Used to just be all the Bluenoroff hacks. Back when I was not insane. Now it's a dumping ground for everything. 😅
“If the Internet is like a gun, cyberattacks are like atomic bombs.” – Kim Jon Il
“Cyberwarfare is an all-purpose sword that guarantees the North Korean People’s Armed Forces ruthless striking capability, along with nuclear weapons and missiles.” – Kim Jong-un
"The real purpose of the DPRK’s cyber, military, policy, and political aggressiveness is ultimately to control and subdue its own population and retain power."
- North Korean Cyber Attacks
- Recorded Future: North Korea's Cyber Strategy
- Recorded Future: Crypto Country
- The Incredible Rise of North Korea's Hacking Elite
- Comprehensive timeline of North Korea sanctions with the events that triggered them: 1985-2021
- Why is North Korea so Interested in Bitcoin? (2017)
- Exposing the Financial Footprints of North Korea’s Hackers
- Tracking Internet Use Out of North Korea Reveal The Adaptable and Innovative Ruling Elite
- Organizational Map of DPRK Cyber Operations (2022)
- Update to the Organizational Map of DPRK Cyber Operations (2023)
- Update to the Organizational Map of DPRK Cyber Operations (2024)
- Lazarus Group Deep Dive: 1
- Lazarus Group Deep Dive: 2
- Lazarus: Under The Hood
- Spotlight On Lazarus
- The All-Purpose Sword: North Korea’s Cyber Operations and Strategies (2019)
- US Army's Report on North Korean Tactics (2020)
- CISA's Guidance on the North Korean Cyber Threat (2020)
- North Korea's Military Power
- North Korea's Crypto Hackers Are Paving the Road to Nuclear Armageddon
- Kim Jong Un is directly handling results of new COVID-19 hacking organization's work
- [The DPRK’s Violation and Evasion of UN Sanctions through Cyber and Information Technology Worker Activities]./pdfs/2025-10-22_MSMT-Report.pdf)
| Tay's Totals | Tay's Count | Chain's 2024 Totals | Chain's 2024 Count | Chain's 2023 Totals | Count | TRM's Totals | TRM's Counts | UN Totals | UN Counts | |
|---|---|---|---|---|---|---|---|---|---|---|
| 2016 | $1,500,000 | 1 | $2,000,000 | 1 | $1,500,000 | 1 | 0 | n/a | 0 | 0 |
| 2017 | $88,790,000 | 6 | $29,000,000 | 4 | $29,000,000 | 4 | $100,000,000 | n/a | $88,640,000 | 6 |
| 2018 | $456,265,000 | 18 | $522,000,000 | 10 | $522,000,000 | 10 | $400,000,000 | n/a | $447,600,000 | 11 |
| 2019 | $207,814,000 | 11 | $271,000,000 | 9 | $271,000,000 | 9 | $200,000,000 | n/a | $209,272,000 | 8 |
| 2020 | $313,713,000 | 14 | $300,000,000 | 5 | $300,000,000 | 5 | $290,000,000 | n/a | $300,200,000 | 4 |
| 2021 | $551,142,751 | 23 | $506,000,000 | 11 | $428,800,000 | 9 | $250,000,000 | n/a | $175,600,000 | 6 |
| 2022 | $810,222,860 | 16 | $1,100,000,000 | 14 | $1,650,000,000 | 15 | $850,000,000 | n/a | $991,700,000 | 5 |
| 2023 | $646,804,332 | 27 | $660,000,000 | 20 | $1,000,000,000 | 20 | $600,000,000 | n/a | $753,019,000 | 17 |
| 2024 | $974,740,667 | 62 | $1,300,000,000 | 49 | n/a | n/a | ||||
| 2025 | $2,035,816,317 | 70 | ||||||||
| $6,086,771,927 | 248 | $4,690,000,000 | 123 | $4,202,300,000 | 73 | $2,690,000,000 | n/a | $2,966,031,000 | 57 |
| 📁 | Date | Incident | Amt Stolen |
|---|---|---|---|
| 🎙️ | 2025-01-09 | Crypto Staker Theft | $13,000 |
| 🔑 | 2025-01-20 | Unknown Jan 2025 | $1,700,000 |
| 👛 | 2025-01-23 | Phemex | $85,085,704 |
| 🔑 | 2025-02-05 | Russell | $1,125,700 |
| 🔑 | 2025-02-05 | Unknown Feb 2025 | $610,000 |
| 🎙️ | 2025-02-15 | Misc CI Thefts | $Unknown |
| 🔐 | 2025-02-17 | Ripio | $9,400,000 |
| 🔑 | 2025-02-18 | Individual 0xpete | $1,334,230 |
| 👛 | 2025-02-21 | Bybit | $1,500,000,000 |
| 🔑 | 2025-02-28 | Founder/CEO of A6 | $410,000 |
| 🔑 | 2025-02-28 | Fantom Reuse Address | $3,200,000 |
| 🔑 | 2025-03-07 | Founder/CEO of B3 | $3,186,200 |
| 🔑 | 2025-03-14 | Huge March 2025 Theft | $171,000,000 |
| 🔑 | 2025-03-21 | Zoth | $8,361,915 |
| 🎙️ | 2025-04-14 | Atlos | $10,000 |
| 🎙️ | 2025-04-23 | Oxya Admin Key Mint | $45,221 |
| 🔑 | 2025-04-23 | April 2025 Theft | $525,000 |
| 🎙️ | 2025-04-25 | Malicious Du-store Repo | $217,190 |
| 🎙️ | 2025-04-29 | Malicious BbaudConferenceDV Repo | $7,919 |
| 💼 | 2025-05-08 | LND FI | $500,000 |
| ❓ | 2025-05-09 | BitoPro | $12,300,000 |
| 🔑 | 2025-05-16 | Unknown JUP Holder | $3,360,880 |
| 🔑 | 2025-05-19 | MarketAcross | $560,000 |
| 🔑 | 2025-05-20 | Individual M6 | $1,200,000 |
| 🔑 | 2025-05-24 | TAO Founder | $5,116,358 |
| 🎙️ | 2025-06-03 | SpaceM | $187,090 |
| 🔑 | 2025-06-12 | Medhi | $230,000 |
| 🔑 | 2025-06-12 | June 12 2025 Theft | $330,388 |
| 🔑 | 2025-06-14 | Clober | $1,391,963 |
| 💼 | 2025-06-18 | Chainsaw | $350,000 |
| 💼 | 2025-06-19 | Bunzz | $5,500 |
| 🔑 | 2025-06-21 | June 21 2025 Theft | $54,000 |
| 🎙️ | 2025-06-22 | Hacken HAI Token Mint | $267,000 |
| 🔑 | 2025-06-22 | Sololabs | $963,000 |
| 💼 | 2025-06-25 | Favrr | $650,000 |
| 🔑 | 2025-06-26 | June 26 2025 Theft | $1,316,809 |
| 🎙️ | 2025-06-27 | Noya AI | $236,000 |
| ❓ | 2025-06-29 | VALR API Key Trade Extraction | $100,000 |
| 🔑 | 2025-06-30 | June 30 2025 Theft | $1,277,499 |
| 🔑 | 2025-07-04 | Individual DD | $544,086 |
| 🎙️ | 2025-07-10 | Malicious Store-V Repo | $44,000 |
| 👛 | 2025-07-15 | BigONE | $27,000,000 |
| 🎙️ | 2025-07-17 | Open Fabric | $241,000 |
