{"investigation":{"slug":"harmony-horizon-bridge","entity_name":"Harmony Horizon Bridge","trust_score":4,"severity_base":null,"score_modifier":0,"confidence":0.95,"status":"published","content_type":"investigation","summary":"The Harmony Horizon Bridge was a cross-chain bridge enabling asset transfers between Harmony, Ethereum, and Binance Smart Chain. On June 23–24, 2022, attackers exploited a critically under-configured 2-of-5 multisignature scheme to steal approximately $99.7 million across 14 asset types. The FBI formally attributed the attack to the North Korean state-linked Lazarus Group (APT38) in January 2023.","sections":[{"content":"On June 23, 2022, beginning at approximately 11:06 AM UTC, attackers began draining funds from the Harmony Horizon Bridge's Ethereum-side smart contracts. By the morning of June 24, Harmony publicly disclosed the breach and estimated losses at approximately $100 million USD. The attack targeted 14 bridged asset types held in the bridge's Ethereum and Binance Smart Chain vaults, including ETH, WETH, USDC, USDT, DAI, AAVE, SUSHI, and BNB. After the theft, approximately $98 million in ETH equivalent was held in the attacker's Ethereum address and $1.79 million in Binance Smart Chain assets. Harmony engaged the FBI and brought the incident public the same day, also pausing the bridge to prevent further losses.","heading":"Incident Overview","sources":[{"url":"https://www.cnbc.com/2022/06/24/hackers-steal-100-million-in-crypto-from-harmonys-horizon-bridge.html","name":"cnbc.com","type":"other","credibility":3},{"url":"https://medium.com/harmony-one/harmonys-horizon-bridge-hack-1e8d283b6d66","name":"medium.com","type":"other","credibility":3},{"url":"https://fortune.com/crypto/2022/06/24/hackers-steal-100-million-in-crypto-from-harmony-horizon-bridge-ethereum-binance/","name":"fortune.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The Horizon Bridge secured its Ethereum-side funds using a MultiSigWallet contract that required only 2 of 5 authorized signatories to approve any outbound transaction. This 2-of-5 threshold meant that compromising just two private keys was sufficient to authorize arbitrary withdrawals of all bridged assets. According to Harmony's own post-mortem, the private keys were encrypted at rest and managed through a key management service, with no single machine intended to hold multiple keys in plaintext. Despite these controls, attackers successfully accessed and decrypted at least two keys. The exploit itself consisted of 11 outbound transactions crafted and signed using the two compromised validator accounts. Following the incident, Harmony upgraded the Ethereum bridge to a 4-of-5 multisig threshold. Security researchers and analysts noted that the 2-of-5 configuration had been a known and publicly discussed risk prior to the attack.","heading":"Technical Vulnerability: Multisignature Misconfiguration","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-harmony-horizon-bridge-hack","name":"halborn.com","type":"other","credibility":3},{"url":"https://news.bitcoin.com/harmonys-100m-hack-was-due-to-a-compromised-multi-sig-scheme-says-analyst/","name":"news.bitcoin.com","type":"other","credibility":3},{"url":"https://www.merklescience.com/blog/hack-track-analysis-of-harmonys-horizon-bridge-exploit","name":"merklescience.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The FBI, in conjunction with CISA and the U.S. Treasury Department, attributed the initial access vector to a malware campaign designated 'TraderTraitor.' This campaign involves North Korean threat actors sending recruitment-themed phishing messages to employees at target firms, enticing recipients with high-paying job offers and directing them to download malware-laced cryptocurrency applications. The malware is written in cross-platform JavaScript packaged within the Electron framework, capable of deploying secondary payloads on both Windows and macOS systems. Once installed, TraderTraitor enables attackers to move laterally within organizational infrastructure and harvest credentials, including encrypted private keys. In the Harmony case, this technique