FTX被盗资产去向分析:黑客疯狂洗钱

知帆科技Published on 2022-11-23Last updated on 2022-11-24

Abstract

当地时间 11 月 12 日,据外媒报道,加密货币交易所 FTX 在其 Telegram 频道宣布遭到黑客攻击,加密钱包中被盗资金超过 6 亿美元。

当地时间 11 月 12 日,据外媒报道,加密货币交易所 FTX 在其 Telegram 频道宣布遭到黑客攻击,加密钱包中被盗资金超过 6 亿美元。

事件回顾

11 月 12 日午间, FTX 疑似被黑客攻击。链上记录显示,FTX 与 FTX US 的大量交易所资产开始归集到同一个链上地址——0x59abf3837fa962d6853b4cc0a19513aa031fd32b。

多个项目方提醒用户存在信息泄漏的可能性,建议卸载 FTX App,请勿下载新版 FTX 或进行版本更新。

此外,FTX Telegram 管理员 Rey 表示 FTX 遭黑客攻击,并提示不要访问 FTX 网站,因为它可能会下载木马病毒。

FTX US 法律总顾问 Ryne Miller 回应称,正在调查与跨交易所合并 FTX 余额相关的钱包异动情况,会尽快分享更多信息。

图片

一直追踪本次事件的推特用户 Autism Capital 则给出了更为耸人听闻的猜想:黑客子虚乌有,系内部人员卷款潜逃。

资金流向

黑客地址 0x59ab...d32b 同时对 FTX 在以太坊和币安链上的资产进行转移。使用虚拟货币追踪查证平台逐迹的通用工具查询,该黑客的 ETH 地址持有 20 万枚 ETH。

此外,黑客在币安链地址上持有 74041 个 BNB,1685309 个 DAI。

黑客的资金中转地址如下:

0x585ed783c9246553e8bc9f9046c80f54afee7765

0xb7e3d0fe8349c980a7a93e8378ec6d728970bd52

0x2cb356d17ce28135d593795de6a398f2b997a69f

0xadb8ddf11607fc5faf1d6b50beed9f6c3577203e

0x23a43cf429ec32ebca4624e2182a799141425556

0xc40abf7e6499694ea6f965df96e39e51305e019a

0x29bd06bfb1b52bdae3190f7151ec0367b745b67f

0x961baeb17b99da67daba6de02933fa0195cb425e

0xd73ac858a9b5a83792d2a5e56fb755273620fe73

0x866eeecd1f248d1a0a2e0263f13594a6b8b7c01a

0x60478ad54604f63fe1e46dcee72a7f6463a08f77

资金来源

1、多种资产发生转移

以太坊链的 FTX 地址:

0x2faf487a4414fe77e2327f0bf4ae2a264a776ad2

以太坊链的 FTX US 地址:

0x7abe0ce388281d2acf297cb089caef3819b13448

以太坊链的 FTX 地址以及 FTX US 地址,向黑客地址 0x59ab...d32b 转移资产,共转移了ETH、USDT、UNI、stETH、1INCH、WBTC、SUSHI、YFI、LDO、LINK、MATIC、AAVE、SHIB、APE、PAXG、cUSDT、SNX、USDP、DAI 十九个币种。

币安链上的 FTX 地址也同时被转移转移资产到黑客地址 0x59ab...d32b,转移了BNB、BSC-USDT、BSC-ETH、BSC-DAI 四种币种。

AVAX 链黑客地址 0x59ab...d32b 同时转入 USDT。

2、被转移资金汇总

根据链上交易可知,FTX 地址被转移资产金额 4 余亿美元:以太坊链上被转移资产达 2.88 亿美元,币安链上被转移资产 1 亿美元,AVAX 链被转移 397 万美元。

3、多种手法兑换资产

黑客转移完资产后将以太坊链上的所有代币通过去1inch、Compound、Curve、Uniswap 等去中心化交易所兑换为 ETH,并且滑点极高。币安的一部分的资产利用跨链桥进行跨链转移到了以太坊上,并且中间利用多个地址进行资产兑换。

4、代币兑换汇总

通过链上交易可以发现,被盗资产的变现十分着急,并且滑点极高。变现资金中折损金额达 5900 万美元,除此之外,还向 0x866e...c01a 地址转移了 50000 枚 ETH,在该地址将 ETH 兑换为 rBTC,并进行跨链资金转移。以太坊链持有以太坊 20 万,PAXG 持有 8184 枚,币安链 BNB 持有 44288.94 枚,DAI 持有 1685309.12 枚,AVAX 持有 397 万枚 USDT。

事件汇总

此次的 FTX 被盗案件的资金变现可以看出黑客的变现匆忙,为了防止各种代币被冻结没收,低价出手砸盘,不惜高滑点。现在该黑客地址持有的以太坊量成为了第三大以太坊持有量钱包。