| 🎙️ | 2025-07-23 | Malicious Blackbaud Moon Monkey Repo | $120,000 |
| 👛 | 2025-07-24 | WOO X | $14,038,066 |
| 🔑 | 2025-08-06 | Aug 2025 Theft from Individual | $2,738,690 |
| 🔑 | 2025-08-08 | Newfuture | $100,000 |
| 🎙️ | 2025-08-11 | Unknown Canadian Victim | $250,000 |
| 🔑 | 2025-08-13 | Rena | $405,938 |
| 👛 | 2025-08-14 | BTCTurk | $55,000,000 |
| 🎙️ | 2025-08-14 | AreonX | $200,000 |
| 🔑 | 2025-09-01 | OlaXBT | $2,206,525 |
| 🔑 | 2025-09-01 | Venus Whale | $27,000,000 |
| 🎙️ | 2025-09-06 | Unknown Sep 6 2025 Theft | $60,000 |
| 🔑 | 2025-09-06 | Individual AN5 | $420,000 |
| 🔑 | 2025-09-09 | JP Thor | $2,435,000 |
| ❓ | 2025-09-10 | Request / Singularity | $3,000,000 |
| 💼 | 2025-09-11 | Shibarium | $2,000,000 |
| 🔑 | 2025-09-12 | Sep 12 Theft | $1,137,772 |
| 🔑 | 2025-09-19 | Ross Gates | $150,000 |
| 🔑 | 2025-09-19 | Sep 19 Theft | $160,000 |
| 🔑 | 2025-09-22 | UXLINK | $44,112,708 |
| 🎙️ | 2025-09-23 | Seedify | $1,700,000 |
| ❓ | 2025-09-24 | SBI Crypto Mining | $20,283,197 |
| 🎙️ | 2025-10-18 | Unknown Oct 18 2025 Theft | $120,000 |
| 🎙️ | 2025-10-21 | YourCryptoFren | $300,000 |
| 🎙️ | 2025-10-27 | Capital DAO | $320,000 |
| ❓ | 2025-10-30 | Garden Finance | $12,371,369 |
| 🔑 | 2025-10-31 | Individual Laura66 | $187,600 |
| 🔑 | 2025-11-03 | Proph3ttt | $224,600 |
| 2025 | TOTAL | $2,035,816,317 | |
| 🎙️ | 2024-01-22 | ConcentricFi | $1,720,000 |
| 🎙️ | 2024-01-25 | Wall Street Memes | $2,500,000 |
| 🎙️ | 2024-02-01 | Linkedin Job Dev Scam | $200,000 |
| 🔑 | 2024-02-09 | PlayDapp | $36,000,000 |
| 🔐 | 2024-02-13 | Duelbits | $4,600,000 |
| 🎙️ | 2024-02-27 | Serenity Shield | $586,000 |
| 🎙️ | 2024-02-28 | Braintrust Job Dev Scam | $100,000 |
| 🎙️ | 2024-03-05 | MurAll | $278,000 |
| 🔑 | 2024-03-13 | NFPrompt | $10,400,000 |
| 🎙️ | 2024-03-13 | CloudAI | $309,400 |
| 🎙️ | 2024-03-16 | Wilder World | $2,314,583 |
| 🔑 | 2024-03-20 | Huge March 2024 Theft | $90,000,000 |
| 💼 | 2024-03-26 | Munchables | $62,000,000 |
| 💼 | 2024-03-29 | Solareum | $1,114,813 |
| 🎙️ | 2024-04-02 | Unknown Apr Victim | $815,000 |
| 🎙️ | 2024-04-11 | Endblock | $72,000 |
| 🔐 | 2024-04-29 | Rain | $16,300,000 |
| 🎙️ | 2024-05-06 | Genius / GNUS Token | $1,262,630 |
| 🔑 | 2024-05-15 | ALEX Labs | $4,300,000 |
| 🎙️ | 2024-05-22 | Exclusible Penthouse | $820,000 |
| 🎙️ | 2024-05-28 | HYVE | $100,000 |
| 🎙️ | 2024-05-29 | SpaceCatch | $200,000 |
| 👛 | 2024-05-31 | Bitcoin DMM | $305,800,000 |
| 🔑 | 2024-06-11 | Theft from Individual C7 | $4,200,000 |
| 👛 | 2024-06-22 | CoinStats | $2,300,000 |
| 🔑 | 2024-06-28 | Theft from Individual C4 | $400,000 |
| 👛 | 2024-07-01 | Kyrrex | $13,500,000 |
| 👛 | 2024-07-18 | Wazirx | $230,000,000 |
| 🔑 | 2024-07-22 | Founder/CEO of I4 | $1,500,000 |
| 🔐 | 2024-07-24 | T6 | $400,000 |
| 🔑 | 2024-07-24 | Bmer01915811 | $465,636 |
| 🎙️ | 2024-08-07 | Bitgert / BRISE | $437,000 |
| 🎙️ | 2024-08-07 | Nexera | $1,900,000 |
| 🔑 | 2024-08-16 | Theft from Individual A4 | $2,500,000 |
| 🔑 | 2024-08-30 | Metaschool | $212,182 |
| 👛 | 2024-09-10 | Indodax | $22,000,000 |
| 🔑 | 2024-09-13 | Adot | $300,000 |
| 🎙️ | 2024-09-13 | HODL Token | $160,000 |
| 🎙️ | 2024-09-19 | NiiFi | $Unknown |
| 👛 | 2024-09-19 | BingX | $45,000,000 |
| 🎙️ | 2024-09-20 | Masa | $175,000 |
| 🔑 | 2024-09-20 | Dexnet | $459,484 |
| 🔑 | 2024-09-25 | Truflation | $5,125,000 |
| 🍎 | 2024-10-16 | Radiant | $58,000,000 |
| 🎙️ | 2024-10-18 | Tapioca | $4,700,000 |
| 🔑 | 2024-10-18 | Fake Hack VC Thefts | $372,000 |
| 🔑 | 2024-10-23 | Theft from Individual M4 | $1,400,000 |
| 🎙️ | 2024-10-30 | Bitbucket Dev Scam | $Unknown |
| 🎙️ | 2024-10-31 | Scallop | $165,000 |
| 🔐 | 2024-10-31 | M2 | $13,000,000 |
| 🎙️ | 2024-11-15 | Nov 15 Contagious Interview | $Unknown |
| 🔑 | 2024-11-25 | TON Dude | $14,000,000 |
| 👛 | 2024-11-28 | XT | $1,700,000 |
| 🔑 | 2024-11-29 | MAK / Metacene | $2,056,995 |
| 🎙️ | 2024-12-05 | Fake UltraX Dex Job Scam | $110,000 |
| 🔑 | 2024-12-11 | Founder/CEO of O6 | $500,000 |
| 🎙️ | 2024-12-12 | Willo Campaign | $64,020 |
| 🔑 | 2024-12-16 | Uknown Dec 2024 Theft | $1,000,000 |
| 🔑 | 2024-12-16 | SyFu | $1,936,593 |
| 🔑 | 2024-12-17 | Zigcoin | $400,000 |
| 🔑 | 2024-12-18 | Rainfi | $2,009,331 |
| 🔑 | 2024-12-30 | Napier Founder | $500,000 |
| 2024 | TOTAL | **$974,740,667 ** | |
| 💼 | 2023-01-01 | Various 2023 Rug Pulls | $350,000 |
| 💼 | 2023-04-10 | Terraport | $3,900,000 |
| 💼 | 2023-04-26 | Merlin DEX | $1,800,000 |
| 👛 | 2023-06-03 | Atomic Wallet | $121,000,000 |
| ❓ | 2023-06-11 | A Large Theft / Investment Platform | $17,600,000 |
| 🍎 | 2023-07-01 | PolyNetwork | $10,000,000 |
| 👛 | 2023-07-22 | Alphapo + Coinspaid | $97,000,000 |
| 🔑 | 2023-08-07 | Steadefi | $1,140,000 |
| 🔑 | 2023-08-16 | Coinshift | $2,900,000 |
| 🎙️ | 2023-08-17 | SPooCK | $38,032 |
| 👛 | 2023-09-04 | Stake | $41,000,000 |
| 👛 | 2023-09-12 | CoinEx | $54,000,000 |
| ❓ | 2023-09-24 | HTX Theft Returne) | $0 |
| ❓ | 2023-09-28 | Unidentified Company | $3,000,000 |
| 💼 | 2023-10-05 | Blockbusters Tech | $Unknown |
| 🔑 | 2023-10-17 | Fantom Foundation | $7,624,588 |
| 🔑 | 2023-10-26 | Maverick | $8,300,000 |
| ❓ | 2023-11-07 | NFT Phishing | $1,077,186 |
| 👛 | 2023-11-10 | Poloniex | $130,000,000 |
| 🔑 | 2023-11-10 | Samudai | $1,100,000 |
| 🎙️ | 2023-11-10 | Waygate | $200,000 |
