FTX 'Hacker' Moved 15K ETH This Weekend

The moving funds, coming soon before FTX founder and former chief executive Sam Bankman-Fried goes on trial, deepens one of the ongoing mysteries around the exchange's collapse last year.

AccessTimeIconOct 2, 2023 at 7:47 a.m. UTC
Updated Oct 2, 2023 at 8:04 p.m. UTC
10 Years of Decentralizing the Future
May 29-31, 2024 - Austin, TexasThe biggest and most established global hub for everything crypto, blockchain and Web3.Register Now

All 15,000 ether (ETH) sitting in a wallet associated with last year's $600 million attack on FTX's wallets have now moved through privacy tools and bridges.

In November 2022, hours after FTX and its related companies filed for bankruptcy, an unknown party managed to drain various wallets of as much as $600 million. About $26 million worth of ETH – 15,000 ether – sat in a single wallet until earlier this weekend, when a first tranche of 2,500 ETH ($4 million) began moving, ultimately ending up at the Thorchain bridge, the Railgun privacy wallet, or intermediary addresses.

The remainder of these funds have now moved, with many of them similarly landing up at the Thorchain router. Some of these funds also went to a contract labeled "Metamask: Swap Router."

Railgun is a privacy wallet that lets users store tokens and use funds for decentralized financial services, such as lending and borrowing. These transactions are shielded, meaning the exact use of such funds is not known. On the other hand, Thorchain is a bridge that lets users freely swap tokens between different blockchains without the fear of getting their transfers blocked.

As such, addresses associated with the exploit may have moved over $32 million worth of ether using THORChain, as per estimates.

ftx exploiter flow chart by brad keoun

The moving funds, coming soon before FTX founder and former chief executive Sam Bankman-Fried goes on trial, deepens one of the ongoing mysteries around the exchange's collapse last year. The identity of the party or parties behind the attack was never identified.

After the exploit, several addresses amassed various tokens, such as ETH and the dai (DAI) stablecoin, and swapped it all into 37,000 ether. The address held more than 288,000 ether at peak and was once the 35th-largest owner of the cryptocurrency, as previously reported.

Bankman-Fried was charged with two counts of wire fraud and five counts of conspiracy to commit various forms of fraud by federal prosecutors last year, weeks after stepping down from his role at FTX. He resigned the same day FTX filed for bankruptcy.

With reporting by Bradley Keoun.

Edited by Oliver Knight.


Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. In November 2023, CoinDesk was acquired by the Bullish group, owner of Bullish, a regulated, digital assets exchange. The Bullish group is majority-owned by Block.one; both companies have interests in a variety of blockchain and digital asset businesses and significant holdings of digital assets, including bitcoin. CoinDesk operates as an independent subsidiary with an editorial committee to protect journalistic independence. CoinDesk employees, including journalists, may receive options in the Bullish group as part of their compensation.

Nikhilesh De

Nikhilesh De is CoinDesk's managing editor for global policy and regulation. He owns marginal amounts of bitcoin and ether.

Shaurya Malwa

Shaurya is the Deputy Managing Editor for the Data & Tokens team, focusing on decentralized finance, markets, on-chain data, and governance across all major and minor blockchains.

Learn more about Consensus 2024, CoinDesk's longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.