Original Source: Beosin
Recently, the cryptocurrency exchange BTCTurk announced that it had been hacked, with over $48 million in funds flowing out of multiple on-chain hot wallets . The Beosin security team analyzed the incident and tracked the funds, sharing their findings below:
The hot wallet addresses where funds have been transferred are as follows:
0xde2faca4bbc0aca08ff04d387c39b6f6325bf82a
0x2cea0297bfb1b55ff37126b677d78e2b1fd2e856
0xb5a46bc8b76fd2825aeb43db9c9e89e89158ecde
Involving chains such as Bitcoin, Ethereum (ETH), Avalanche (AVAX), Arbitrum (ARB), Base (BASE), Optimism (OP) and Polygon (POL).
The following hacker transfer addresses are currently detected:
0xa041feb3a8297c5689fee180083164a061a17fd6
0xb4b537626e21df5386cf167d1e654b38785056cc
0x7d91d1ebeba91257733a523409125aedac5d8b6e
Using the Beosin Trace tool to track the stolen funds, we can obtain the following flow chart of the main stolen funds on the EVM chain and the Bitcoin chain:
Beosin Trace EVM chain fund analysis chart
Beosin Trace Bitcoin Chain Funding Analysis Chart
The cause of the BTCTurk hot wallet attack remains undisclosed. Investigations and evidence collection are needed to assess the exchange's internal operational security, signature device security, seed phrase management, and signature environment security. Similar exchange security incidents have occurred numerous times before, including the Bybit incident, the largest crypto security incident, where over $1.44 billion was stolen. A comprehensive chain trace analysis was also conducted, as was the Beosin analysis of the $235 million theft from the Indian exchange WazirX .
Exchange security remains a major challenge in the Web 3 ecosystem, requiring continued efforts and collaboration from exchanges, security companies, regulators, and law enforcement agencies. Beosin Trace has added the hacker-related addresses to its blacklist and will continue tracking them.
- 核心观点:BTCTurk遭黑客攻击损失4800万美元。
- 关键要素:
- 涉及多链热钱包异常流出资金。
- 黑客中转地址已被追踪标记。
- 交易所安全仍是Web3重大挑战。
- 市场影响:加剧用户对中心化交易所信任危机。
- 时效性标注:短期影响。
