ZachXBT: $1.2M Theft Address Likely Belongs to THORChain Founder John-Paul

By: theblockbeats.news|2026/03/28 08:27:16

BlockBeats News, September 12th, On-chain detective ZachXBT commented on the "A THORChain User Was Hacked for $1.2 Million" incident, suggesting that the address may belong to THORChain founder John-Paul Thorbjornsen (JP, @jpthor), whose private wallet was compromised a few days ago due to a fake conference scam. "JP is one of those who has greatly benefited from laundering money through North Korean hacker attacks/vulnerability exploits. Therefore, he suffered losses due to a North Korean-related retaliatory attack, somewhat echoing the idea of karma."

BlockBeats Note: JP's "relationship" with North Korean hackers (mainly the Lazarus Group) is not direct cooperation or personal contact but stems from the THORChain protocol's stance in the 2025 Bybit exchange hack incident. In February 2025, North Korean hackers stole around $1.4 billion worth of cryptocurrency from Bybit, making it one of the largest crypto thefts in history. These hackers then used THORChain as the primary tool to launder the stolen funds, bridging 85% of the stolen funds (approximately $1.2 billion) and converting them into other assets to evade tracking.

-- Price

--
--
--

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

THORChain Soft Launch Integrates Monero, ADR31 and ADR27 Proposals Passed, v3.20 Enters Testing

DeFi has reached its most dangerous moment: the real vulnerabilities are not in the code

April 2026 is not just a security crisis; it is the moment when the industry's mental model completely collapses, and it is also the moment when the protocols that can survive are distinguished from those that cannot.

THORChain has released a recovery plan for the attack incident, and voting for node operators has begun

THORChain has released its fourth update regarding the attack incident on May 15, and the proposal ADR028 has been announced, with voting for node operators now open.According to the recovery plan, the protocol will first absorb losses through its own liquidity, with the remaining portion to be shar...

Cryptocurrency Market Update: Major Developments and Insights

Key Takeaways Sky co-founder Rune Christensen has leveraged strategic moves to short the S&P 500 and invest in…

Kelp DAO Exploit Fallout Deepens as Attacker Routes $175M in ETH via Privacy Rails

Key Takeaways: The attacker moved $175 million in stolen ETH to new wallets using privacy tools. The exploit…

Three major DeFi attacks in five days, with a total of 14 cryptocurrency hacking incidents in May

The Echo Protocol encountered a vulnerability attack on the Monad network, where the attacker minted 1,000 eBTC (worth approximately $76.64 million). According to PeckShield's tracking, the attacker deposited 45 eBTC (about $3.45 million) into Curvance, borrowed 11.29 WBTC, and then bridged it to Et...
...
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com