| 🎙️ | 2023-11-14 | UnoRe DAO | $219,000 |
| 🔐 | 2023-11-19 | Kronos | $26,000,000 |
| 👛 | 2023-11-22 | HTX / Heco | $116,000,000 |
| 🔑 | 2023-12-10 | Degen Reborn | $164,000 |
| 🎙️ | 2023-12-12 | OKX Dex | $2,390,976 |
| 🎙️ | 2023-12-28 | Upwork Developer Jobs Scams | $550 |
| 2023 | TOTAL | $646,804,332 | |
| 💼 | 2022-01-11 | MetaPlay ITW Theft | $2,700,000 |
| 🔑 | 2022-01-27 | ANKR founder | $1,799,228 |
| 💼 | 2022-02-04 | DEPO ITW Theft | $1,723,632 |
| 🔑 | 2022-02-10 | Feb 10 2022 Theft | $300,000 |
| 🔑 | 2022-03-22 | Arthur_0x | $1,700,000 |
| 🔑 | 2022-04-07 | Wonderhero | $1,025,000 |
| 👛 | 2022-04-14 | Ronin Bridge | $620,000,000 |
| 👛 | 2022-06-24 | Harmony Horizon Bridge | $105,000,000 |
| 🔑 | 2022-08-05 | deBridge (Attempt) | $0 |
| 🔑 | 2022-09-07 | GERA Coin | $142,000 |
| 🍎 | 2022-09-22 | DWF Labs | $45,150,000 |
| 🔑 | 2022-10-11 | Algorand | $750,000 |
| 🔑 | 2022-10-17 | Darshan | $1,750,000 |
| 🔑 | 2022-10-31 | Oct 31 2022 Theft | $183,000 |
| 🍎 | 2022-11-02 | Deribit | $28,000,000 |
| 💼 | 2022-12-01 | Pixelcraft Potential IT Worker | $0 |
| 2022 | TOTAL | $810,222,860 | |
| 🍎 | 2021-01-22 | Indodax ATO | $2,830,000 |
| 🔑 | 2021-02-18 | BOLT Token Holder | $42,000 |
| 💼 | 2021-03-05 | Paid Network | $160,000,000 |
| 🔑 | 2021-03-16 | GaijinEagle | $446,898 |
| 🔑 | 2021-04-02 | Mudge / Etna / Mokens Deployer | $1,000,000 |
| 🔑 | 2021-04-19 | EasyFi Founder | $81,000,000 |
| 🍎 | 2021-05-12 | 990.1 BTC | $55,600,000 |
| 🔑 | 2021-05-17 | FinNexus | $7,000,000 |
| 🔑 | 2021-06-03 | NAOs Finance | $750,000 |
| 🔑 | 2021-06-07 | Fetch AI | $2,600,000 |
| 🔑 | 2021-06-21 | Market Maker | $13,682,000 |
| 👛 | 2021-06-23 | Coinsquare | $22,620,000 |
| 🍎 | 2021-07-13 | Tower Capital | $Unknown |
| 🍎 | 2021-07-13 | Advcash | $14,000,000 |
| 🔑 | 2021-07-14 | Bondly Finance | $8,500,000 |
| 🔑 | 2021-08-01 | Aug Sept Oct 2021 Hacks | $2,000,000 |
| 💼 | 2021-08-12 | DAO Maker | $7,000,000 |
| 👛 | 2021-08-18 | Liquid Global | $91,000,000 |
| 🔑 | 2021-10-08 | MGNR | $24,100,000 |
| 🔑 | 2021-10-28 | Metaplay / Polyplay | $1,710,991 |
| 🔑 | 2021-11-01 | YFETH Admin Key | $200,000 |
| 🔑 | 2021-11-03 | bZx | $55,000,000 |
| 🔑 | 2021-11-26 | SCC | $60,862 |
| 2021 | TOTAL | $551,142,751 | |
| ❓ | 2020-01-01 | BTC Changers | $Unknown |
| 👛 | 2020-08-07 | New York Financial Services Company | $11,800,000 |
| 🔑 | 2020-08-18 | Hobocrypt | $134,000 |
| 🔑 | 2020-08-19 | FundRequest FND | $326,000 |
| 🔑 | 2020-08-24 | Coinberry | $370,000 |
| 🔑 | 2020-08-29 | Tap Global | $Unknown |
| 👛 | 2020-09-07 | Eterbase | $5,400,000 |
| 🔑 | 2020-09-11 | Unibright | $500,000 |
| 👛 | 2020-09-26 | Kucoin | $275,000,000 |
| 🔑 | 2020-10-06 | CoinMetro | $740,000 |
| 🔑 | 2020-10-16 | LEAD Wallet Token | $50,000 |
| 🔑 | 2020-11-13 | L2 Theft | $893,000 |
| 🔑 | 2020-12-14 | Hugh Karp / Nexus Mutual | $8,000,000 |
| 👛 | 2020-12-21 | Exmo | $10,500,000 |
| 2020 | TOTAL | $313,713,000 | |
| 🔑 | 2019-01-14 | Cryptopia | $16,000,000 |
| 👛 | 2019-03-23 | Etbox | $132,000 |
| 🍎 | 2019-03-24 | DragonEx | $7,090,000 |
| 🔑 | 2019-03-25 | Coinbene | $105,000,000 |
| 👛 | 2019-03-26 | BiKi | $12,300,000 |
| 👛 | 2019-06-30 | Bitcoin Norway (AlphaPoint) | $500,000 |
| 🔑 | 2019-07-01 | CoinTiger | $272,000 |
| 🔑 | 2019-08-26 | Individual Serej | $20,000 |
| 🔑 | 2019-09-25 | Algo Capital | $2,000,000 |
| 👛 | 2019-11-27 | Upbit | $48,500,000 |
| 👛 | 2019-03-?? | Bithumb | $16,000,000 |
| 2019 | TOTAL | $207,814,000 | |
| 💼 | 2018-01-01 | Marine Chain | $Unknown |
| 🔑 | 2018-03-18 | Cypherium | $8,500,000 |
| 👛 | 2018-04-12 | Coinsecure | $3,500,000 |
| 🔑 | 2018-04-19 | E7 Theft | $5,000,000 |
| 🍎 | 2018-04-21 | Gate.io | $234,000,000 |
| 🔑 | 2018-04-25 | OBZ ICO | $Unknown |
| 🔑 | 2018-05-29 | Taylor ICO | $1,700,000 |
| 👛 | 2018-06-09 | Coinrail | $37,000,000 |
| 🔑 | 2018-06-16 | G13 Theft | $275,000 |
| 🔑 | 2018-07-09 | Bancor | $23,500,000 |
| 🔑 | 2018-08-07 | BTC Markets | $3,500,000 |
| 🔑 | 2018-08-09 | Klickl / IDCM | $620,000 |
| 👛 | 2018-09-01 | Indodax | $24,900,000 |
| 👛 | 2018-09-14 | Zaif | $59,000,000 |
| 🔑 | 2018-10-20 | Trade.io | $10,000,000 |
| 🔑 | 2018-11-04 | Kryptono | $270,000 |
| 👛 | 2018-06-?? | Bithumb | $31,500,000 |
| 2018-08-?? | Unidentified Company | $13,000,000 | |
| 2018 | TOTAL | $456,265,000 | |
| 👛 | 2017-01-01 | Youbit aka Yapizon aka Coinbin | $7,450,000 |
| 👛 | 2017-01-01 | Bithumb | $14,000,000 |
| 👛 | 2017-05-12 | Wannacry | $150,000 |
| 👛 | 2017-07-15 | 2017 Cryptojacking Incidents | $Unknown |
| 🔑 | 2017-09-23 | Coinis | $2,190,000 |
| 🔑 | 2017-12-06 | NiceHash | $65,000,000 |
| 2017 | TOTAL | $88,790,000 | |
| 👛 | 2016-10-13 | Bitcurex | $1,500,000 |
| 2016 | TOTAL | $1,500,000 |
-
DPRK has many teams. They operate independently. The laundry stays separate. The indicators are different. The malware is different.
-
The clusters and teams change over time and have many names.
-
This is how I cluster them.
-
My research is primarily onchain and directly from victim reports. It is aided by reports and OSINT done by those tracking the malware, c2s, etc.
-
I often get it wrong bc the clustering and dynamic nature of DPRK is insane to keep track of. Don't take any of this as gospel. I am always learning.