allegedly allowed the attackers to access the key management infrastructure underpinning the bridge's multisig validators. The TraderTraitor campaign had previously been flagged in a joint U.S. government advisory issued in April 2022, approximately two months before the Horizon Bridge attack.","heading":"Attack Vector: TraderTraitor Social Engineering Campaign","sources":[{"url":"https://thehackernews.com/2023/01/fbi-says-north-korean-hackers-behind.html","name":"thehackernews.com","type":"other","credibility":3},{"url":"https://therecord.media/fbi-north-korean-hacking-group-lazarus-behind-100-million-crypto-heist","name":"therecord.media","type":"other","credibility":3},{"url":"https://securityaffairs.com/141266/apt/harmony-horizon-bridge-lazarus-apt.html","name":"securityaffairs.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On January 24, 2023, the Federal Bureau of Investigation formally confirmed that Lazarus Group — also known as APT38 and Hidden Cobra — cyber actors associated with the Democratic People's Republic of Korea (DPRK), were responsible for the Horizon Bridge theft. This attribution was based on on-chain transaction analysis, comparison to prior Lazarus laundering patterns, and law enforcement investigation. Blockchain analytics firm Elliptic states it was the first to publicly identify the Lazarus attribution at the time of the hack in June 2022, noting that the programmatic structuring of funds through Tornado Cash matched prior Lazarus Group behavior seen in other major bridge exploits including the March 2022 Ronin Bridge hack ($540 million). The FBI noted that the stolen virtual currency is used to support North Korea's ballistic missile and weapons of mass destruction programs.","heading":"Attribution: Lazarus Group (APT38 / Hidden Cobra)","sources":[{"url":"https://www.fbi.gov/news/press-releases/fbi-confirms-lazarus-group-cyber-actors-responsible-for-harmonys-horizon-bridge-currency-theft","name":"fbi.gov","type":"other","credibility":3},{"url":"https://www.elliptic.co/blog/analysis/fbi-confirms-north-korea-s-lazarus-group-as-hackers-behind-100-million-harmony-horizon-bridge-theft","name":"elliptic.co","type":"other","credibility":3},{"url":"https://decrypt.co/119861/fbi-north-korea-lazarus-horizon-harmony-bridge-hack","name":"decrypt.co","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the June 2022 theft, the stolen assets were consolidated into ETH and held relatively dormant for several months. Elliptic's analysis found that approximately $96 million from the Harmony hack was laundered through Tornado Cash, the Ethereum-based transaction mixer. The U.S. Treasury's OFAC sanctioned Tornado Cash on August 8, 2022, citing its use by Lazarus Group and others to launder hundreds of millions in stolen cryptocurrency. In January 2023, approximately seven months after the theft, the attackers moved approximately $60 million worth of ETH through RAILGUN, a zero-knowledge proof-based privacy protocol on Ethereum. Elliptic reported that 99.9% of all deposits into RAILGUN between January 11 and January 14, 2023, were proceeds of the Harmony bridge exploit. A portion of these funds was subsequently sent to several virtual asset service providers and converted to bitcoin. Binance and Huobi reportedly identified, blocked, and seized a portion of the laundered funds after detecting deposits from addresses linked to the mixing activity.","heading":"Laundering: Tornado Cash and RAILGUN","sources":[{"url":"https://www.elliptic.co/blog/analysis/fbi-confirms-north-korea-s-lazarus-group-as-hackers-behind-100-million-harmony-horizon-bridge-theft","name":"elliptic.co","type":"other","credibility":3},{"url":"https://home.treasury.gov/news/press-releases/jy0916","name":"home.treasury.gov","type":"other","credibility":3},{"url":"https://techcrunch.com/2023/01/24/north-korea-fbi-harmony-horizon-crypto/","name":"techcrunch.com","type":"other","credibility":3},{"url":"https://therecord.media/fbi-north-korean-hacking-group-lazarus-behind-100-million-crypto-heist","name":"therecord.media","type":"other","credibility":3}],"severity":"medium"},{"content":"The hack affected