The movement of funds, valued at approximately $44.4 million, occurred between July 23 and July 24. On-chain records from PeckShield and Etherscan show the exploiter processing hundreds of transactions, frequently depositing batches of 100 ETH into the mixing service to decouple the link between the origin and destination addresses. Smaller amounts—totaling 0.85 ETH—were traced to wallets tagged as Bybit deposit addresses, signaling potential attempts to move assets onto an exchange.
Prominent investigator ZachXBT, who had been tracking the stolen assets, stated he would not continue monitoring these specific funds. He noted that the resources required to track a nine-figure, North Korea-linked operation are prohibitive for a single person, especially without institutional backing. Mandiant has previously linked the April attack to the threat group UNC6862, which exploited social engineering and compromised access rather than a smart contract vulnerability.

Comments (0)
No comments yet. Be the first!