-
aka: CryptoCore, APT38, Bluenoroff, Leery Turtle, SnatchCrypto, Alluring Pisces, CryptoMimic, UNC1069, Black Alicanto, CageyChameleon
-
VC impersonating, Telegram messagers, fake video meet calls, Fake Google Drive links, RustBucket, Mac malware, Applescript, malicious PDFs, "Fast changes to stablecoin risk.pdf"
-
Jul 2025 | macOS NimDoor: Targetting Web3 and Crypto Platforms with Nim-Based Malware
-
Apr 2024 | How Lazarus Group laundered $200M from 25+ crypto hacks to fiat from 2020–2023
-
They are the best dust collectors! 🥰
-
🔑 🔐 💼 Dust Collector ae69 (0xae69012d15d6b1a3b2412aadef712f06f9286e0e)
-
🔑 Dust Collector 9a5 (0x9a5fc00f9aaa07817725fd38d7e73252f9f49e27)
-
🔑 Dust Collector b5d (0xb5d70f00608c77724b5cb73b93da89df1ae9f6e8)
-
🔑 Dust Collector fda (0xfda946270a6f452e0a134e22b493f4e7e8bdbc50)
-
🔑 Dust Collector a54 (0xa547c81b67ec09072b21baa8e107816d39cbd969)
-
🔑 Dust Collector 7ec (0x7ec567ce97ec28e19ce7e2d4bcbb7943eb90ede0)
-
🔑 Dust Collector 314 (0x31499e03303dd75851a1738e88972cd998337403)
-
🔑 Dust Collector 2d7 (0x2d7554062664050294640891a122019a68ac5a2b)
-
🔑 Dust Collector 997 (0x99739fa525c0a98384430235d278fd08938997f9)
-
🔑 Dust Collector c0b (0xc0b635fb9dc28dea84db150b89d4578ff9859877)
| 📁 | Date | Incident | Amt Stolen |
|---|---|---|---|
| 🔑 | 2025-01-20 | Unknown Jan 2025 | $1,700,000 |
| 🔑 | 2025-02-05 | Russell | $1,125,700 |
| 🔑 | 2025-02-05 | Unknown Feb 2025 | $610,000 |
| 🔑 | 2025-02-18 | Individual 0xpete | $1,334,230 |
| 🔑 | 2025-02-28 | Fantom Reuse Address | $3,200,000 |
| 🔑 | 2025-02-28 | Founder/CEO of A6 | $410,000 |
| 🔑 | 2025-03-07 | Founder/CEO of B3 | $3,186,200 |
| 🔑 | 2025-03-14 | Huge March 2025 Theft | $171,000,000 |
| 🔑 | 2025-03-21 | Zoth | $8,361,915 |
| 🔑 | 2025-04-23 | April 2025 Theft | $525,000 |
| 🔑 | 2025-05-16 | Unknown JUP Holder | $3,360,880 |
| 🔑 | 2025-05-19 | MarketAcross | $560,000 |
| 🔑 | 2025-05-20 | Individual M6 | $1,200,000 |
| 🔑 | 2025-05-24 | TAO Founder | $5,116,358 |
| 🔑 | 2025-06-12 | June 12 2025 Theft | $330,388 |
| 🔑 | 2025-06-12 | Medhi | $230,000 |
| 🔑 | 2025-06-14 | Clober | $1,391,963 |
| 🔑 | 2025-06-21 | June 21 2025 Theft | $54,000 |
| 🔑 | 2025-06-22 | Sololabs | $963,000 |
| 🔑 | 2025-06-26 | June 26 2025 Theft | $1,316,809 |
| ❓ | 2025-06-29 | VALR API Key Trade Extraction | $100,000 |
| 🔑 | 2025-06-30 | June 30 2025 Theft | $1,277,499 |
| 🔑 | 2025-07-04 | Individual DD | $544,086 |
| 🔑 | 2025-08-06 | Aug 2025 Theft from Individual | $2,738,690 |
| 🔑 | 2025-08-08 | Newfuture | $100,000 |
| 🔑 | 2025-08-13 | Rena | $405,938 |
| 🔑 | 2025-09-01 | OlaXBT | $2,206,525 |
| 🔑 | 2025-09-01 | Venus Whale | $27,000,000 |
| 🔑 | 2025-09-06 | Individual AN5 | $420,000 |
| 🔑 | 2025-09-09 | JP Thor | $2,435,000 |
| ❓ | 2025-09-10 | Request / Singularity | $3,000,000 |
| 🔑 | 2025-09-12 | Sep 12 Theft | $1,137,772 |
| 🔑 | 2025-09-19 | Ross Gates | $150,000 |
| 🔑 | 2025-09-19 | Sep 19 Theft | $160,000 |
| 🔑 | 2025-09-22 | UXLINK | $44,112,708 |
| ❓ | 2025-09-24 | SBI Crypto Mining | $20,283,197 |
| ❓ | 2025-10-30 | Garden Finance | $12,371,369 |
| 🔑 | 2025-10-31 | Individual Laura66 | $187,600 |
| 🔑 | 2025-11-03 | Proph3ttt | $224,600 |
| 2025 | TOTAL | $324,831,427 | |
| 🔑 | 2024-02-09 | PlayDapp | $36,000,000 |
| 🔑 | 2024-03-13 | NFPrompt | $10,400,000 |
| 🔑 | 2024-03-20 | Huge March 2024 Theft | $90,000,000 |
| 🔑 | 2024-05-15 | ALEX Labs | $4,300,000 |
| 🔑 | 2024-06-11 | Theft from Individual C7 | $4,200,000 |
| 🔑 | 2024-06-28 | Theft from Individual C4 | $400,000 |
| 🔑 | 2024-07-22 | Founder/CEO of I4 | $1,500,000 |
| 🔑 | 2024-07-24 | Bmer01915811 | $465,636 |
| 🔑 | 2024-08-16 | Theft from Individual A4 | $2,500,000 |
| 🔑 | 2024-08-30 | Metaschool | $212,182 |
| 🔑 | 2024-09-13 | Adot | $300,000 |
| 🔑 | 2024-09-20 | Dexnet | $459,484 |
| 🔑 | 2024-09-25 | Truflation | $5,125,000 |
| 🔑 | 2024-10-18 | Fake Hack VC Thefts | $372,000 |
| 🔑 | 2024-10-23 | Theft from Individual M4 | $1,400,000 |
| 🔑 | 2024-11-25 | TON Dude | $14,000,000 |
| 🔑 | 2024-11-29 | MAK / Metacene | $2,056,995 |
| 🔑 | 2024-12-11 | Founder/CEO of O6 | $500,000 |
| 🔑 | 2024-12-16 | SyFu | $1,936,593 |
| 🔑 | 2024-12-16 | Uknown Dec 2024 Theft | $1,000,000 |
| 🔑 | 2024-12-17 | Zigcoin | $400,000 |
| 🔑 | 2024-12-18 | Rainfi | $2,009,331 |
| 🔑 | 2024-12-30 | Napier Founder | $500,000 |
| 2024 | TOTAL | $180,037,221 | |
| 🔑 | 2023-08-07 | Steadefi | $1,140,000 |
| 🔑 | 2023-08-16 | Coinshift | $2,900,000 |
| 🔑 | 2023-10-17 | Fantom Foundation | $7,624,588 |
| 🔑 | 2023-10-26 | Maverick | $8,300,000 |
| 🔑 | 2023-11-10 | Samudai | $1,100,000 |
| 🔑 | 2023-12-10 | Degen Reborn | $164,000 |
| 2023 | TOTAL | $21,228,588 | |
| 🔑 | 2022-01-27 | ANKR founder | $1,799,228 |
| 🔑 | 2022-02-10 | Feb 10 2022 Theft | $300,000 |
| 🔑 | 2022-03-22 | Arthur_0x | $1,700,000 |
| 🔑 | 2022-04-07 | Wonderhero | $1,025,000 |
| 🔑 | 2022-08-05 | deBridge (Attempt) | $0 |
| 🔑 | 2022-09-07 | GERA Coin | $142,000 |
| 🔑 | 2022-10-11 | Algorand | $750,000 |
| 🔑 | 2022-10-17 | Darshan | $1,750,000 |
| 🔑 | 2022-10-31 | Oct 31 2022 Theft | $183,000 |
| 2022 | TOTAL | $7,649,228 | |
| 🔑 | 2021-02-18 | BOLT Token Holder | $42,000 |
| 🔑 | 2021-03-16 | GaijinEagle | $446,898 |
| 🔑 | 2021-04-02 | Mudge / Etna / Mokens Deployer | $1,000,000 |
| 🔑 | 2021-04-19 | EasyFi Founder | $81,000,000 |
| 🔑 | 2021-05-17 | FinNexus | $7,000,000 |
| 🔑 | 2021-06-03 | NAOs Finance | $750,000 |
| 🔑 | 2021-06-07 | Fetch AI | $2,600,000 |
| 🔑 | 2021-06-21 | Market Maker | $13,682,000 |
| 🔑 | 2021-07-14 | Bondly Finance | $8,500,000 |
| 🔑 | 2021-08-01 | Aug Sept Oct 2021 Hacks | $2,000,000 |
| 🔑 | 2021-10-08 | MGNR | $24,100,000 |
| 🔑 | 2021-10-28 | Metaplay / Polyplay | $1,710,991 |
| 🔑 | 2021-11-01 | YFETH Admin Key | $200,000 |
| 🔑 | 2021-11-03 | bZx | $55,000,000 |
| 🔑 | 2021-11-26 | SCC | $60,862 |
| 2021 | TOTAL | $198,092,751 | |
| 🔑 | 2020-08-18 | Hobocrypt | $134,000 |
| 🔑 | 2020-08-19 | FundRequest FND | $326,000 |
| 🔑 | 2020-08-24 | Coinberry | $370,000 |
| 🔑 | 2020-08-29 | Tap Global | $Unknown |
| 🔑 | 2020-09-11 | Unibright | $500,000 |
| 🔑 | 2020-10-06 | CoinMetro | $740,000 |
| 🔑 | 2020-10-16 | LEAD Wallet Token | $50,000 |
| 🔑 | 2020-11-13 | L2 Theft | $893,000 |
| 🔑 | 2020-12-14 | Hugh Karp / Nexus Mutual | $8,000,000 |
| 2020 | TOTAL | $11,113,000 | |
| 🔑 | 2017-07-01 | Korbit | $Unknown |
| 🔑 | 2017-09-23 | Coinis | $2,190,000 |
| 🔑 | 2017-12-06 | NiceHash | $65,000,000 |
| 🔑 | 2018-03-18 | Cypherium | $8,500,000 |
| 🔑 | 2018-04-19 | E7 Theft | $5,000,000 |
| 🔑 | 2018-04-25 | OBZ ICO | $Unknown |
| 🔑 | 2018-05-29 | Taylor ICO | $1,700,000 |
| 🔑 | 2018-06-16 | G13 Theft | $275,000 |
| 🔑 | 2018-07-09 | Bancor | $23,500,000 |
| 🔑 | 2018-08-07 | BTC Markets | $3,500,000 |
| 🔑 | 2018-08-09 | Klickl / IDCM | $620,000 |
| 🔑 | 2018-10-20 | Trade.io | $10,000,000 |
| 🔑 | 2018-11-04 | Kryptono | $270,000 |
| 🔑 | 2019-01-14 | Cryptopia | $16,000,000 |
| 🔑 | 2019-03-25 | Coinbene | $105,000,000 |
| 🔑 | 2019-07-01 | CoinTiger | $272,000 |
| 🔑 | 2019-08-26 | Individual Serej | $20,000 |
| 🔑 | 2019-09-25 | Algo Capital | $2,000,000 |
| 2019-2017 | TOTAL | $243,847,000 |
- Apparently also DangerousPassword shit but is completely separate onchain so we keep it off to the side a bit.
