The attacker behind Triple-A's July treasury breach moved 4,970 ETH into Tornado Cash on Oct. 9, according to blockchain security firm Salus. Triple-A said the breach affected company treasury assets, while customer funds remained untouched.
The attacker behind Triple-A's July treasury breach transferred 4,970 ETH worth approximately $12.4 million into Tornado Cash, according to blockchain security firm Salus. Salus said its Tornado monitoring system tracked 49 deposits of 100 ETH and seven deposits of 10 ETH linked to the attacker on Oct. 9.
Attacker combined two fund streams before depositing ETH
Salus described two streams of funds that passed through separate intermediary addresses before reaching one wallet, which the attacker used to make the deposits. According to Salus: "One stream included funds from earlier withdrawals."
The tracing account places the transfers after the attacker moved assets across blockchains to Ethereum, exchanged the tokens, and divided the funds between two addresses on Sep. 6. Salus's breakdown puts 4,900 ETH in the 49 larger deposits and another 70 ETH in the seven smaller ones.
Triple-A said the July breach hit its treasury, not customer funds
In its official statement, Triple-A said it detected unauthorized access on July 25 and temporarily placed certain services into maintenance mode for approximately three hours. The company said customer funds were held separately in trust accounts and were not exposed, because it did not provide digital asset custody on behalf of its clients.
Public estimates placed the loss at approximately $11.8 million. Triple-A said it remained well capitalised and able to meet all its liabilities.
Social engineering opened the door
In an Aug. 21 post-mortem, Triple-A said the attack began with social engineering against an engineering employee, involving impersonation, communications across different channels, and a live call. After compromising credentials, the attacker obtained elevated system permissions, deployed malware, accessed production databases, and abused API credentials to execute cryptocurrency withdrawals, the report said.
Triple-A engaged Sygnia for forensic work and zeroShadow for asset tracing. The company said it had removed active attacker access, while tracing and potential freezing actions remained in progress.
Source: crypto.news
Trading involves risk.