Cointime

Download App
iOS & Android

White Hat v. Black Hat: What Really Happened With the FTX Hack?

Cointime Official

Bankruptcy lawyers are battling Bahamian regulators over crypto tied to former billionaire Sam Bankman-Fried’s FTX empire — raising questions about a peculiar half-billion-dollar hack on the exchange last week.

Last weekend, blockchain analytics unit Elliptic reported that $663 million in various cryptocurrencies had been drained from FTX wallets just 24 hours after 134 affiliated entities had filed for Chapter 11 bankruptcy on Nov. 11.

Elliptic at the time attributed $186 million of those outflows to FTX personnel, who’d appeared to be securing compromised funds to avoid further losses. The remaining $447 million in digital assets were said to have been siphoned in “unauthorized transfers,” with $220 million cashed out for ether and stablecoin DAI. Blockchain data shows the attacker interacting with decentralized exchanges such as Uniswap alongside aggregators 1inch and CoW Protocol.

At the time of the attack, FTX representatives in the firm’s Telegram channel characterized the situation as a hack and urged FTX users not to interact with the exchange’s website and apps for fear of malware.

FTX US general counsel Ryne Miller later shared a statement from FTX’s appointed restructurer John J. Ray III, who confirmed that “unauthorized access to certain assets has occurred.”

Fast forward to Thursday, and the Securities Commission of the Bahamas announced via Twitter it had assumed control of assets belonging to FTX Digital Markets, leading onlookers to question whether the commission was the hacker — albeit a “white hat” — all along.

“On [Nov. 12], the Commission, in the exercise of its powers as regulator acting under the authority of an Order made by the Supreme Court of the Bahamas, took the action of directing the transfer of all digital assets of FTX Digital Markets to a digital wallet controlled by the Commission, for safekeeping,” the Commission said.

It went on: “Urgent interim regulatory action was necessary to protect the interests of clients and creditors of FTX Digital Markets.”

The statement aligns with evidence provided by FTX representatives in their court filing, released shortly after the Commission’s tweet. They say government officials allegedly directed Bankman-Fried and co-founder Gary Wang — described as “effectively in the custody of Bahamas authorities” — to make the presumably unauthorized transfers.

According to FTX lawyers, the crypto is being kept with New York-based direct custody-service startup Fireblocks under control of the Bahamian government. Fireblocks declined to comment on the record.

FTX hacker could’ve been in waiting for a long time

The question remains: Was FTX actually hacked? On-chain data reviewed by Blockworks does indeed show addresses linked to an attacker draining almost half a billion dollars in various cryptocurrencies from FTX hot wallets — including FTX US — on Nov. 12.

Tokens were apparently siphoned across multiple blockchains including Ethereum, Solana and Binance Chain. Cryptocurrencies such as gold-pegged asset pax gold, tether, ether, chainlink, shiba inu and bitcoin all featured prominently in the haul, as well as aave and apecoin.

As earlier noted by Elliptic, much of the funds in question were quickly sold for MakerDAO’s decentralized stablecoin DAI and ether — assets considered uncensorable. Notably, no funds were sent to crypto mixers such as Tornado Cash.

Tether, on the other hand, quickly moved to freeze around $47 million in USDT, rendering the tokens moot and valueless.

But Tom Robinson, chief scientist at Elliptic, isn’t totally convinced the incident was a hack. In an email to Blockworks, Robinson explained that based on the information shared publicly it’s still not clear exactly what happened. But his interpretation would be that the Bahamian regulator gave instructions to convert the stablecoins and other tokens into ETH and DAI to avoid them being frozen by their issuers.

“That or whoever was directed to move the assets took it upon themselves to perform the conversion. But that’s just speculation on my part at the moment,” Robinson said.

Bankman-Fried addressed the apparent hack in recent conversations with Vox journalist Kelsey Piper, saying that the hacker was either a disgruntled employee or a bad actor who had smuggled malware onto an employees machine, leading to compromised hot wallet private keys.

Indeed, court filings recently showed just how lax FTX cybersecurity practices were. Lawyers maintain that former CEO Bankman-Fried and chief technology officer Wang used an “unsecured group email account to access confidential private keys and other critically sensitive information.”

Retrieving FTX’s stolen crypto could take years — if at all

To Nick Bax, head of research at crypto research and development startup Convex Labs, this leaves open the possibility that a company insider was phished — which could’ve directly led to the hack last week. Similar prominent thefts have been linked to the Lazarus hacking group affiliated with the North Korean government, which has cultivated vulnerabilities within crypto companies, although there has been no direct evidence or allegations made by law enforcement in this case.

