Justice Department Launches Criminal Probe Into $400M FTX Hack: Bloomberg

Experts have suggested the digital fingerprints left by the alleged hacker points to an inside job.

AccessTimeIconDec 27, 2022 at 6:12 p.m. UTC
Updated Dec 27, 2022 at 9:53 p.m. UTC

The U.S. Department of Justice has reportedly launched a criminal probe into the alleged hack that drained nearly $400 million out of FTX-controlled wallets the night the Bahamas-based exchange filed for bankruptcy.

Bloomberg first reported the news on Tuesday, citing persons familiar with the case.

Between Nov. 11 and the early hours of Nov. 12, massive outflows of cryptocurrencies began moving out of FTX and FTX US’s wallets. Multiple FTX employees told Twitter sleuth ZachXBT that they didn't recognize the transfers.

Over an hour after the suspected hack began, FTX General Counsel Ryne Miller tweeted that his company was “investigating abnormalities with wallet movements” and later pinned a message in FTX’s official Telegram support channel: “FTX has been hacked. FTX apps are malware. Delete them. Chat is open. Don’t go on FTX site as it might download Trojans.”

The official FTX Twitter account remained silent throughout the pandemonium. In the afternoon of Nov. 12, FTX CEO John Jay Ray III confirmed the hack through a statement posted via Miller’s Twitter account, and said they were in contact with law enforcement.

The criminal investigation is separate from the fraud case against disgraced former CEO Sam Bankman-Fried, according to the Bloomberg report, which also said authorities have been able to freeze a portion of the stolen funds.

Blockchain experts have pointed to several clues that the hacker was an FTX insider, including the simultaneous hacks of the FTX and FTX US websites, the suspect’s access to multiple cold wallets and the use of a personal Kraken account to withdraw gas fees for at least one transaction.


Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. In November 2023, CoinDesk was acquired by the Bullish group, owner of Bullish, a regulated, digital assets exchange. The Bullish group is majority-owned by Block.one; both companies have interests in a variety of blockchain and digital asset businesses and significant holdings of digital assets, including bitcoin. CoinDesk operates as an independent subsidiary with an editorial committee to protect journalistic independence. CoinDesk employees, including journalists, may receive options in the Bullish group as part of their compensation.

Cheyenne Ligon

Cheyenne Ligon is a CoinDesk news reporter with a focus on crypto regulation and policy. She has no significant crypto holdings.