Top

North Korean Hackers Take Off With $100M Atomic Wallet Honeypot

Policy & Regulation·June 14, 2023, 11:44 PM

Having reported last week on a $35 million hack of Atomic Wallet users’ funds, an update on the matter reveals that the situation is much worse than originally thought, with losses now exceeding $100 million.

Photo by Kenny Eliason on Unsplash

 

5,500 wallets compromised

The attack has sent shockwaves throughout the crypto community, raising concerns about the security of decentralized wallets. Atomic Wallet, an Estonia-based project known for its non-custodial approach where users take full responsibility for storing their assets securely, has been hit hard by this unforeseen breach.

Elliptic, a crypto compliance analysis company, published an update on the situation on Tuesday. According to that blog article, it estimates that approximately 5,500 crypto wallets have been compromised, meaning that losses have risen to more than $100 million, highlighting the severity of the attack.

Despite the significant impact on users, Atomic Wallet has yet to provide an explanation regarding the root cause of these substantial losses. Users have taken to social media in frustration, demanding clarification from the company. Surprisingly, the company’s last direct update on Twitter dates back to June 7, leaving users feeling even more anxious.

 

User frustration

One user, Ezra Carlson, expressed frustration, questioning why Atomic Wallet didn’t warn users when they were aware of the ongoing hack. Carlson tweeted: “@AtomicWallet why won’t AM give me a straight answer about why they didn’t warn me, knowing full well that they were being hacked, that it was not safe to use AM last week before I made a transfer to my wallet that was then hacked.”

Another user, “Real Deal Crypto,” criticized Atomic Wallet’s lack of updates, stating: “Your last update was five days ago — SERIOUSLY?!?!”

Although Atomic Wallet acknowledged reports of compromised wallets on June 3, downplaying the impact by claiming that less than 1% of users were affected, the staggering sum of losses indicates a significant breach. Its last communication on the matter came on June 11 when, in responding to a user, the firm said that it continued to investigate and to await Twitter updates on the matter.

 

Hack tied to North Korea’s Lazarus Group

Elliptic has connected this heist to the notorious Lazarus Group, a cyber-criminal organization with ties to the North Korean regime, responsible for stealing over $2 billion in crypto assets through various thefts. This attribution marks the first time a significant crypto heist has been openly linked to the Lazarus Group since their $100 million exploit of Horizon Bridge in June 2022.

In response to the heist, Elliptic has been collaborating with international investigators and exchanges, mobilizing resources to recover the stolen assets. Their efforts have reportedly led to the freezing of over $1 million worth of funds. However, the thief has adapted its behavior in response to the freezing of assets, turning to the Russia-based Garantex exchange to launder the stolen assets, as noted by Elliptic.

This recent attack adds to a series of notable breaches in the crypto industry. Jimbos Protocol experienced an exploit resulting in a loss of $7.5 million, and Tornado Cash faced a malicious proposal that seized control of its governance in May. According to a report by Chainalysis, crypto hackers made off with an estimated $3.8 billion in 2022, with North Korea being responsible for a significant portion of the attacks.

