{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-phishing-of-a-harmony-developer-preceded-the-100m-horizon-bridge-theft"},"incident":{"title":"Phishing of a Harmony developer preceded the $100M Horizon Bridge theft","date":"2022-06-23","date_precision":"day","victim_org":"Harmony (Horizon Bridge)","sector":"Cryptocurrency","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft"],"loss_usd":100000000,"loss_note":"The FBI put the theft at $100 million in virtual currency, spanning 14 bridged assets including USDC, ETH, USDT and BNB.","records_affected":null,"threat_actor":"Lazarus Group and APT38 (DPRK), per FBI attribution","summary":"Harmony's Horizon Bridge lost about $100 million on June 23, 2022. Harmony's own incident summary described a coordinated attack on its internal infrastructure rather than a smart contract flaw, beginning with a phishing scheme that tricked at least one software developer into installing malicious software. The FBI confirmed in January 2023 that Lazarus Group and APT38 were responsible, after tracing laundering activity through Railgun.","how_it_worked":"Harmony stated the attackers 'employed a phishing scheme to trick at least one software developer to install malicious software on their laptop.' That access let them read internal chat threads to learn how the bridge was operated and reach non-public bridge infrastructure code, then obtain backdoor access to one or more servers. Because the Horizon Bridge used a multisignature scheme requiring only two of five signatures, compromising the operational hosts holding those keys was enough to authorise transfers. On June 23 the attackers moved fourteen bridged asset types out in a series of transactions. Harmony emphasised the bridge contracts themselves were never exploited.","lessons":"Raising the signature threshold and isolating signing keys on dedicated hardware away from developer workstations would have meant that phishing one laptop could not produce a valid bridge withdrawal.","confidence":"Confirmed","sources":[{"title":"Summary of the Harmony Horizon Bridge Incident","url":"https://medium.com/harmony-one/summary-of-the-harmony-horizon-bridge-incident-f9bd87c0c68e","publisher":"Harmony"},{"title":"FBI: North Korean hackers stole $100 million in Harmony crypto hack","url":"https://www.bleepingcomputer.com/news/security/fbi-north-korean-hackers-stole-100-million-in-harmony-crypto-hack/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2022-phishing-of-a-harmony-developer-preceded-the-100m-horizon-bridge-theft","year":2022,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-phishing-of-a-harmony-developer-preceded-the-100m-horizon-bridge-theft"}}