- Astrill, Mullvad. Tornado Cash to Wormhole or eXch. Gets lost in Tornado with all the other DPRK shit.
| 📁 | Date | Incident | Amt Stolen |
|---|---|---|---|
| ❓ | 2023-06-11 | A Large Theft / Investment Platform | $17,600,000 |
| ❓ | 2023-09-28 | Unidentified Company | $3,000,000 |
| 🔐 | 2023-11-19 | Kronos | $26,000,000 |
| 2023 | TOTAL | $46,600,000 | |
| 🔐 | 2024-02-13 | Duelbits | $4,600,000 |
| 🔐 | 2024-04-29 | Rain | $16,300,000 |
| 🔐 | 2024-07-24 | T6 | $400,000 |
| 🔐 | 2024-10-31 | M2 | $13,000,000 |
| 2024 | TOTAL | $34,300,000 | |
| 🔐 | 2025-02-17 | Ripio | $9,400,000 |
| ❓ | 2025-05-09 | BitoPro | $12,300,000 |
| 2025 | TOTAL | $21,700,000 |
- The big boys, the insane on-chain laundry sessions.
- Targets technical / backend guys with fake job offers or requests for help.
| 📁 | Date | Incident | Amt Stolen |
|---|---|---|---|
| 👛 | 2025-01-23 | Phemex | $85,085,704 |
| 👛 | 2025-02-21 | Bybit | $1,500,000,000 |
| 👛 | 2025-07-15 | BigONE | $27,000,000 |
| 👛 | 2025-07-24 | WOO X | $14,038,066 |
| 👛 | 2025-08-14 | BTCTurk | $55,000,000 |
| 2025 | TOTAL | $1,681,123,770 | |
| 👛 | 2024-05-31 | Bitcoin DMM | $305,800,000 |
| 👛 | 2024-06-22 | CoinStats | $2,300,000 |
| 👛 | 2024-07-01 | Kyrrex | $13,500,000 |
| 👛 | 2024-07-18 | Wazirx | $230,000,000 |
| 👛 | 2024-09-10 | Indodax | $22,000,000 |
| 👛 | 2024-09-19 | BingX | $45,000,000 |
| 👛 | 2024-11-28 | XT | $1,700,000 |
| 2024 | TOTAL | $620,300,000 | |
| 👛 | 2023-06-03 | Atomic Wallet | $121,000,000 |
| 👛 | 2023-07-22 | Alphapo + Coinspaid | $97,000,000 |
| 👛 | 2023-09-04 | Stake | $41,000,000 |
| 👛 | 2023-09-12 | CoinEx | $54,000,000 |
| 👛 | 2023-11-10 | Poloniex | $130,000,000 |
| 👛 | 2023-11-22 | HTX / Heco | $116,000,000 |
| 2023 | TOTAL | $559,000,000 | |
| 👛 | 2022-04-14 | Ronin Bridge | $620,000,000 |
| 👛 | 2022-06-24 | Harmony Horizon Bridge | $105,000,000 |
| 2022 | TOTAL | $725,000,000 | |
| 👛 | 2021-06-23 | Coinsquare | $22,620,000 |
| 👛 | 2021-08-18 | Liquid Global | $91,000,000 |
| 2021 | TOTAL | $113,620,000 | |
| 👛 | 2020-08-07 | New York Financial Services Company | $11,800,000 |
| 👛 | 2020-09-07 | Eterbase | $5,400,000 |
| 👛 | 2020-09-26 | Kucoin | $275,000,000 |
| 👛 | 2020-12-21 | Exmo | $10,500,000 |
| 2020 | TOTAL | $302,700,000 | |
| 👛 | 2016-10-13 | Bitcurex | $1,500,000 |
| 👛 | 2017-01-01 | Bithumb | $14,000,000 |
| 👛 | 2017-01-01 | Youbit aka Yapizon aka Coinbin | $7,450,000 |
| 👛 | 2017-05-12 | Wannacry | $Unknown |
| 👛 | 2017-07-15 | 2017 Cryptojacking Incidents | $Unknown |
| 👛 | 2018-04-12 | Coinsecure | $3,500,000 |
| 👛 | 2018-06-09 | Coinrail | $37,000,000 |
| 👛 | 2018-09-01 | Indodax | $24,900,000 |
| 👛 | 2018-09-14 | Zaif | $59,000,000 |
| 👛 | 2018-Jun-?? | Bithumb | $31,500,000 |
| 👛 | 2019-03-23 | Etbox | $132,000 |
| 👛 | 2019-03-26 | BiKi | $12,300,000 |
| 👛 | 2019-06-30 | Bitcoin Norway (AlphaPoint) | $500,000 |
| 👛 | 2019-11-27 | Upbit | $48,500,000 |
| 👛 | 2019-Mar-?? | Bithumb | $16,000,000 |
| 2019-2016 | TOTAL | $256,282,000 |
- aka: Gleaming Pisces, Labyrinth Chollima, Hidden Cobra, DEV-0139
- Has been active since at least 2018. Today they aren't seen hacking as much. They seem to sometimes have a relationship with ITW or Contagious Interview guys? They also have shitcoin farms but we don't talk about that.
- Nick Franklin has his own folder. Because he's special.
| 📁 | Date | Incident | Amt Stolen |
|---|
| 🍎 | 2018-04-21 | Gate.io | $234,000,000 | | 🍎 | 2019-03-24 | DragonEx | $7,090,000 | | 🍎 | 2021-01-22 | Indodax ATO | $2,830,000 | | 🍎 | 2021-05-12 | 990.1 BTC | $55,600,000 | | 🍎 | 2021-07-13 | Advcash | $14,000,000 | | 🍎 | 2021-07-13 | Tower Capital | $Unknown | | 🍎 | 2022-09-22 | DWF Labs | $45,150,000 | | 🍎 | 2022-11-02 | Deribit | $28,000,000 | | ❓ | 2023-11-07 | NFT Phishing | $1,077,186 | | 🍎 | 2023-07-01 | PolyNetwork | $10,000,000 | | 🍎 | 2024-10-16 | Radiant | $58,000,000 | | | 2024-2018 | TOTAL | $455,747,186 |
- Overlaps with Contagious Interview a lot. IT Workers Have resumes. Get hired. Get paid payroll that goes to DPRK.
- Will hack via backdoors, stealing private keys. Will also get hacked. Will also extort. They are creative little fucks.
- The IT Workers also get their own folder.
- There's also the lazarus.group site which is pretty.
