Crypto privacy software refuses money stolen in $9.5m hack
A hacker tried to quietly move almost $10 million in stolen crypto. This privacy service didn’t let him.
Software that conceals the flow of crypto is a standard part of hackers’ toolkit, allowing them to sell stolen assets unnoticed.
That software just thwarted a hacker.
Privacy protocol Railgun reverted a Thursday transaction in which a hacker attempted to move almost $10 million in stolen crypto, according to blockchain records.
It’s perhaps the first real-world victory for technology built to satisfy two diametrically opposed parties: the regulators and law enforcement agencies alarmed by cybercriminals’ growing use of crypto, and the privacy-obsessed cypherpunks who created the first cryptocurrencies and were their earliest users.
That technology was first detailed in a 2023 paper authored by Ethereum co-founder Vitalik Buterin and several other researchers.
Privacy enhancing software has been controversial in crypto. Proponents have long argued that blockchains need privacy if they’re going to become the backbone of a new financial system — nobody will transact entirely “onchain” if doing so has the potential to reveal their entire financial history.
But privacy protocols have proven popular with cybercriminals, including hackers with ties to North Korea and its nuclear weapons programme. The US has sanctioned crypto “mixer” Tornado Cash and charged one of its developers with money laundering and sanctions evasion, a case that has the potential to dramatically chill development of privacy-preserving software, according to industry groups.
ZkLend, a lending-and-borrowing protocol on the Starkware blockchain, suffered a $9.5 million hack Thursday, according to crypto security experts. The hacker transferred the crypto to the Ethereum blockchain, and then attempted to transfer it again using Railgun, a protocol that allows users to break the chain of traceability between blockchain transactions.
That would have allowed the hacker to continue moving the stolen crypto across the blockchain or to transfer it to an exchange unnoticed, where it could be exchanged for cash.
Instead, Railgun functionally refused the hacker’s request.
That’s because it uses a version of the technology detailed in Buterin’s 2023 paper.
That technology lets honest users create a cryptographic proof showing their money — the origin of which is otherwise kept secret — didn’t come from wallets associated with stolen funds or other illicit activity.
“And if they are [ill-gotten], the only action the bad actor can perform is to send back to their originating address,” Alan Scott, co-founder of the Railgun project, told DL News.
Pseudonymous crypto security expert Officer’s Notes called it a solution that struck a “perfect balance.”
“It will avoid unnecessary attention and regulatory pressure while respecting the basic principles of privacy,” he told DL News.
“After all, it wasn’t Railgun itself that sent the money to the hacker. It was the hacker who could not use the service and had to withdraw his money back.”
Aleks Gilbert is DL News’ New York-based DeFi reporter. You can reach him at aleks@dlnews.com.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Florida teens arrested in connection with a kidnapping and theft of $4M in crypto
Share link:In this post: Three Florida teens have been accused of kidnapping a man at gunpoint and forcing him to transfer $4 million worth of digital assets to them. The teens kidnapped the victim from Las Vegas and threatened to kill him and his father if he didn’t cooperate. Law enforcement agencies across the globe are now warning individuals with substantial crypto holdings to be cautious amid a rise in kidnappings.
UK icons slam AI ‘theft’ in fiery plea to Starmer before key vote
Share link:In this post: Over 400 UK artists urged PM, Keir Starmer, to strengthen copyright laws ahead of an AI legislation vote. UK government’s proposed “opt-out” rule for AI training on copyrighted content faces strong backlash. Hayao Miyazaki and others condemn AI-generated art, fueling copyright debates and legal challenges.
Americans have wiped out $3 trillion in savings in the past 3 years, mostly from stimulus checks
Share link:In this post: Americans have drained $3 trillion in savings since 2021, with excess savings now at negative $900 billion. The US savings rate dropped to 3.9% in March, below pre-pandemic levels of 5-6%. Consumer spending rose 0.7% in March, but GDP still shrank by 0.3% due to soaring imports.

Banking the unbanked, but this time for real?
Trending news
MoreCrypto prices
More








