that it had come from the mixing service (something that raises flags at some exchanges), zachxbt observed the funds go to a broker of Magic: The Gathering based in the United States. Altogether, the hacker appeared to be spending millions on starter decks, alpha sets, and sealed boxes — often overpaying by 5-10%. These items routinely sell for hundreds or thousands of dollars.The thief is probably a creative money launderer rather than an massive MTG fan, and is probably reselling the cards to further obscure the source of the money. Then again, MTG is more than a little addictive.

Technical Details

Initial Attack Vector
On-chain theft (attributed by zachxbt)
Vendor / Product
Uranium Finance

Timeline

  1. 2023-12-07 Breach occurred
  2. 2023-12-07 Publicly disclosed