- They also have a dust collector in their midst: 💼 DPRK IT Laundry Dust Collector ae69 (0xae69012d15d6b1a3b2412aadef712f06f9286e0e)
| 📁 | Date | Incident | Amt Stolen |
|---|---|---|---|
| 💼 | 2025-05-08 | LND FI | $500,000 |
| 💼 | 2025-06-18 | Chainsaw | $350,000 |
| 💼 | 2025-06-19 | Bunzz | $5,500 |
| 💼 | 2025-06-25 | Favrr | $650,000 |
| 💼 | 2025-09-11 | Shibarium | $2,000,000 |
| 2025 | TOTAL | $3,505,500 | |
| 💼 | 2024-03-26 | Munchables | $62,000,000 |
| 💼 | 2024-03-29 | Solareum | $1,114,813 |
| 2024 | TOTAL | $63,114,813 | |
| 💼 | 2023-01-01 | Various 2023 Rug Pulls | $350,000 |
| 💼 | 2023-04-10 | Terraport | $3,900,000 |
| 💼 | 2023-04-26 | Merlin DEX | $1,800,000 |
| 💼 | 2023-10-05 | Blockbusters Tech | $Unknown |
| 2023 | TOTAL | $6,050,000 | |
| 💼 | 2022-01-11 | MetaPlay ITW Theft | $2,700,000 |
| 💼 | 2022-02-04 | DEPO ITW Theft | $1,723,632 |
| 💼 | 2022-12-01 | Pixelcraft Potential IT Worker | $0 |
| 2022 | TOTAL | $4,423,632 | |
| 💼 | 2018-01-01 | Marine Chain | $Unknown |
| 💼 | 2021-03-05 | Paid Network | $160,000,000 |
| 💼 | 2021-08-12 | DAO Maker | $7,000,000 |
| 2021 | TOTAL | $167,000,000 |
- "Willo" Job Campaigns, Bybit assessment, trevorgreer, Beavertail, Invisible Ferret
- Connects cases onchain. Is a real fucking mess. Stargate / Defiway / RhinoFi / Railgun / Dust Collectors.
| 📁 | Date | Incident | Amt Stolen |
|---|---|---|---|
| 🎙️ | 2025-01-09 | Crypto Staker Theft | $13,000 |
| 🎙️ | 2025-02-15 | Misc CI Thefts | $Unknown |
| 🎙️ | 2025-04-14 | Atlos | $10,000 |
| 🎙️ | 2025-04-23 | Oxya Admin Key Mint | $45,221 |
| 🎙️ | 2025-04-25 | Malicious Du-store Repo | $217,190 |
| 🎙️ | 2025-04-29 | Malicious BbaudConferenceDV Repo | $7,919 |
| 🎙️ | 2025-06-03 | SpaceM | $187,090 |
| 🎙️ | 2025-06-22 | Hacken HAI Token Mint | $267,000 |
| 🎙️ | 2025-06-27 | Noya AI | $236,000 |
| 🎙️ | 2025-07-10 | Malicious Store-V Repo | $44,000 |
| 🎙️ | 2025-07-17 | Open Fabric | $241,000 |
| 🎙️ | 2025-07-23 | Malicious Blackbaud Moon Monkey Repo | $120,000 |
| 🎙️ | 2025-08-11 | Unknown Canadian Victim | $250,000 |
| 🎙️ | 2025-08-14 | AreonX | $200,000 |
| 🎙️ | 2025-09-06 | Unknown Sep 6 2025 Theft | $60,000 |
| 🎙️ | 2025-09-23 | Seedify | $1,700,000 |
| 🎙️ | 2025-10-18 | Unknown Oct 18 2025 Theft | $120,000 |
| 🎙️ | 2025-10-21 | YourCryptoFren | $300,000 |
| 🎙️ | 2025-10-27 | Capital DAO | $320,000 |
| 2025 | TOTAL | $4,338,420 | |
| 🎙️ | 2024-01-22 | ConcentricFi | $1,720,000 |
| 🎙️ | 2024-01-25 | Wall Street Memes | $2,500,000 |
| 🎙️ | 2024-02-01 | Linkedin Job Dev Scam | $200,000 |
| 🎙️ | 2024-02-27 | Serenity Shield | $586,000 |
| 🎙️ | 2024-02-28 | Braintrust Job Dev Scam | $100,000 |
| 🎙️ | 2024-03-05 | MurAll | $278,000 |
| 🎙️ | 2024-03-13 | CloudAI | $309,400 |
| 🎙️ | 2024-03-16 | Wilder World | $2,314,583 |
| 🎙️ | 2024-04-02 | Unknown Apr Victim | $815,000 |
| 🎙️ | 2024-04-11 | Endblock | $72,000 |
| 🎙️ | 2024-05-06 | Genius / GNUS Token | $1,262,630 |
| 🎙️ | 2024-05-22 | Exclusible Penthouse | $820,000 |
| 🎙️ | 2024-05-28 | HYVE | $100,000 |
| 🎙️ | 2024-05-29 | SpaceCatch | $200,000 |
| 🎙️ | 2024-08-07 | Bitgert / BRISE | $437,000 |
| 🎙️ | 2024-08-07 | Nexera | $1,900,000 |
| 🎙️ | 2024-09-13 | HODL Token | $160,000 |
| 🎙️ | 2024-09-19 | NiiFi | $Unknown |
| 🎙️ | 2024-09-20 | Masa | $175,000 |
| 🎙️ | 2024-10-18 | Tapioca | $4,700,000 |
| 🎙️ | 2024-10-30 | Bitbucket Dev Scam | $Unknown |
| 🎙️ | 2024-10-31 | Scallop | $165,000 |
| 🎙️ | 2024-11-15 | Nov 15 Contagious Interview | $Unknown |
| 🎙️ | 2024-12-05 | Fake UltraX Dex Job Scam | $110,000 |
| 🎙️ | 2024-12-12 | Willo Campaign | $64,020 |
| 2024 | TOTAL | $18,988,633 | |
| 🎙️ | 2023-08-17 | SPooCK | $38,032 |
| 🎙️ | 2023-11-10 | Waygate | $200,000 |
| 🎙️ | 2023-11-14 | UnoRe DAO | $219,000 |
| 🎙️ | 2023-12-12 | OKX Dex | $2,390,976 |
| 🎙️ | 2023-12-28 | Upwork Developer Jobs Scams | $550 |
| 2023 | TOTAL | $2,848,558 |
| Date | Incident | MSMT Attribution | Tay Notes | |
|---|---|---|---|---|
| 2024-01-22 | ConcentricFi | DPRK IT workers | 👍 | 🎙️ CI Classic |
| 2024-01-25 | Wall Street Memes | DPRK IT workers | 👍 | 🎙️ CI Classic |
| 2024-03-05 | MurAll | DPRK IT workers | 👍 | 🎙️ CI Classic |
| 2024-03-13 | CloudAI | DPRK IT workers | 👍 | 🎙️ CI Classic |
| 2024-03-15 | NFPrompt | CryptoCore | 👍 | 🔑 SQ Fake Zoom |
| 2024-04-29 | Rain | CryptoCore | 👍 | 🔐 Same as M2 |
| 2024-05-15 | ALEX Labs | CryptoCore | 👍 | 🔑 SQ Same as Irys |
| 2024-05-29 | SpaceCatch | DPRK IT workers | 👍 | 🎙️ CI Classic |
| 2024-05-31 | Bitcoin DMM | TraderTraitor | 👍 | 👛 TR |
| 2024-06-22 | CoinStats | TraderTraitor | 👍 | 👛 TR |
| 2024-07-01 | Kyrrex | TraderTraitor | 👍 | 👛 TR |
| 2024-07-15 | Irys | CryptoCore | 👍 | 🔑 SQ |
| 2024-07-18 | Wazirx | TraderTraitor | 👍 | 👛 TR |
| 2024-08-07 | Nexera | DPRK IT workers | 👍 | 🎙️ CI Classic |
| 2024-09-10 | Indodax | TraderTraitor | 👍 | 👛 TR |
| 2024-09-20 | BingX | TraderTraitor | 👍 | 👛 TR |
| 2024-10-17 | Radiant Capital | Citrine Sleet | 👍 | 🍎 AJ |
| 2024-10-31 | M2 Exchange | CryptoCore | 👍 | 🔐 Same as Rain |
| 2025-01-23 | Phemex | TraderTraitor | 👍 | 👛 TR |
| 2025-02-17 | Ripio | CryptoCore | 👍 | 🔐 Rookery Cap Style |
| 2025-02-21 | Bybit | TraderTraitor | 👍 | 👛 TR |
| 2025-02-28 | Private victim | CryptoCore | 👍 | 🔑 Fake Zoom SDK |
| 2025-06-18 | Favrr | DPRK IT workers | 👍 | 💼 ITW |
| 2025-07-15 | BigONE | TraderTraitor | 👍 | 👛 TR |
| 2024-01-16 | Hector Network | DPRK (Unidentified) | 🤏 | Prob ITW |
| 2024-02-10 | PlayDapp | TraderTraitor | 🤏 | Prob SQ |
| 2024-05-22 | Exclusible Penthouse | DPRK (unidentified) | 🤏 | 🎙️ CI Classic |
| 2024-09-25 | Truflation | DPRK (Unidentified) | 🤏 | 🔑 SQ |
| 2024-10-18 | Tapioca DAO | DPRK (Unidentified) | 🤏 | 🎙️ CI Classic |
| 2025-03-21 | Zoth.io | TraderTraitor | 🤏 | 🔑 SQ Same as Feb 28 |
| 2025-05-00 | BitPro | DPRK (Unidentified) | 🤏 | ❓ DPRK, maybe like Rain |
| 2024-06-04 | Lykke | DPRK (Unidentified) | ❓ | If it is SHOW ME |
| 2024-06-09 | Loopring | TraderTraitor | ❓ | Prob not |
| 2024-03-26 | PrismaFi | DPRK (Unidentified) | ❌ | ❌ Not DPRK |
| 2024-06-10 | UwU Lend | TraderTraitor | ❌ | ❌ Not DPRK |
| 2024-06-22 | BTCTurk | TraderTraitor | ❌ | ❌ Not DPRK |
| 2024-09-16 | DeltaPrime Key Compromise | DPRK IT workers | ❌ | ❌ Not DPRK |
| 2024-09-26 | Onyx DAO | DPRK IT workers | ❌ | ❌ Not DPRK |
| 2024-11-11 | DeltaPrime | DPRK IT workers | ❌ | ❌ Not DPRK |
| 2025-09-09 | SwissBord | DPRK (Unidentified) | ❌ | ❌ Not DPRK |
| Date | Document |
|---|---|
| 2024-03-01 | UN Security Council: 2023 Year End Report |
| 2023-09-01 | UN Security Council: 2023 Midterm Report |
| 2023-03-01 | UN Security Council: 2022 Year End Report |
| 2022-09-01 | UN Security Council: 2022 Midterm Report |
| 2022-03-01 | UN Security Council: 2021 Year End Report |
| 2021-09-01 | UN Security Council: 2021 Midterm Report |
| 2021-03-01 | UN Security Council: 2020 Year End Report |
| 2020-09-01 | UN Security Council: 2020 Midterm Report |
| 2020-03-01 | UN Security Council: 2019 Year End Report |
| 2019-09-01 | UN Security Council: 2019 Midterm Report |
| 2019-03-01 | UN Security Council: 2018 Year End Report |
