Cryptocurrency [loss] $15M+

Telegram post by zachxbt

2024-04-29 [vendor] Rain [chain] bitcoin, ethereum, ripple, solana
Primary Source ↗
Financial Loss $14.8M (14,800,000 USD)
Blockchain(s) Bitcoin, Ethereum, Ripple, Solana

Incident Details

Bahrain-based cryptocurrency exchange Rain was exploited for around $16.13 million dollars on April 29. The exchange did not publicly disclose the hack until the suspicious outflows across wallets on multiple blockchains were noticed by blockchain investigator zachxbt.After zachxbt sounded the alarm on May 13, Rain admitted that they had had a “security incident”, but stressed that customer funds were safe, and stated that the Rain Group had “covered any potential losses resulting from this incident”.The attack was later attributed to North Korean state-sponsored attackers.

Total loss estimated at $14,800,000.

Technical Details

Initial Attack Vector
Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise
Vendor / Product
Rain

Timeline

  1. 2024-04-29 Breach occurred
  2. 2024-04-29 Publicly disclosed