approximately 65,000 wallets and 14 distinct asset types. Harmony's native ONE token had already declined significantly in 2022 prior to the hack; the bridge incident further damaged community confidence. Harmony initially proposed reimbursing victims by minting billions of new ONE tokens and executing a hard fork, but this proposal was withdrawn following overwhelming negative community reaction due to concerns about token dilution. A revised recovery plan using the Harmony Foundation treasury was subsequently tabled. Recovery efforts continued through at least 2023 via the Recovery ONE Foundation, which conducted multiple funding rounds for affected users. As of mid-2023, some assets — including those locked in Aave on the Harmony chain — remained frozen and unrecovered more than a year after the incident, highlighting the long-term protocol-level damage caused by the exploit.","heading":"Community and Protocol Impact","sources":[{"url":"https://www.coindesk.com/tech/2022/07/27/harmony-proposes-issuing-one-tokens-to-reimburse-victims-of-100m-hack","name":"coindesk.com","type":"other","credibility":3},{"url":"https://decrypt.co/110379/harmony-publishes-revamped-horizon-bridge-recovery-plan","name":"decrypt.co","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/aave-assets-are-still-stuck-over-a-year-after-usd100m-harmony-bridge-hack","name":"thedefiant.io","type":"other","credibility":3}],"severity":"medium"},{"content":"The FBI's January 24, 2023, public attribution statement confirmed Lazarus Group's responsibility and noted that the agency was continuing efforts to identify and disrupt DPRK's theft and laundering of virtual currency. The August 2022 OFAC sanctioning of Tornado Cash was directly connected to its use in laundering proceeds from the Harmony hack and other Lazarus Group operations. No criminal indictments specifically naming individuals responsible for the Horizon Bridge attack had been publicly announced as of mid-2026. The OFAC Tornado Cash sanctions were later reversed by the U.S. Fifth Circuit Court of Appeals in a November 2024 ruling, with Treasury formally delisting Tornado Cash in early 2025, though criminal proceedings against Tornado Cash founders Roman Storm and Roman Semenov for money laundering and sanctions violations related to the protocol's operation continued separately.","heading":"Regulatory and Law Enforcement Actions","sources":[{"url":"https://www.fbi.gov/news/press-releases/fbi-confirms-lazarus-group-cyber-actors-responsible-for-harmonys-horizon-bridge-currency-theft","name":"fbi.gov","type":"other","credibility":3},{"url":"https://home.treasury.gov/news/press-releases/jy0916","name":"home.treasury.gov","type":"other","credibility":3},{"url":"https://www.mayerbrown.com/en/insights/publications/2024/12/federal-appeals-court-tosses-ofac-sanctions-on-tornado-cash-and-limits-federal-governments-ability-to-police-crypto-transactions","name":"mayerbrown.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2022-03-29","event":"Ronin Bridge (Axie Infinity) hacked for ~$540M by Lazarus Group, establishing a pattern of cross-chain bridge attacks attributed to North Korea.","source":""},{"date":"2022-04-18","event":"U.S. government issues joint advisory warning about the TraderTraitor malware campaign used by North Korean hackers targeting cryptocurrency organizations.","source":""},{"date":"2022-06-23","event":"Attackers begin draining Harmony Horizon Bridge at approximately 11:06 AM UTC using two compromised multisig private keys, executing 11 unauthorized outbound transactions.","source":""},{"date":"2022-06-24","event":"Harmony publicly discloses the breach, estimates losses at approximately $100 million, engages the FBI, and pauses the Horizon Bridge.","source":""},{"date":"2022-06-30","event":"Blockchain analytics firms including Elliptic and TechCrunch reporting links the attack to North Korea's Lazarus Group based on on-chain fund movement patterns.","source":""},{"date":"2022-07-27","event":"Harmony proposes minting new ONE tokens and executing a hard fork to reimburse hack victims; the proposal is met with strong community