Blockchain analytics firm Match Systems has identified an individual believed to be selling tokens associated with recent CoinEx and Stake hacks at discounted rates. These investigations reveal a pattern of cryptocurrency laundering operations, with stolen tokens being offered through peer-to-peer transfers.
A representative from Match Systems revealed exclusively to Cointelegraph that their investigations into several major breaches during the summer of 2023 have led them to an individual allegedly involved in the sale of stolen cryptocurrency tokens. The investigators successfully identified and contacted this individual on Telegram, who was in control of an address containing over $6 million worth of cryptocurrencies.

The exchange of stolen assets was facilitated through a Telegram bot, which offered a 3% discount off the token’s market price. Following initial conversations, the individual reported that the initial assets had been sold, with new tokens becoming available in approximately three weeks. It is believed that these funds are connected to the CoinEx or Stake hacks.
While the Match Systems team has not fully identified the individual, they have narrowed down their location to a European time zone based on received screenshots and conversation timings. It is speculated that this individual is not part of the core hacking team but is somehow associated with them, potentially having been de-anonymized to ensure responsible handling of the stolen assets.
The individual displayed erratic behavior during interactions, abruptly leaving conversations with excuses like “Sorry, I must go; my mom is calling me to dinner.” Typically, a 3% discount was offered, with 3.14 TRX sent as proof to potential clients during the initial identification.
Blockchain security firm CertiK previously detailed the movement of stolen funds from the Stake hack, with approximately $4.8 million of the total $41 million being laundered through various token transfers and cross-chain swaps.
The United States Federal Bureau of Investigation attributed the Stake attack to North Korean Lazarus Group hackers, while cybersecurity firm SlowMist linked the $55 million CoinEx hack to the same group. However, Match Systems’ analysis suggests slight differences in the methods used in these two hacks.
Their findings indicate that earlier Lazarus Group laundering efforts did not involve Commonwealth of Independent States nations such as Russia and Ukraine, whereas the 2023 summer hacks saw stolen funds actively laundered in these jurisdictions. Moreover, recent incidents have left more digital traces for investigators to follow. Social engineering was identified as a significant attack vector in the summer hacks, whereas the Lazarus Group targeted “mathematical vulnerabilities.”
The firm also noted that Lazarus hackers typically used Tornado Cash for laundering stolen cryptocurrency, whereas recent incidents have seen funds mixed through protocols like Sinbad and Wasabi. These hacks predominantly utilized BTC wallets as the primary repository for stolen assets, alongside the Avalanche Bridge and mixers for token laundering.
As of mid-September, North Korea-linked groups had pilfered a total of $340.4 million in cryptocurrency in 2023, according to Chainalysis.