Elliptic – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Tue, 24 Jun 2025 02:09:34 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Elliptic – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Dark market activity on Telegram persists despite $27B Huione ban – Elliptic https://earlybirdsinvest.com/dark-market-activity-on-telegram-persists-despite-27b-huione-ban-elliptic/ https://earlybirdsinvest.com/dark-market-activity-on-telegram-persists-despite-27b-huione-ban-elliptic/#respond Tue, 24 Jun 2025 02:09:33 +0000 https://earlybirdsinvest.com/dark-market-activity-on-telegram-persists-despite-27b-huione-ban-elliptic/

Telegram-based dark markets rapidly filled the gap left by Huione Guarantee after the $27 billion marketplace disappeared on May 13, according to a June 23 Elliptic report.

Elliptic noted that Telegram banned thousands of Huione Guarantee channels and usernames once researchers traced billions of USDT-denominated sales to pig-butchering scams. However, data shows that merchants immediately moved to Tudou Guarantee, a rival in which Huione owns a 30% stake.

On-chain data recorded incoming USDT at Huione falling to near zero after the ban, while Tudou’s user count more than doubled, with inflows matching Huione’s pre-shutdown volumes.

Guarantee markets operate in Chinese on Telegram and settle exclusively in USDT. Vendors supply stolen data, money laundering pathways, and other services essential to large-scale online fraud. 

The escrow model lets buyers and sellers resolve disputes without exposing real identities, and Tether’s dollar peg eliminates local currency volatility.

Distinct payment rail from Huione Pay

Observers sometimes confuse Huione Guarantee with Huione Pay, a Cambodia-based payment firm still processing large USDT volumes. 

Elliptic separated the two through wallet analysis and noted that Huione Pay’s traffic remained high even after FinCEN labeled the parent Huione Group “a financial institution of primary money laundering concern” and proposed cutting its US access.

Elliptic tracked more than 30 active Guarantee markets and warned about fake venues that target inexperienced criminals. 

Tudou led the post-shutdown surge, but smaller competitors also gained users as merchants duplicated listings across platforms.

Ecosystem adapts to channel bans

The closure of the Huione Guarantee sent temporary shock waves through a network of hundreds of thousands of scammers, intermediaries, and brokers across Southeast Asia and China. 

Elliptic’s data showed no enduring decline in overall Guarantee-market volume one month later, indicating that liquidity migrated swiftly to replacement channels.

The report concluded that coordinated, sustained, removals will be required to disrupt an ecosystem built on Telegram escrow and USDT settlements. 

Huione Guarantee’s downfall disrupted one node, but the broader dark market structure continues to expand within the messaging app.

Mentioned in this article
]]>
https://earlybirdsinvest.com/dark-market-activity-on-telegram-persists-despite-27b-huione-ban-elliptic/feed/ 0 43756
‘Huge Shift’ in crypto firms’ compliance mindset, says Elliptic co-founder https://earlybirdsinvest.com/huge-shift-in-crypto-firms-compliance-mindset-says-elliptic-co-founder/ https://earlybirdsinvest.com/huge-shift-in-crypto-firms-compliance-mindset-says-elliptic-co-founder/#respond Wed, 30 Apr 2025 23:04:58 +0000 https://earlybirdsinvest.com/huge-shift-in-crypto-firms-compliance-mindset-says-elliptic-co-founder/

The crypto industry has seen a significant shift toward regulatory compliance since its early days, according to James Smith, co-founder of Elliptic, a crypto compliance firm established in 2013.

“In the early days, only a few companies approached compliance in a serious way,” Smith told Cointelegraph at the Token2049 event. “Coinbase was our first customer — they knew from the start that they wanted to build their business that way. But for most others, it just wasn’t a major priority.”

Elliptic co-founder James Smith at Token2049. Source: Cointelegraph

That began to shift as regulators, including those in New York State, took a more active interest in the crypto industry. The involvement of traditional financial institutions like Fidelity and DBS Bank also contributed, as they entered the space with established compliance expectations from traditional finance services.

Fidelity, for instance, offered its first crypto service for customers in 2019, while the Asian giant DBS created a digital exchange for accredited and institutional investors in 2020.

“We’ve seen a big change in the last couple of years. Exchanges on the global map all care about compliance now, because they want to be part of a global ecosystem,” Smith said.

Related: DeFi security and compliance must be improved to attract institutions

Compliance questions after Bybit hack

Crypto exchanges and peer-to-peer protocols remain the industry’s key compliance targets. For authorities, these firms are seen as critical choke points where Anti-Money Laundering and broader financial surveillance controls take effect. At the same time, they’re frequent candidates for sophisticated hacks and laundering operations, as seen in the Lazarus Group’s tactics.

