Share this article

Harmony Horizon Exploit Linked to North Korea, $10M Bounty Offered

The blockchain's develops now have a "global manhunt" to track down the attackers.

Updated May 11, 2023, 6:42 p.m. Published Jun 30, 2022, 10:15 a.m.
(boonchai wedmakawand/Getty Images)
(boonchai wedmakawand/Getty Images)

Harmony developers said Thursday they had started a “global manhunt” to catch the culprits behind last week’s $100 million exploit of its Horizon bridge, according to a Thursday update.

The exploited "Horizon" bridge allowed users to exchange assets such as tokens, stablecoins and non-fungible tokens (NFTs), among the Ethereum, Binance Smart Chain and Harmony blockchains.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

A bounty offered to individuals who could provide information about the attacker to Harmony was increased to $10 million from the previous $1 million. The ETH address to return the funds is 0xd6ddd996b2d5b7db22306654fd548ba2a58693ac.

Harmony team has also offered “one final opportunity” for the attackers to return the assets with anonymity: “The final term is they retain $10 million and return the remaining amount, in addition to the team ceasing the investigation.”

Meanwhile, security firm Elliptic linked the attack to North Korean hacker group Lazarus in a release Wednesday.

“There are strong indications that North Korea’s Lazarus Group may be responsible for this theft,” Elliptic researchers said. “Based on the nature of the hack and the subsequent laundering of the stolen funds.”

Elliptic noted that the movement of stolen funds occurred mostly during Asia-Pacific nighttime hours and that the attack used techniques that were “frequently used” by the Lazarus Group.

Lazarus is believed to have stolen over $2 billion in crypto assets from exchanges and decentralized finance (DeFi) platforms, Elliptic said. It added that the Horizon Bridge hacker has so far sent 41% of the $100 million in stolen crypto assets into the Tornado Cash mixer.

Earlier this week, the attackers transferred over 36,000 ether, worth $44 million at the time, to Tornado Cash over several transactions, as reported.

The attacker’s main wallet – tagged as “Horizon Bridge Exploiter” on blockchain tracing service Etherscan – continues to hold over 33,000 stolen ethers, blockchain data shows.

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

Solana’s Drift Launches v3, With 10x Faster Trades

Drift (b52_Tresa/Pixabay)

With v3, the team says that about 85% of market orders will fill in under half a second, and liquidity will deepen enough to bring slippage on larger trades down to around 0.02%.

What to know:

  • Drift, one of the largest perpetuals trading platforms on Solana, has launched Drift v3, a major upgrade meant to make on-chain trading feel as fast and smooth as using a centralized exchange.
  • The new version will deliver 10-times faster trade execution thanks to a rebuilt backend, marking the largest performance jump the project has made so far.