More to Read
View All
Policy & Regulation·

Aug 23, 2023

Thailand Pushes Back Against Facebook-Enabled Crypto Scams

Thailand Pushes Back Against Facebook-Enabled Crypto ScamsThai authorities are contemplating serious action against social media giant Meta (formerly Facebook), as Thailand battles against fraudulent cryptocurrency schemes and misleading investment advertisements propagated through Facebook, given a rise in the occurrence of such scams.Photo by Dan Freeman on Unsplash200,000 victimsThe Ministry of Digital Economy and Society (MDES) in Thailand has revealed that over 200,000 individuals in the country have fallen victim to fraudulent Facebook advertisements, which tout promises of massive returns through crypto-related investments and other financial opportunities. These deceitful ads have preyed on unsuspecting users, leading to growing concerns about online safety and consumer protection.The fraudulent adverts often make outrageous claims, guaranteeing daily profits as high as 30%. To add credibility, scammers even resort to using images of celebrities and renowned figures from the financial industry as fabricated endorsements. Some ads have gone to the extent of replicating the logos and symbols of the Thailand Securities and Exchange Commission (SEC) and the Stock Exchange of Thailand to establish an appearance of legitimacy.Inadequate responseChaiwut Thanakamanusorn, Minister of MDES, acknowledged that the ministry has engaged in discussions with Facebook regarding the alarming prevalence of these fraudulent ads on its platform.Thanakamanusorn stated: “In the past, the ministry talked to Facebook all the time, but did not screen advertisers, causing damage to Thai people of more than 100,000 million baht.” Despite sending a letter to the platform requesting the removal of more than 5,301 misleading advertisements, Facebook’s response has been inadequate in addressing the issue effectively.In the face of Facebook’s reluctance to take appropriate action against these fraudulent ads and the substantial financial damage amounting to $2.8 million, MDES has issued a stern warning. Should Facebook fail to rectify the situation, MDES is prepared to pursue a court-issued shutdown order against the platform within a span of seven days.To protect the public from falling victim to these scams, MDES has advised individuals to exercise caution when encountering ads that promise exorbitant profits. Moreover, users are urged to be skeptical of endorsements from celebrities, as these images are often manipulated to deceive the public. The ministry also emphasized the importance of verifying the credentials of businesses and platforms before engaging with them.Safeguarding investorsThailand’s regulatory efforts in the cryptocurrency domain have taken a cautious trajectory. Thailand’s Securities and Exchange Commission (SEC) has stepped up its efforts to safeguard investors from crypto scams by instituting stringent guidelines against deceptive crypto marketing.As part of those guidelines, the SEC stated: “It is forbidden to advertise or persuade the general public or do any other act in the manner of supporting the deposit taking & lending service.” Acknowledging the inherent volatility of the crypto market, the SEC has mandated risk-related disclosures for all crypto trading platforms.With Facebook boasting around 48.1 million users in Thailand as of January 2023, the platform holds substantial influence, making the resolution of this issue even more critical. Striking a balance between innovation and regulatory measures is imperative to ensure that online spaces remain safe and conducive to a healthy crypto market.

news
Markets·

Jul 22, 2025

Bit Origin makes first purchase following DOGE treasury announcement

Bit Origin, the Nasdaq-listed (BTOG) pork processor turned crypto mining infrastructure firm, has acquired 40.5 million Dogecoin (DOGE), the company’s first purchase of the world’s largest memecoin by market cap since it announced that it was establishing a Dogecoin treasury. In a press release published on July 17, the Singapore-headquartered company with operations in the United States, Canada and China, set out that it would become the “first publicly listed company on a major US exchange to accumulate Dogecoin as a core asset.”Photo by Kanchanara on Unsplash$500 million treasury fundingThe firm outlined that it had entered into agreements with accredited investors, implicating the sale of $400 million in Class A ordinary shares in the company. An additional $100 million unlocked via convertible debt brought funding for its Dogecoin treasury to $500 million. Jinghai Jiang, Bit Origin’s CEO and Chairman, asserted that “what started as a joke has evolved into a globally liquid asset with a payments utility.” Jiang asserted that very few digital assets match the settlement speed and scale of community that Dogecoin offers. X Money potentialIn particular, he singled out the potential use of DOGE for X Money, a new payment system that is in the process of being established by Elon Musk’s X social media platform. Alongside many proponents of the cryptocurrency, Bit Origin is hoping that Musk will implement the use of DOGE to power X money. Jiang added:“In an age of broken institutions, Doge embodies a shared culture of optimism and resilience that transcends existing political and financial systems.” On social media, the company outlined that it believes in “Dogecoin not just as a meme, but as a future payments backbone.” Having utilized the services of Chardan Capital Markets as a placement agent, the company has already completed an initial closing of $15 million under the convertible debt facility that has been established.  On July 21, Bit Origin published another press release, detailing the acquisition of 40,543,745 DOGE with the memecoin holding having been purchased at an average acquisition cost of $0.2466 per DOGE.  Nearing inflection point for paymentsCommenting on the development, Jiang stated:“From our experience in mining, we understand the tradeoffs that define proof-of-work systems. We see Dogecoin’s utility potential for micropayments nearing an inflection point, driven by renewed developer activity and broader institutional interest in tokenization.” Dogecoin emerged in December 2013 having been developed by Jackson Palmer and Billy Markus as a joke. The project borrowed much of its code from Bitcoin. Despite having originated as a joke, the project has developed a sizeable community. The digital asset currently holds a market capitalization of $40.5 billion, according to CoinMarketCap data.  Bit Origin rebranded from China Xiangtai Food Co., Ltd. in April 2022. Up until that point, it had been involved in the pork processing business. The company pivoted to crypto mining, partnering with MineOne on a Wyoming mining facility in the United States. The facility was ordered to be shut down by the former Biden administration on the basis of it being a national security risk to have a Chinese project located within a mile of a U.S. Air Force base that houses nuclear intercontinental ballistic missiles.