The latest example comes from the Bybit hack, where the Lazarus Group engaged in a sophisticated money laundering scheme to funnel funds. The hackers quickly swapped low-liquidity tokens for Ether (ETH), then swapped them for Bitcoin (BTC) using no-KYC (Know Your Customer) decentralized exchanges.

“They went through some no KYC exchanges, which probably shouldn’t exist, but also through a decentralized protocol where there was lots of liquidity provision that enabled them to get it into Bitcoin,” Smith said, adding that “we’re making it too easy for them as an industry.”

Smith also noted that even after firms flagged the funds as stolen, users continued to trade them through decentralized platforms. “Why was there so much liquidity available to help launder this money?” he said, arguing that those providing liquidity to such protocols should be subject to basic checks on the source and destination of funds. “Go and look at who’s making money. And that’s the first place to start putting some controls.”

Magazine: Lazarus Group’s favorite exploit revealed — Crypto hacks analysis

]]> https://earlybirdsinvest.com/huge-shift-in-crypto-firms-compliance-mindset-says-elliptic-co-founder/feed/ 0 33689 Can I add two points of different elliptic curves? https://earlybirdsinvest.com/can-i-add-two-points-of-different-elliptic-curves/ https://earlybirdsinvest.com/can-i-add-two-points-of-different-elliptic-curves/#respond Mon, 14 Apr 2025 07:28:15 +0000 https://earlybirdsinvest.com/can-i-add-two-points-of-different-elliptic-curves/

TL; PhD: Just reusing the formula is limited in adding points between two different curves, but there is no relationship between this and the corresponding private key.


Consider the elliptic curve of a form

y2 = x3 + ax + bmodulo p

(These are called short weierStrass curves)

for secp256k1, p = 2256 -232 -977, a = 0, b = 7.

The most impactful parameter is p. If you change it pwhat will you change Something like numbers x and y teeth. They are written in the same way, but “integers” 37“,” integer 37 for set of numbers p“,” integer 37 for set of numbers Q≠p“All three very Different beasts, with very different mathematical properties. For this reason, I’m going to stick to the same modulus p from now on. When I change the modulus, I don’t know how to define what the elliptic curve manipulation looks like. Which modulus are you using?

Instead, limit yourself to modulus p. Next, to add points, look at the elliptic curve point addition equation (which does not apply when adding points to itself, but ignores these). (x1y1)) In (x2y2))the result (x3y3)):

x32 -X1 -X2and y3 =λ(x1 -X3) – y1where λ=(x2 -X1))-1(y2 – y1))all modulo p.

note that ()-1 Here we refer to the inverse of modular rather than the reverse of normal.

Here we observe that there is no curve coefficient a or b It appears in this equation. This means that in theory there is no problem repurposing the same equation that attempts to add a cross-chain point. We’ll get Some I’ll give the numbers. The only question is whether these are meaningful numbers.

As you are asking about the relationship between private keys, there are additional requirements. Private keys live in spaces of yet another type, Integers modulo nwhere n It is the order of the curves, and this order depends on other parameters (p, aand b). If we hold a = 0 Like secp256k1find the next order.

  • b = 1: N = P -671331852483699643819086596696745227419
  • b = 2: N = P + 432420386565659656852420866390673177328
  • b = 3: N = P -23891146591803998696665730306072050092
  • b = 4: N = P + 23891146591803998696665730306072050094
  • b = 5: N = P -23891146591803998696665730306072050092 (same as b = 3))
  • b = 6: N = P + 671331852483699643819086596696745227421
  • b = 7: N = P -432420386565659656852420866390673177326 (secp256k1))
  • b = 8: N = P -671331852483699643819086596696745227419 (same as b = 1))
  • b = 12: N = P -671331852483699643819086596696745227419 (same as secp256k1, b = 7))

Private keys are not comparable when using curves from different orders, so choose two equal curves.

  • e1 :y2 = x3 +7 (secp256k1))
  • e2 :y2 = x3 + 12 (same order secp256k1).

Then, choose a point for each one:

  • p1 =(1,√8)∊ e1 (note that Here we refer to the modular square root).
  • p2 =(3,√39)∊ e2

Applying an additional formula to these points: (95199522409000127469965119215597403251155081608447444174576216444444444495047495870, 1781786278411321976761920437055831493304961098652000013158227081296748670101) This is in yet another curve, y2 = x3 + 113806959725436624290596825687872189644220457918942327168084848630572715522289there is an order N = P + 671331852483699643819086596696745227421. Because the order is different secp256k1which means that private key cannot be compared secp256k1 Private key.