结合近期 SBF 的一系列“操作”和坊间传闻,人们对此次黑客事件尚存疑虑,幕后真相也变得扑朔迷离。目前平台已经对这起黑客事件进行调查,知帆安全团队也会持续关注此事。

最后,可以肯定的是,随着 FTX 事件影响的扩大,势必会引起全球对加密行业监管的进一步重视。

Related Reads

Critical Game Week: BTC Retracement Confirmation vs. HYPE Support Battle | Guest Analysis

This weekly analysis outlines a critical juncture for BTC and HYPE markets, focusing on key price level confirmations. **BTC Analysis:** BTC is at a pivotal point after a five-wave rally from the June 5th low of $59,100. The price has broken below a short-term rising channel's lower boundary, with the current move seen as a pullback to test this breakdown. Failure to reclaim this level could lead to a retest of the $59,000-$60,000 support zone. The core scenario hinges on this channel retest outcome. * **Key Levels:** Resistance at $64,500-$65,000 (channel boundary) and $69,500-$70,500. Support at $59,000-$60,000 and $55,000. * **Strategy:** A core bearish stance is maintained (20% short from last week), with short-term plans for tactical trades. Three detailed contingency plans (A/B/C) are provided for short positions on resistance tests or breakdowns, emphasizing strict stop-loss discipline. **HYPE Analysis:** HYPE shows strong momentum but is currently in a corrective phase after hitting a new high of $76.94. The price is retesting the crucial $64-$66 support area. * **Key Levels:** Resistance near $77 and $80-$82. Support at $64-$66 and $52-$54. * **Strategy:** The short-term approach is "buy on dips, avoid chasing rallies." A long position is considered only if clear stabilization signals appear at the $64-$66 or deeper $52-$54 support zones, with tight risk controls. **General Risk Management:** A standardized trailing stop-loss protocol is emphasized: set initial stop, breakeven at +1% profit, then trail stops upward to lock in gains. *Disclaimer: All analysis is presented as a personal trading framework, not investment advice. Market conditions are complex and require dynamic adjustment.*

marsbit14m ago

Critical Game Week: BTC Retracement Confirmation vs. HYPE Support Battle | Guest Analysis

marsbit14m ago

Research Report Interpretation: Citi Attends AWS Summit, Bullish on Cloud Business Acceleration but Data Governance Remains Key Variable

Citi analyst Tyler Radke's team attended the AWS New York Summit (June 17-18), engaging with over 10 clients and partners. In a June 19 report, they highlighted the summit's focus on scaling agent AI for enterprise deployment. Citi maintains a "Buy" rating on Amazon, forecasting AWS revenue growth to accelerate to 37% in FY27 from 30% in FY26, noting this estimate may be conservative. Key takeaways: 1. **AWS Strategy Shift:** AWS is moving from proof-of-concepts to scalable deployment. New offerings like AWS Context (building enterprise knowledge graphs), Amazon Quick (cross-application AI assistant), and security tool Continuum address core enterprise pain points for AI adoption. 2. **Data Infrastructure Beneficiaries:** Data infrastructure companies like Snowflake, Elastic, Oracle, and ClickHouse are seen as direct beneficiaries of scaling AI workloads, as evidenced by strong growth and use cases presented. 3. **Critical Role of Data Governance:** As AI agents scale from hundreds to thousands, effective data governance becomes the key variable for deploying AI in core business processes. AWS Context represents AWS's strategic extension from providing compute/models to offering a data governance infrastructure layer. The report emphasizes that without solving data governance, AI will remain confined to pilot projects. The investment thesis focuses on AWS revenue acceleration and data infrastructure vendors' growth, while monitoring signals like AWS's quarterly revenue growth, Bedrock AgentCore task volume, and pricing impacts on companies like Elastic.

marsbit20m ago

Research Report Interpretation: Citi Attends AWS Summit, Bullish on Cloud Business Acceleration but Data Governance Remains Key Variable

marsbit20m ago

Crucial Week of Contention: BTC Tests Support and HYPE's Key Level Battle | Special Analysis