| 2018-03-01 | UN Security Council: 2017 Year End Report |
| 2017-09-05 | UN Security Council: 2017 Midterm Report |
| 2017-03-01 | UN Security Council: 2016 Year End Report |
| 2016-02-24 | UN Security Council: 2015 Year End Report |
- Also covered by OXT Research (corrections to some of this below)
| Identifier | Entity | Date / Defendant Property |
|---|---|---|
| Exchange 1 | Gate.io Hack (10k BTC, $230m total) | April 21, 2018 |
| Exchange 2 | Youbit Hack ("17% Assets") | April 22nd, 2017 |
| Exchange 3 | Upbit Hack (342,000 ETH) | November 27, 2019 |
| Exchange 4 | Coinrail Hack ($40m) | Summer 2018 |
| VCE 1 | HitBTC/Changelly | DP 63-64 |
| VCE 2 | KuCoin | DP 112 |
| VCE 3 | Bittrex | DP 50-52 |
| VCE 4 | Yobit | DP 92-111 |
| VCE 5 | Huobi | DP 65-70 |
| VCE 6 | CoinCola | DP 55-62 |
| VCE 7 | Paxful | DP 83-84 |
| VCE 8 | LocalBitcoin | DP 71-80 |
| VCE 9 | P2Pb2b | DP 113 |
| VCE 10 | Binance | DP 44-49 |
| VCE 11 | Poloniex | DP 85-90 |
| VCE 12 | Unknown | DP 53-54 |
| Identifier | Entity | Quote |
|---|---|---|
| Exchange 2 | Upbit (Victim) | On November 27, 2019 342,000 ETH was stolen from Exchange 2. |
| Exchange 3 | CoinTiger (Victim) | On July 1, 2019, 400m PTT Tokens were stolen |
| Exchange 4 | HitBTC (Laundry) | All deposit activity for Target Actor 1’s account at Exchange 4 occurred on or about July 1, 2019, the same day as the theft from Exchange 3. The PXG and IHT deposits (17,829,785 PXG @ 2019-07-01 8:42 + 137,793 IHT @ 2019-07-01 13:22) came directly from the theft at Exchange 3. |
| Exchange 5 | BiKi (Laundry) | 1BHnp77MqZGGFaCGQ9J4GhLstPUeBshVcc also received approximately 15 BTC from accounts at Exchange 3 (CoinTiger), Exchange 5 (BiKi), and Exchange 6 (Huobi) |
| Exchange 6 | Huobi (Laundry) | The 4,342,294.43 Yee (“YEE”), 171,145.04 All Sports Coin (“SOC”), 71,237.03 StatusNetworks (“SNT”), and 23,300.29 Cortex Coin (“CTXC”) stolen from CoinTiger were deposited to an account at Exchange 6 on or about July 2, 2019 at 10:29, 22:32, 10:42, and 07:13 respectively. - 0x1016b7835d409692e02ed2035e053fbfb4602982 |
| Exchange 7 | KuCoin (Laundry) | 0x2dbc0f6b71e341c7eca01c5287eb57af3038a9c5 also received approximately 41,702 USDT from an account at Exchange 7” via 14 transactions between August 12, 2019 and August 14, 2019. - e.g. txn 0xa690bf67b9347ac0ca155a473df26d91b20a62acc63546863dae0b1418c11782 |
| Exchange 8 | Switchain (Laundry) | 0x2dbc0f6b71e341c7eca01c5287eb57af3038a9c5 sent the USDT to Exchange 8, converted to BTC, and withdrawn to 1BHnp77MqZGGFaCGQ9J4GhLstPUeBshVcc. On or about December 20, 2019, Exchange 8 received approximately 8.65658 ETH that was converted to 0.15012721 BTC e.g. txn bf4f4c33fb1613524ad72cd082adb42d1816b1aef8907ce30b73bf9b78078c94 |
| Exchange 9 | Changelly? (Laundry) | In December 2019, Target Actor 1 attempted to convert ETH to BTC through a cryptocurrency trading platform “Exchange 9” which was designed to enable the transfer of one form of cryptocurrency in exchange for another. The stolen REP in 0x2DBC0f6B71e341C7Eca01c5287Eb57AF3038A9c5 was then sent to Exchange 9, converted to BTC, and also withdrawn to cluster 1BHnp. The funds associated with Order ID 6918d31f-097c-4afe-8d06-054dd38a34ac are currently frozen at Exchange 9, pursuant to their own internal policies. |
| Exchange 10 | Algo Capital (Victim) | U.S. Algorand crypto company hacked on September 25, 2019 - Defendant Property 25–130 |
| Exchange 11 | Binance (Laundry) | The photos submitted to Exchange 11 were likely stolen during the 2018 hack of a U.S.-based CEX where IDT Victim 1 was a customer. |
| Exchange 12 | Unknown | Algo Capital's Binance Account also sent approximately 2.0285 BTC to an account at Exchange 12. |
USA v PARK JIN HYOK (2018)
- Chosun Expo
- Sony Pictures Entertainmnet
- Mammoth Screen
- AMC Pictures
- WannaCry
- Lockheed Martin
- Bangladesh Bank
- Philippine Bank
| Entity | Description |
|---|---|
| Sony Pictures | Sony Pictures Entertainment Inc. |
| AMC Theatres | |
| Mammoth Screen | A United Kingdom television production company |
| African Bank | A bank headquartered in a country in Africa |
| Bangladesh Bank | The central bank of Bangladesh, was headquartered in Dhaka, Bangladesh |
| Bancomext aka Banco Nacional De Comercio Exterior | A Mexican state-owned bank headquartered in Mexico City, Mexico |
| Maltese Bank | A bank headquartered in Malta |
| BankIslami aka BankIslami Pakistan Limited | A bank headquartered in Karachi, Pakistan |
| New York Financial Services Company | A financial services company headquartered in New York, New York |
| Polish Financial Supervision Authority | The financial regulatory authority for Poland, and was based in Warsaw, Poland |
| Philippine Bank | A bank headquartered in Makati, Philippines |
| Far Eastern International Bank | A bank headquartered in Taipei, Taiwan |
| Vietnamese Bank | A bank headquartered in Hanoi, Vietnam |
| Indodax aka Indonesian Cryptocurrency Company | A cryptocurrency exchange based in Jakarta, Indonesia |
| South Korean Cryptocurrency Company | A cryptocurrency exchange based in the Republic of Korea |
| NiceHash aka Slovenian Cryptocurrency Company | A crypto-mining company headquartered in Ljubljana, Slovenia |
| Central American Online Casino 1 | An online casino business headquartered in a Central American country |
| Central American Online Casino 2 | An online casino business headquartered in a Central American country |
| Date | Location / Bank | Details |
|---|---|---|
| Dec 2015 | Guatemala | Reported loss of $16M USD |
| Dec 2015 | Vietnam Tien Phong Bank |
Attempted theft of more than 1 million Euro ($1.1M USD) of funds through fraudulent SWIFT messages according to statement Tien Phong Bank later issued |
| Feb 2016 | Bangladesh Bangladesh Bank |
Attempted theft of $951M USD |
| May 2016 | South Africa / Japan Standard Bank |
Reported theft of $18M USD from Standard Bank that caused a malfunction of the system shortly before the cash was withdrawn from ATM machines at convenience stores in Tokyo and 16 prefectures across Japan with forged cards made with data stolen from credit cards issued by the bank. A reply from the Government of Japan to the Panel dated 25 July 2019 stated, “As of 9 July 2019, approximately 260 suspects, including organized crime group members, have been arrested, and the total amount of the cash illegally withdrawn from the ATMs across Japan was approximately 1.86 billion yen. The suspects used forged cards with data of roughly 3,000 pieces of customer information stolen from the Standard Bank in the Republic of South Africa, in order to withdraw cash from approximately 1,700 ATMs located in Tokyo and 16 prefectures across Japan. The case is still under investigation.” |
| Jul 2016 | India | Attempted theft of $166M USD using tactics and techniques similar to February 2016 attack on Bangladesh Bank. Funds were transferred to the Canadia Bank Plc and RHB IndoChina Bank Ltd in Cambodia, the Siam Commercial Bank in Thailand, Bank Sinopac in Taiwan Province of China, and a bank in Australia (routed by Citibank New York and JP Morgan Chase New York). |
