Skip to content

Hackers steal $200 million from five crypto exchanges

CryptoCore hackers steal $200M from crypto exchanges using spear-phishing

On June 24, reports emerged that one hacker group has managed to steal $200 million in cryptocurrency from exchanges. It used “spear-phishing” attacks to gain access to these crypto exchanges, which proved to be effective.

The group is known as ‘CryptoCore’ allegedly operated out of Eastern Europe targeting exchanges since 2018, based on ClearSky cyber-security firm’s reports. These criminals targeted exchanges in Japan and the United States.

Although these cyber-criminals have stolen over $200 million within two years, experts believe:

“the group is not extremely technically advanced. Instead, it is swift, persistent, and effective.”

They use that strategy to steal from unsuspecting individuals quickly which accounts for their massive success rate.

How they operate

This CryptoCore gang accesses crypto wallets that are owned by employees and exchanges. The hackers start with an extensive reconnaissance phase against the company and its workers.

Then, they find their way to using spear-phishing attacks. These attacks consist of emailing an executive from an account that appears like a bona fide high-ranking employee. They pose as they work from the same company or from an organization that they partner with.

After the network is compromised, the cybercriminals install malware and access the executive’s password manager accounts. The manager accounts are the places where all the crypto wallet keys are kept.

The gang waits, and should a multi-factor authentication be removed; they pounce immediately and responsively. At that moment, these thieves drain funds from the wallets. Expert reports state that:

“Activity receded in the first half of 2020, one possible reason being the limitations induced by the COVID-19 pandemic.” But it “didn’t stop completely.”  

Spear-phishing has become a common strategy used by hackers, and it has become a significant problem. A mega spear-phishing campaign was launched against YouTubers at the start of this year. Accounts with many subscribers got hijacked when the owners opened dodgy links.

After gaining entrance, hackers changed passwords and deleted all the videos. They then ran single live streams featuring an interview with celebrities like digital assets exchange Binance’s CEO Changpeng Zhao or Tesla’s Elon Musk.

The phony celebrities requested their viewers to send them crypto funds promising to send even more back. That was a scam, but it was successful. One major Musk scam stole $2 million in two months. But, the crypto exchanges were hit much worse.

Best Crypto Exchange for Intermediate Traders and Investors

  • Invest in 70+ cryptocurrencies and 3,000+ other assets including stocks and precious metals.

  • 0% commission on stocks - buy in bulk or just a fraction from as little as $10. Other fees apply. For more information, visit etoro.com/trading/fees.

  • Copy top-performing traders in real time, automatically.

  • eToro USA is registered with FINRA for securities trading.

30+ million Users
Securities trading offered by eToro USA Securities, Inc. (“the BD”), member of FINRA and SIPC. Cryptocurrency offered by eToro USA LLC (“the MSB”) (NMLS: 1769299) and is not FDIC or SIPC insured. Investing involves risk, and content is provided for educational purposes only, does not imply a recommendation, and is not a guarantee of future performance. Finbold.com is not an affiliate and may be compensated if you access certain products or services offered by the MSB and/or the BD

Read Next:

Finance Digest

By subscribing you agree with Finbold T&C’s & Privacy Policy

Related posts

Disclaimer: The information on this website is for general informational and educational purposes only and does not constitute financial, legal, tax, or investment advice. This site does not make any financial promotions, and all content is strictly informational. By using this site, you agree to our full disclaimer and terms of use. For more information, please read our complete Global Disclaimer.