Let’s try again:

  • Q1 =(4,√71)∊ e1
  • Q2 =(8,√524)∊ e2

Add these and you’ll see (8386077744065949110268813889711978972482433634987436290509042796539639347581, 9410084904444375978007588367501158030247960607256518328981974291822837065288)on the curve y2 = x3 + 49979308264444391589663903731913831145103210634021312327468912561582998092there is an order N = P + 432420386565659656852420866390673177328.


So even if you choose the largest similar curve and try to add points to them, you’ll end up with different points. clear Unrelated curves, private keys are pointless to compare secp256k1.

]]>
https://earlybirdsinvest.com/can-i-add-two-points-of-different-elliptic-curves/feed/ 0 30688
Elliptic Says Lazarus Group Using eXch To Launder Stolen Funds Despite Requests From Bybit To Block Transactions https://earlybirdsinvest.com/elliptic-says-lazarus-group-using-exch-to-launder-stolen-funds-despite-requests-from-bybit-to-block-transactions/ https://earlybirdsinvest.com/elliptic-says-lazarus-group-using-exch-to-launder-stolen-funds-despite-requests-from-bybit-to-block-transactions/#respond Tue, 25 Feb 2025 13:34:21 +0000 https://earlybirdsinvest.com/elliptic-says-lazarus-group-using-exch-to-launder-stolen-funds-despite-requests-from-bybit-to-block-transactions/

The Lazarus Group has laundered stolen crypto from last week’s record-shattering Bybit hack through the exchange eXch, according to the blockchain research firm Elliptic.

Hackers looted nearly $1.5 billion worth of Ethereum (ETH) and Lido Staked Ether (stETH) from Bybit on Friday.

The attack represented the largest crypto hack ever and possibly the biggest heist in world history.

Elliptic, pseudonymous on-chain investigator ZachXBT and other researchers have pinned the exploit on the Lazarus Group, a prolific North Korean cybercriminal outfit known for numerous high-profile hacks on major crypto platforms.

In a new analysis, Elliptic notes that Lazarus’ money-laundering process typically follows the same steps. First, the group exchanges any stolen tokens for a native blockchain asset like Ethereum, because ETH can’t be frozen by a central authority.

LI_bybit_top_heists
Source: Elliptic

Subsequently, the cybercriminal outfit “layers” the stolen funds through multiple wallets, exchanges, cross-chain bridges and crypto mixers to obfuscate the transaction trail.

Elliptic says that Lazarus is currently in the middle of the second step.

“Within two hours of the theft, the stolen funds were sent to 50 different wallets, each holding approximately 10,000 ETH. These are now being systematically emptied – as of 1pm UTC on February 24, 14.5% of the stolen assets (now worth $195 million) have been moved from these wallets.

Once moved out of these wallets, the funds are being laundered through various services, including DEXs (decentralized exchanges), cross-chain bridges and centralized exchanges.

However, one service has emerged as a major and willing facilitator of this laundering. eXch is a cryptocurrency exchange, notable for allowing its users to swap cryptoassets anonymously. This has led them to being used to exchange hundreds of millions of dollars in crypto assets derived from criminal activity, including multiple thefts perpetrated by North Korea. Despite attempting to conceal this activity, our analysis shows that since the hack, crypto assets stolen from Bybit worth over $75 million have been exchanged using eXch. Despite direct requests from Bybit, eXch has refused to block this activity.”

Over the weekend, eXch took to the BitcoinTalk forum to deny claims it was laundering crypto for Lazarus, though it did cop to processing an “insignificant” portion of the stolen Bybit funds.

“1. eXch is NOT laundering money for Lazarus/DPRK (North Korea).

2. The insignificant portion of funds from the ByBit hack eventually entered our address 0xf1da173228fcf015f43f3ea15abbb51f0d8f1123 which was an isolated case and the only part processed by our exchange, fees from which we will be donated for the public good.

3. Any claims by ZachXBT and others on Twitter regarding transactions not related to 0xf1da173228fcf015f43f3ea15abbb51f0d8f1123 that are falsely attributed to eXch are a targeted FUD attack on our exchange.”

Bybit CEO Ben Zhou says the firm has restored a 1:1 backing on all client assets after the record-setting hack, and the Dubai-based exchange announced a full restoration of services on Saturday.

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Follow us on X, Facebook and Telegram

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/elliptic-says-lazarus-group-using-exch-to-launder-stolen-funds-despite-requests-from-bybit-to-block-transactions/feed/ 0 21779