A well-known crypto analyst ZachXBT has made a noteworthy discovery concerning the crypto hacks targeting the crypto exchanges Bybit as well as Phemex. As per ZachXBT, Lazarus Group, a notorious North Korean group of hackers, has been engaged in the Phemex and Bybit’s recent breaches. The analyst provided comprehensive evidence concerning these exploits and the clear role of Lazarus Group in these incidents.
ZachXBT Provides Evidence on Lazarus Group’s Involvement in Bybit and Phemex Hacks
In an X thread, ZachXBT provided the data highlighting the sophisticated methods that Lazarus Group utilized for these hacks. Based on the on-chain data, the funds from Phemex and Bybit were commingled via a sole overlapping address. This reportedly indicates that the hackers exercised skillful approaches to perform both the exploits. On the 22nd of this month, Bybit experienced a high-profile exploit involving several transfers.
ZachXBT disclosed 0x411374feedcfa560335f00c0fcfa0a3906fdcc33687e6f924dd78ebecc45cd00 and 0xc963e65b9ec39b11076f78990c31f29aaa80705c75312dafd1748479e3e94ed0 as the 2 crucial transfer hashes. The respective transfer hashes point toward the initial theft. Similarly convincing, the Phemex exploit on the 20th of this month, took into account a transfer “0x6262a3339842240aeebae4ebfe338dbc771aa0e2df8f5a1ebcd7f9b090bedfe3.” It shared the path of same funds via the covering address “0x33d057af74779925c4b2e720a820387cb89f8f65.”
The crypto analyst further backed his findings with a joint research that he and Josh (his colleague from CF) had conducted formerly. It identified that Bybit’s testing addresses associated with laundering activities on Tron were particularly connected to the Phemex exploit. This discovery provided critical additional indicators concerning a coordinated illegal activity.
Investigative Community Acknowledges ZachXBT’s Research
The investigative community recognized the brilliant worth of both the analysts as the cybersecurity platform Arkham established a bounty for them. Arkham confirmed the landmark research that ZachXBT submitted, including the thorough evidence like analysis of test transfers and linked wallets, detailed timing data, and forensic graphs. The Bybit team also received the submission to get assistance in the current investigation into the exploit.
Arkham Establishes a Bounty Initiative of 50K to Identify Culprit Behind Attack
ZachXBT also attached Arkham’s announcement of an exclusive bounty initiative that offers an enormous reward of up to 50K $ARKM. The initiative invites submissions for help in detecting organizations or individuals at the back of the attack. The investigation into these cyber heists underscores the evolving and intricate methods that state-sponsored exploiters like Lazarus Group utilize for intrusion into the crypto landscape.


