Skip to content

Commit

Permalink
Create 2024-02-23-BirForex.md (#380)
Browse files Browse the repository at this point in the history
* Create 2024-02-23-BirForex.md

* Update and rename 2024-02-23-BirForex.md to 2024-02-23-BitForex.md

Name and timeline fix

* Update 2024-02-23-BitForex.md

* Update 2024-02-23-BitForex.md

* Update 2024-02-23-BitForex.md

* Update 2024-02-23-BitForex.md

* Update 2024-02-23-BitForex.md

---------

Co-authored-by: Evgeny Dmitriev <[email protected]>
  • Loading branch information
svg-arch and evgenydmitriev authored Apr 8, 2024
1 parent a432ff1 commit 76a85cb
Showing 1 changed file with 55 additions and 0 deletions.
55 changes: 55 additions & 0 deletions content/attacks/posts/2024-02-23-BitForex.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
---
date: 2024-02-23
target-entities: BitForex
entity-types:
- Exchange
- Custodian
attack-types:
- Scam
title: "BitForex's Exit Scam Leads to $56.5 Million in Financial Losses."
loss: 56500000
---

## Summary

Since February 23, 2024, BitForex, a crypto exchange operational since 2017, ceased processing withdrawals amidst unexplained outflows of about $56.5M worth of crypto from its hot wallets. The absence of communication from BitForex, coupled with the recent departure of its CEO Jason Luo, has raised concerns over a potential inside job or exit scam.

## Attackers

The identity of the scammers is unknown, but the main suspect is the CEO of the exchange, Jason Luo. The nature of the outflows and a significant delay in response from BitForex, suggests this may not be a straightforward hack. Initial transactions, such as the test transaction of 0.01 $ETH, followed by 58-hour inactivity, indicate a controlled extraction of funds rather than a grab-and-run attack.

The following addresses are associated with the scam:

- Ethereum Wallet:
- [0xdcacd7eb6692b816b6957f8898c1c4b63d1fc01f](https://etherscan.io/address/0xdcacd7eb6692b816b6957f8898c1c4b63d1fc01f)

- Tron Wallet:
- [TQcnqaU4NDTR86eA4FZneeKfJMiQi7i76o](https://tronscan.org/#/address/TQcnqaU4NDTR86eA4FZneeKfJMiQi7i76o)

- Bitcoin Wallet:
- [3DbbF7yxCR7ni94ANrRkfV12rJoxrmo1o2](https://www.blockchain.com/explorer/addresses/btc/3DbbF7yxCR7ni94ANrRkfV12rJoxrmo1o2)

## Losses

The total loss from the BitForex scam amounted to approximately [$56.5 million](https://twitter.com/zachxbt/status/1762028433574650347), distributed across the following networks:

- Ethereum:
- 471,414 TRB (54,200,000 USD)
- 148 ETH (444,000 USD)
- 258,700 USDC
- 40,771 USDT

- Tron
- 657,698 USDT
- 44,000 TRX (6072 USD)

- Bitcoin
- 5.7 BTC (290,000 USD)

## Timeline

- **January 31, 2024, 02:07 PM UTC:** Exchange CEO Jason Luo [steps down](https://support.bitforex.com/hc/en-us/articles/28260960127385-Jason-Stepped-Down-as-CEO-of-BitForex).
- **February 21, 2024, 08:16 AM UTC:** The [first malicious](https://etherscan.io/tx/0xee8a0e425670b53e5066451362324fb6ef36fb5507a525567fc8c9b68a03709f) transaction occurred.
- **February 23, 2024:** [The exchange website was closed.](https://decrypt.co/219012/exit-scam-bitforex-shutters-after-57-million-withdrawn)
- **February 26, 2024:** 0xScope [published](https://www.0xscope.com/blog-posts/hack-or-exit-scam-what-happened-at-bitforex) an analysis of the incident.
- **March 4, 2024:** Hong Kong’s regulator for securities and futures markets has [warned](https://www.sfc.hk/en/alert-list/3010) the public about BitForex for suspected fraud.

0 comments on commit 76a85cb

Please sign in to comment.