news
Policy & Regulation·

Sep 22, 2023

Linear Finance Dealing With LUSD Exploit

Linear Finance Dealing With LUSD ExploitLinear Finance, the Hong Kong-based DeFi protocol, made an announcement by way of a blog post published to the project’s website on Thursday, suggesting that the project’s native stablecoin, LUSD, has come under attack.Photo by Markus Spiske on UnsplashTaking precautionary actionThis security breach has prompted the team to take immediate action to safeguard user accounts and the project’s integrity. The project team is actively investigating the exploit attack on LUSD. It has issued a stern warning to its users, advising them against buying or trading LUSD until the team can confirm the situation’s status.This measure is aimed at preventing further complications and ensuring the community’s interests remain protected. Furthermore, the project has temporarily suspended liquidations to secure users’ accounts. This step has been taken to mitigate immediate concerns and ensure that no user faces undue losses as a result of the exploit.Assets disposed on PancakeSwap & AscendexAmid the ongoing investigation, Linear Finance’s team has pledged to provide timely updates as soon as more information becomes available. In explaining away the nature of the attack, the project team clarified:”The attacker was able to mint an unlimited supply of LAAVE and subsequently traded the liquid asset to LUSD on the Linear Exchange, prior to selling it on PancakeSwap and Ascendex.”Project responseIn its efforts to deal with the issue, the Linear Finance project team has engaged an on-chain data specialist to track down the attackers. The Linear bridge contract has been disabled relative to LUSD. All protocol contracts that allow tokens to be minted, exchanged, or burnt have been paused. Meanwhile, wallets identified as having been involved in the protocol exploit have been shared with the authorities and major cryptocurrency exchanges.Synthetic asset protocolLinear Finance creates synthetic assets with the protocol design enabling unlimited liquidity. The network has been built on top of the Ethereum blockchain. As a consequence of activity surrounding the exploit, trading of LUSD over the course of the past 24 hours has proven to be out of the ordinary. At the time of writing volume over the past 24-hour period had increased by 8412%. The current market price of the stablecoin stands at $0.9874.Protocol and network hacks and exploits have been coming in thick and fast in recent days. Hong Kong crypto exchange CoinEx has been trying to recover from a $70 million hack on the platform over recent days. Meanwhile, Seychelles-headquartered peer-to-peer crypto platform Remitano suffered a $2.7 million hack late last week.On Wednesday, the project team behind DeFi protocol Balancer warned network users that the Balancer front-end user interface was under attack. The Ethereum-based DeFi network fell victim to another exploit last month, resulting in losses in the region of $900,000.In the dynamic crypto sector, unforeseen events like potential exploits can disrupt the market and sow uncertainty. The issue remains a major challenge both for centralized exchange platforms and DeFi protocols.

news
Loading