Unibot Exploiter Swaps Stolen Crypto for Ether Via Tornado Cash

Unibot confirmed on X that it had suffered a token approval exploit in its new order router.

AccessTimeIconOct 31, 2023 at 6:54 a.m. UTC
Updated Oct 31, 2023 at 8:23 a.m. UTC
10 Years of Decentralizing the Future
May 29-31, 2024 - Austin, TexasThe biggest and most established global hub for everything crypto, blockchain and Web3.Register Now

Crypto stolen via an exploit on Telegram chatbot Unibot has been swapped for ether via Tornado Cash and is on the move.

According to PeckShield, the attacker first moved the stolen crypto to Uniswap and then sent it to Tornado Cash.

Earlier, the protocol disclosed it was the victim of a token approval exploit when moving to a new router, and it would reimburse any stolen funds.

Tornado Cash is often at the nexus of high-profile hacks and exploits in the crypto world. In August, some of its development team were charged with helping hackers launder over $1 billion, including from entities tied to North Korea. Volume on the privacy protocol is down 90% after the arrests and subsequent sanctions.

The price of the Unibot token is down nearly 25% to just over $42. The price of the token peaked in mid-August at almost $220. The protocol, at its peak, generated a significant amount of revenue, thus attracting the interest of investors.

This is the latest exploit in the crypto world. Last week, LastPass users lost $4.4 million worth of crypto.

According to data spotted by Lookonchain, the attacker’s wallet now has just over $630,000 in crypto assets, with the majority being in ether (ETH) followed by USDC.

UPDATE (Oct. 31, 08:20 UTC): Adds details from Peckshield, updates headline.

Edited by Parikshit Mishra.

Disclosure

Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. In November 2023, CoinDesk was acquired by the Bullish group, owner of Bullish, a regulated, digital assets exchange. The Bullish group is majority-owned by Block.one; both companies have interests in a variety of blockchain and digital asset businesses and significant holdings of digital assets, including bitcoin. CoinDesk operates as an independent subsidiary with an editorial committee to protect journalistic independence. CoinDesk employees, including journalists, may receive options in the Bullish group as part of their compensation.


Learn more about Consensus 2024, CoinDesk's longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.



Read more about