Justice Department Launches Criminal Probe Into $400M FTX Hack: Bloomberg

Experts have suggested the digital fingerprints left by the alleged hacker points to an inside job.

AccessTimeIconDec 27, 2022 at 6:12 p.m. UTC
Updated Dec 27, 2022 at 9:53 p.m. UTC
Consensus 2023 Logo
Join the most important conversation in crypto and Web3 taking place in Austin, Texas, April 26-28.

Cheyenne Ligon is a CoinDesk news reporter with a focus on crypto regulation and policy. She has no significant crypto holdings.

Consensus 2023 Logo
Join the most important conversation in crypto and Web3 taking place in Austin, Texas, April 26-28.

The U.S. Department of Justice has reportedly launched a criminal probe into the alleged hack that drained nearly $400 million out of FTX-controlled wallets the night the Bahamas-based exchange filed for bankruptcy.

Bloomberg first reported the news on Tuesday, citing persons familiar with the case.

Between Nov. 11 and the early hours of Nov. 12, massive outflows of cryptocurrencies began moving out of FTX and FTX US’s wallets. Multiple FTX employees told Twitter sleuth ZachXBT that they didn't recognize the transfers.

Over an hour after the suspected hack began, FTX General Counsel Ryne Miller tweeted that his company was “investigating abnormalities with wallet movements” and later pinned a message in FTX’s official Telegram support channel: “FTX has been hacked. FTX apps are malware. Delete them. Chat is open. Don’t go on FTX site as it might download Trojans.”

The official FTX Twitter account remained silent throughout the pandemonium. In the afternoon of Nov. 12, FTX CEO John Jay Ray III confirmed the hack through a statement posted via Miller’s Twitter account, and said they were in contact with law enforcement.

The criminal investigation is separate from the fraud case against disgraced former CEO Sam Bankman-Fried, according to the Bloomberg report, which also said authorities have been able to freeze a portion of the stolen funds.

Blockchain experts have pointed to several clues that the hacker was an FTX insider, including the simultaneous hacks of the FTX and FTX US websites, the suspect’s access to multiple cold wallets and the use of a personal Kraken account to withdraw gas fees for at least one transaction.

DISCLOSURE

Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

The leader in news and information on cryptocurrency, digital assets and the future of money, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups. As part of their compensation, certain CoinDesk employees, including editorial employees, may receive exposure to DCG equity in the form of stock appreciation rights, which vest over a multi-year period. CoinDesk journalists are not allowed to purchase stock outright in DCG.

CoinDesk - Unknown

Cheyenne Ligon is a CoinDesk news reporter with a focus on crypto regulation and policy. She has no significant crypto holdings.


Learn more about Consensus 2023, CoinDesk’s longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.


CoinDesk - Unknown

Cheyenne Ligon is a CoinDesk news reporter with a focus on crypto regulation and policy. She has no significant crypto holdings.