backlash.","source":""},{"date":"2022-08-08","event":"U.S. Treasury OFAC sanctions Tornado Cash, citing its use to launder proceeds from the Harmony hack and other Lazarus Group operations.","source":""},{"date":"2023-01-13","event":"North Korean cyber actors launder over $60 million in ETH from the Harmony theft through RAILGUN, a zero-knowledge proof privacy protocol; Elliptic reports 99.9% of RAILGUN deposits over a three-day window originated from Harmony hack proceeds.","source":""},{"date":"2023-01-24","event":"FBI formally confirms Lazarus Group (APT38) is responsible for the Harmony Horizon Bridge theft, stating stolen funds support DPRK ballistic missile and WMD programs.","source":""},{"date":"2023-06","event":"Recovery ONE Foundation continues reimbursement funding rounds for affected users, with some Aave-locked assets on Harmony chain remaining frozen over a year after the exploit.","source":"","date_original":"2023-06-01"},{"date":"2024-11","event":"U.S. Fifth Circuit Court of Appeals reverses OFAC sanctions on Tornado Cash, finding the agency had overstepped its authority in sanctioning immutable smart contracts.","source":"","date_original":"2024-11-01"}],"sources_used":[{"url":"https://www.cnbc.com/2022/06/24/hackers-steal-100-million-in-crypto-from-harmonys-horizon-bridge.html","name":"cnbc.com","type":"other","credibility":3},{"url":"https://medium.com/harmony-one/harmonys-horizon-bridge-hack-1e8d283b6d66","name":"medium.com","type":"other","credibility":3},{"url":"https://fortune.com/crypto/2022/06/24/hackers-steal-100-million-in-crypto-from-harmony-horizon-bridge-ethereum-binance/","name":"fortune.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-harmony-horizon-bridge-hack","name":"halborn.com","type":"other","credibility":3},{"url":"https://news.bitcoin.com/harmonys-100m-hack-was-due-to-a-compromised-multi-sig-scheme-says-analyst/","name":"news.bitcoin.com","type":"other","credibility":3},{"url":"https://www.merklescience.com/blog/hack-track-analysis-of-harmonys-horizon-bridge-exploit","name":"merklescience.com","type":"other","credibility":3},{"url":"https://thehackernews.com/2023/01/fbi-says-north-korean-hackers-behind.html","name":"thehackernews.com","type":"other","credibility":3},{"url":"https://therecord.media/fbi-north-korean-hacking-group-lazarus-behind-100-million-crypto-heist","name":"therecord.media","type":"other","credibility":3},{"url":"https://securityaffairs.com/141266/apt/harmony-horizon-bridge-lazarus-apt.html","name":"securityaffairs.com","type":"other","credibility":3},{"url":"https://www.fbi.gov/news/press-releases/fbi-confirms-lazarus-group-cyber-actors-responsible-for-harmonys-horizon-bridge-currency-theft","name":"fbi.gov","type":"other","credibility":3},{"url":"https://www.elliptic.co/blog/analysis/fbi-confirms-north-korea-s-lazarus-group-as-hackers-behind-100-million-harmony-horizon-bridge-theft","name":"elliptic.co","type":"other","credibility":3},{"url":"https://decrypt.co/119861/fbi-north-korea-lazarus-horizon-harmony-bridge-hack","name":"decrypt.co","type":"other","credibility":3},{"url":"https://home.treasury.gov/news/press-releases/jy0916","name":"home.treasury.gov","type":"other","credibility":3},{"url":"https://techcrunch.com/2023/01/24/north-korea-fbi-harmony-horizon-crypto/","name":"techcrunch.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/tech/2022/07/27/harmony-proposes-issuing-one-tokens-to-reimburse-victims-of-100m-hack","name":"coindesk.com","type":"other","credibility":3},{"url":"https://decrypt.co/110379/harmony-publishes-revamped-horizon-bridge-recovery-plan","name":"decrypt.co","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/aave-assets-are-still-stuck-over-a-year-after-usd100m-harmony-bridge-hack","name":"thedefiant.io","type":"other","credibility":3},{"url":"https://www.mayerbrown.com/en/insights/publications/2024/12/federal-appeals-court-tosses-ofac-sanctions-on-tornado-cash-and-limits-federal-governments-ability-to-police-crypto-transactions","name":"mayerbrown.com","type":"other","credibility":3}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-30T18:25:21.692168+00:00","updated_at":"2026-08-29T01:33:40.854+00:00"}}