Bax remained confident that the initial Ethereum wallet labeled as FTX Account Drainer on Etherscan was a black hat hacker. He described a scenario where a hacker had gotten to FTX’s unsecured email account and FTX private keys.

“Like everybody else, you think FTX has $10 billion or $20 billion — what do you do? Stay in the network and wait for your opportunity to steal it all,” Bax said.

“We do know in other cases, sophisticated or state-sponsored hackers, they had an opportunity to steal a life-changing amount of money, but they stayed and maintained their foothold in the network for months and months, waiting for the opportunity to maximize their theft. In the case of FTX, they could’ve realized that FTX was actually insolvent at the same time as everybody else, and just pulled what they could.”

Kraken Chief Security Officer Nick Percoco tweeted at the time of the attack that the exchange knew the identity of the attacker, as Kraken accounts had funded certain transaction fees for some illicit transactions. Percoco later appeared to walk those comments back, tweeting that the accounts in question may have belonged to FTX, and the cited transactions may have been part of efforts to safeguard crypto from the attack. Blockworks has reached out for comment.

But whether it was a disgruntled employee, North Korean hackers or someone else, the matter of whether the funds could eventually be retrieved and returned to FTX creditors is unclear.

Bax, who has worked extensively in cryptoasset recovery on behalf of hacking victims, explained that retrieving the funds begins with identifying the hacker.

“There’s been several large recoveries from the Silk Road hack and those took years. There’s been a partial recovery from the North Korean hacks of the Ronin network, but they only got around 20% back,” Bax said.

“It really depends on who it is, if it’s an insider — it’s not that hard. If it’s the North Koreans who hacked the insider, then good luck.”

(By DAVID CANELLIS& SEBASTIAN SINCLAIR)

https://blockworks.co/news/what-happened-ftx-hack

Comments

All Comments

Recommended for you

  • BTC breaks through $69,000

     the market shows BTC breaking through $69,000, currently at $69,021.49, with a 24-hour increase of 1.15%. The market is highly volatile, please manage your risk accordingly.

  • Spanish Foreign Minister: Not worried about any consequences of refusing US access to military bases

     on March 3 local time, Spanish Foreign Minister Alvarez defended the Spanish government's refusal to provide the Rota and Moron military bases to the United States for participation in attacks on Iran. Alvarez stated that the operation initiated by the United States and Israel is not supported by the United Nations and is not part of the bilateral agreements allowing the use of the aforementioned Spanish sovereign military bases. Alvarez also said that the Spanish government is not concerned that this stance will have any consequences. Alvarez stated: "The position of the Spanish government represents the will of the vast majority of the Spanish people as well as the vast majority of people worldwide, which is to defend the UN Charter, respect international law, and believe that cooperation is always more powerful than confrontation."

  • Spot gold plunges nearly $100 in the short term.

     spot gold plunged nearly 100 dollars in a short time, spot gold fell below 5170 dollars/ounce, with a daily decline of 2.94%. 

  • BTC falls below $67,000

    the market shows BTC fell below $67,000, currently at $66,996.93, with a 24-hour increase of 1.18%. The market is highly volatile, please manage your risk accordingly.

  • ETH breaks $2,000

    the market shows ETH breaking through $2000, currently at $2001.64, with a 24-hour increase of 2.89%. The market is highly volatile, please manage your risks accordingly.

  • The US spot Bitcoin ETF saw a net inflow of $962.48 million yesterday.

    according to Trader T's monitoring, the US spot Bitcoin ETF had a net inflow of 962.48 million USD yesterday.

  • BTC falls below $66,000

     the market shows BTC fell below 66,000 USD, currently at 65,986.66 USD, with a 24-hour decline of 1.31%. The market is highly volatile, please manage your risks accordingly.

  • BTC falls below $66,000

     the market shows BTC fell below $66,000, currently at $65,973.16, a 24-hour drop of 2.66%. The market is highly volatile, please manage your risks accordingly.

  • ETH breaks $2,000

    market shows ETH breaking through $2000, currently at $2000.29, with a 24-hour increase of 3.73%. The market is volatile, please manage your risk accordingly.

  • The United States uses Anthropic's artificial intelligence technology in its airstrikes in the Middle East.

     United States used Anthropic's artificial intelligence technology in airstrikes in the Middle East, and just hours before the attack, Trump had just issued a ban against Anthropic.