| Jul 2016 | Nigeria | Attempted theft of $100M USD |
| Oct 2017 | Tunisia | Attempted theft of $60M USD |
| Oct 2017 | Taiwan Far Eastern International Bank |
Attempted theft of $60M USD from Far Eastern International Bank. All but $500,000 recovered by the bank |
| Jan 2018 | Mexico Bancomext |
Attempted theft of $110M USD from Bancomext |
| Jan 2018 | Costa Rica | Attempted theft of $19M USD. “A private financial institution experienced an alleged cyberattack in Costa Rica in January 2018. An investigation has been launched by the Offic e of the Public Prosecutor's Division on Fraud. On July 17, 2019, the Division delegated the investigation to the Ministry of Science, Technology and Telecommunication. Because the investigation is still ongoing, it is not possible for the Mission to provide the Panel with any result.” |
| Feb 2018 | India City Union Bank |
Attempted theft of $16.8M USD from City Union Bank using techniques similar to February 2016 attack on Bangladesh Bank. |
| Mar 2018 | Malaysia | Attempted theft of $390M USD. 29 March 2018 cybersecurity incident involving attempted unauthorized fund transfers using falsified SWIFT messages |
| May 2018 | Chile Banco de Chile |
Theft of approximately $10M USD from Banco de Chile through unauthorized transactions using SWIFT, mainly to Hong Kong. The hackers distracted bank employs from the theft by using malware to render 9000 bank owned computers inoperable. |
| Jun 2018 | Liberia | Attempted theft of $32M USD |
| Aug 2018 | India Cosmos Bank |
Reported theft of $13M USD through attack on Cosmos Bank through simultaneous ATM withdrawals across 23 countries in five hours as well as the transfer of 139 million Rupees to a Hong Kong-based company’s account in three unauthorized SWIFT transactions. On 8 October 2018 the United States included this and other similar DPRK attacks in its alert regarding the “FASTCash Campaign” |
| Oct 2018 | Chile Redbanc |
Attack on Redbanc using malware called POWERRATANKBA. Sophisticated social engineering via LinkedIn, Skype. |
| Feb 2019 | Malta Bank of Valletta |
Attempted theft of $14.5M USD from the Bank of Valletta (BOV) on 13 February. Before being reversed, transfers were made to banks located in the UK, the US, Czech Republic, and Hong Kong, China. “phishing” activity using the same digital fingerprint had been detected since October 2018. |
| Feb 2019 | Spain | Attempted theft of $10.8M USD. Spain’s National Cryptologic Centre (CCN), under the National Intelligence Centre stated in its 2019 Cyberthreats and Trends report that hackers associated with the DPRK government conducted the largest number of reported cyberattacks against Spain in 2018. |
| Mar 2019 | Gambia | Attempted theft of $12.2M USD |
| Mar 2019 | Nigeria | Attempted theft of $9.3M USD |
| Mar 2019 | Kuwait | Reported theft of $49M USD |
| Feb 2017 | Bithumb #1 ROK |
Theft of $7M USD in first attack on Bithumb |
| Apr 2017 | Youbit #1 ROK |
Theft of $4.8M USD in first attack on Youbit (3618 Bitcoin) |
| May 2017 | WannaCry Global |
WannaCry attack resulted in Bitcoin laundered through Monero 144,000 USD (52 Bitcoin) |
| Jul 2017 | Bithumb #2 ROK |
Reported theft of more than $7M USD in second attack on Bithumb including: 870,000 USD in Bitcoin and $7M USD in Bitcoin and Ethereum. National Intelligence Services attributed to the DPRK. |
| Summer 2017 | Cryptojacking ROK |
25,000 USD (70 Monero) through Monero cryptojacking / mining through illegal seizure of a Republic of Korea company server. According to a news article, an assessment by Kwak Kyoung-ju at the Republic of Korea Financial Security Institute attributed the seizure of a server at an ROK to a hacking unit called “Andariel”. Sam Kim, “North Korean Hackers Hijack Computers to Mine Cryptocurrencies” Bloomberg, 31 December 2017 |
| May-Sep 2017 | ROK | ROK Police reported attacks on three cryptocurrency exchanges by DPRK actors and detailed that 25 employees at four different exchanges were targeted in 10 separate “spear phishing” attempts since July 2017 |
| 23 Sep 2017 | Coinis ROK |
Theft of undisclosed amount of Bitcoin in attack on Coinis. Possibly $2.19M USD. Total of $6.99M USD reported in losses from this and the April 2017 Youbit attack combined |
| Dec 2017 | Youbit #2 ROK |
Theft of 17% of Youbit assets in second attack on Youbit. Youbit later declared bankruptcy as a result of hack. |
| Dec 2017 | NiceHash Slovenia |
Reported theft of $70M USD from the bitcoin mining company, NiceHash, which reported “a highly professional attack with sophisticated social engineering” that resulted in approximately $63.92M USD of Bitcoin being stolen. |
| Jun 2018 | Bithumb #3 ROK |
Third attack on Bithumb. Bithumb announced in a since deleted tweet that hackers stole approximately $31 million. Proceeds were laundered through a separate crypto-currency exchange called YoBit. |
| Aug 2018 | India | Reported theft of $13M USD |
| Oct 2018 | Bangladesh | Attempted theft of 2.6M USD |
| Mar 2019 | DragonEx Thailand/Singapore/Hong Kong, China |
Reported theft of 9M USD from DragonEx. According to the company’s Twitter and LinkedIn accounts, it is based in Singapore. The LinkedIn page states, “Registered in Singapore, Operation Department headquartered in Bangkok.” However, Singapore indicated to the Panel that it does not currently have any registration information for a company under the name of DragonEx. Singapore further stated, “We note that DragonEx’s announcement of 27 March 2019 on its Telegram channel states that the Hong Kong Cyber Security and Technology Crime Investigation Bureau is investigating the incident.” DragonEx stated in its announcement of the cyberattack that it informed the judicial administrations of Estonia, Thailand, Singapore and Hong Kong. For more information on the attack, see http://www.coinwire.com/360-security-warns-about-lazarus-hacker-group and https://www.secrss.com/articles/9511 |
| Mar 2019 | Bithumb #4 ROK |
Reported theft of 20M USD in fourth attack on Bithumb (3M EOS and 20 million Ripple coins stolen worth $13.4M USD and 6M USD, respectively) |
| May 2019 | UpBit ROK |
UpBit attacked. No losses reported. |
-
no real purpose. i like rabbitholes, i'm weird. i've follow lazarus for a long, long time
-
i had multiple irl friends back in the day who worked at sony. now i have had multiple friends, founders, builders, users who have been rekt by these same fools, grown up
-
if you read about all the hacks and phishing campaigns in crypto, youre basically reading about lazarus, even if you dont know it
-
realizing there's guys on the other side of the world watching you...who likely know your product and codebase better than some of your own team members...guys who come from such a fundamentally different place than you do with regards to experience, ideology, motivation, and desires...and want to steal all your crypto...it's a lot
-
thus, i dive into my rabbithole for comfort. 🕳️🐇
-
gl.