**Market Enters Critical Week: Bitcoin Pullback Test and HYPE Support Battle** The market enters a crucial phase of contention this week. The marginal shifts in Federal Reserve policy expectations continue to dictate the pricing rhythm for risk assets. Meanwhile, in the crypto market, following a period of sideways consolidation, the divergence between bulls and bears is becoming concentrated at key price levels. **Bitcoin (BTC) Analysis & Strategy** * **Technical View:** The 4-hour chart suggests BTC is in a five-wave structure since the June 5th low near $59,100. Price action shows a short-term rising channel. The recent drop below this channel's lower boundary is now being followed by a pullback attempt (wave 40-41). The outcome of this retest is critical. * **This Week's Outlook:** The core focus is whether BTC can reclaim and hold above the channel's lower boundary. * **Bullish Scenario:** A successful hold could lead to a continued rebound, potentially challenging the $69,500 - $70,500 resistance zone. * **Bearish Scenario:** Failure to hold may trigger a renewed test of the $59,000 - $60,000 core support area, with $55,000 as a deeper support level. * **Operational Strategy:** The author maintains a 20% mid-term short position initiated last week near $64,500, based on a model signaling a shift to a bearish structure. Short-term tactics involve using 30% capital for potential "spread" trades, with three contingency plans (A, B, C) outlined for reacting to resistance tests, breakouts, or support breakdowns. **HYPE Analysis & Strategy** * **Technical View:** On the 4-hour chart, HYPE shows strong momentum, having recently broken to a new high since January. The current pullback presents a clear three-wave correction structure, bringing the price back to the critical $64 - $66 support zone. * **This Week's Outlook:** The focus is on the battle for the $64 - $66 support area. * **Bullish Scenario:** Holding this support could signal a continuation of the uptrend from the June 10th low, leading to new highs. * **Bearish Scenario:** A breakdown could extend the correction, potentially testing the deeper $52 - $54 support band. * **Operational Strategy:** The recommended short-term approach is "buy on dips, avoid chasing rallies." A light long position (under 30% capital) could be considered if HYPE shows stabilization signals at the $64-$66 or $52-$54 support zones, confirmed by model signals. Strict stop-loss discipline is emphasized. **General Risk Management:** A strict trailing stop-loss protocol is advised: set an initial stop; move to breakeven at +1% profit; lock in profits progressively thereafter. *Disclaimer: All analysis is presented as the author's personal technical perspective and trading log, not as investment advice. Markets are complex and dynamic; risk control is paramount.*

Odaily星球日报20m ago

Crucial Week of Contention: BTC Tests Support and HYPE's Key Level Battle | Special Analysis

Odaily星球日报20m ago

AI Agents Also Need 'Credit Checks': ERC-8126 is Filling the Gap in On-chain Trust

The article discusses ERC-8126, a proposed standard designed to address the lack of trust and verification for AI Agents operating on-chain. While ERC-8004 provides AI Agents with a basic on-chain identity (answering "Who are you?"), it does not guarantee trustworthiness. ERC-8126 aims to fill this gap by establishing a verification layer (answering "Are you reliable?"). It standardizes how independent verification providers can assess an agent's associated risks across five key areas: Token/Contract Verification (ETV), Media Content Verification (MCV), Solidity Code Verification (SCV), Web Application Verification (WAV), and Wallet Verification (WV). These providers generate a standardized risk score (0-100) and proofs based on their checks, without acting as a single authoritative certifier. This allows wallets, marketplaces, dApps, and other agents to consume these risk signals—for example, to display warnings, filter listings, or make interaction decisions. The standard also incorporates concepts like Private Data Verification (PDV) and Zero-Knowledge Proofs (ZKP) to allow verification without exposing sensitive underlying data. Positioned alongside ERC-8004 (Identity) and ERC-8183 (Commerce for agents), ERC-8126 represents a step toward building a verifiable and accountable infrastructure for the emerging on-chain AI Agent economy, shifting trust assessment from purely user-based judgment to standardized, consumable signals.

marsbit38m ago

AI Agents Also Need 'Credit Checks': ERC-8126 is Filling the Gap in On-chain Trust

marsbit38m ago

Rented Conviction: How Much Real Money Is Behind the Bitcoin ETF Flows

Borrowed Belief: How much of Bitcoin ETF flows are real money? Weekly Bitcoin ETF flows, often interpreted as a measure of institutional conviction, are heavily influenced by a hidden arbitrage trade rather than genuine directional buying. A cash-and-carry arbitrage, where traders buy the ETF while simultaneously shorting Bitcoin futures on the CME to lock in a basis spread (the price difference between futures and spot), drives roughly half of the week-to-week flow volatility. This delta-neutral activity appears as ETF inflows but is unrelated to price views. Data shows a strong correlation (0.70) between weekly ETF inflows and increases in hedge fund short positions on CME futures, while Bitcoin’s weekly price returns have almost no explanatory power. However, this arbitrage activity dominates short-term *fluctuations*, not the cumulative *stock* of investments. Of the total ~$55 billion in net ETF inflows since launch, only about $1 billion currently represents net arbitrage exposure. The vast majority consists of steady, directional buying averaging around $400 million per week. The arbitrage trade has been unwinding for two years, with hedge fund short positions peaking near $14 billion in late 2024 and declining to ~$4.5 billion. Recent ETF outflows partly reflect this ongoing unwind as the basis compresses, not a loss of faith in Bitcoin. Thus, ETF flows overstate the *volatility* of belief, not its *level*. The headline number is more a gauge of arbitrage desk activity than conviction. For accurate interpretation, monitor the CME basis relative to Treasury yields and hedge fund net shorts—these reveal how much of the reported “demand” is truly directional.

marsbit41m ago

Rented Conviction: How Much Real Money Is Behind the Bitcoin ETF Flows

marsbit41m ago

Trading

Spot
Futures
活动图片