Share this article

Hacker Steals $27M in Tether From Wallet Linked to Binance Deployer

The funds were then bridged to bitcoin on the THORChain bridge.

Updated Nov 13, 2023, 2:45 p.m. Published Nov 13, 2023, 1:20 p.m. 1 min read
$27 million stolen from hot wallet (Mika Baumeister/Unsplash)

A hacker stole $27 million worth of tether [USDT] from a wallet linked to the Binance deployer over the weekend, according to blockchain analyst ZachXBT.

The $27 million loot was converted to ether [ETH] before being sent to exchanges FixedFloat and ChangeNow. All funds were then bridged to bitcoin [BTC] via the THORChain bridge.

According to on-chain data, the victim's wallet had received ether via two separate wallets from the Binance deployer in 2019.

"The user made a withdrawal from Binance, which was valid and authorized on our platform. Unfortunately, the DeFi wallet that received the withdrawal was compromised. While this is outside of our scope of control, Binance's security team is looking into the matter and we will provide assistance where we can," a Binance spokesperson told CoinDesk.

A deployer wallet is a wallet used to create smart contracts. Binance's deployer wallet has been inactive since December, 2020.

THORChain has become an epicenter for hack-related activity over the course of the year – in June hackers that stole $35 million from Atomic Wallet used THORChain to conceal the ill-gotten gains, and last month THORSwap put its platform into maintenance mode after a series of FTX hack-related trades.

Exchanges are often the target of hackers. Last week Poloniex lost $114 million after a hack breached that exchange's hot wallets.

UPDATE (November 13, 2023, 14:45 UTC): Adds comment from Binance spokesperson.

More For You

CertiK's Ronghui Gu (Ronghui Gu for CoinDesk)

CertiK CEO and co-founder Ronghui Gu says April was the worst month for DeFi in four years with exploits on 27 out of 30 days.

What to know:

  • Traditional financial institutions are interested in moving trillions of dollars of assets onchain over the next decade but are deterred by pervasive security risks.
  • CertiK CEO Ronghui Gu says near-daily hacks—many accelerated by AI and targeting smart contracts, oracles and cross-chain bridges—are a major barrier to large-scale institutional adoption.
  • Recent...