There is growing concern about the number of hackers using centralized exchanges to fund their crypto attacks.
See also: North Korean hackers stole $600 million worth of crypto in 2023

To pay the transaction fees required to carry out attacks, hackers must first fund wallets . However, due to the transparency of a public ledger, they must carefully consider how to do so without being linked to the crime.
Tornado Cash used to be the standard way to cover one's tracks, used by hackers and privacy advocates alike. Now, it seems that in many cases, malicious actors are simply choosing to bypass exchanges' know-your-customer (KYC) procedures when funding their accounts.
Blockchain monitoring firm Forta Network 's analysis of the funding sources of recent attacks shows that the hacker favorite, Tornado Cash, now accounts for less than half of attacks , with funds originating from centralized exchanges (CEXs) making up a third of cases.
Other funding methods included the innovative privacy tool Railgun and the “middleware operations software” UnionChain , as well as cross-chain exchanges via the Squid router.
The dataset consists of addresses used in 30 recent flash-loan attacks, including the sophisticated $48 million attack in November on decentralized exchange KyberSwap, the ongoing attacks on Arbitrum Radiant Capital and Gamma Strategies , and a $1 million attack on NFT project Loot last month.
See also: Mandiant's X account hacked in crypto scam
Although Tornado Cash remains the main source of funding for on-chain attacks, matters have become more complicated for hackers trying to raise funds following the sanctions imposed by the US Treasury Department on the cryptocurrency mixing service in August 2022.

The high proportion of attacks by hackers funded by centralized exchanges shows how easy it has become to bypass customer authentication, a trend that will likely continue with the wider use of such tools.
Although hackers face the risk of being banned from CEX, they may feel somewhat safer by leaving fewer traces on the chain.
While avoiding genuine KYC checks may pose a problem for the cryptocurrency industry in deterring hackers, this problem is likely to affect many other industries. Paradoxically, the widespread use of cryptographic proofs, the technology that underlies cryptocurrencies, may be the solution to these types of problems in the future.
However, for now, there are reasonable doubts about how seriously centralized exchanges take their role and how strict the checks on customer identity really are.
See also: North Korea: Hackers have stolen crypto to fund nuclear weapons programs
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
How can users protect their digital assets from cryptographic attacks?
Users can protect their digital assets from crypto attacks in a number of ways. First, it is important to keep their software and operating system , as updates often include security patches that can protect against new threats.
Additionally, users should use strong and unique passwords for each of their accounts. This can help protect against attacks aimed at revealing passwords.
It's also important to use two-factor authentication (2FA) where available. 2FA adds an extra layer of security by requiring users to verify their identity in two different ways.
Finally, users should be careful with the emails and messages they receive, as many crypto attacks start with seemingly harmless messages that contain malicious links or attachments.
Source: protos
