{"id":55354,"date":"2023-07-27T05:54:40","date_gmt":"2023-07-27T09:54:40","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=55354"},"modified":"2023-07-27T05:54:44","modified_gmt":"2023-07-27T09:54:44","slug":"lazarus-group-allegedly-behind-60m-alphapo-hack-zachxbt","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/lazarus-group-allegedly-behind-60m-alphapo-hack-zachxbt\/","title":{"rendered":"Lazarus Group Allegedly Behind $60M Alphapo Hack &#8211; ZachXBT"},"content":{"rendered":"\n<p>A report from crypto investigator ZachXBT states that the <a href=\"https:\/\/coinscreed.com\/staging\/north-koreas-lazarus-group-behind-100-million-horizon-hack-as-harmony-begins-manhunt.html\" target=\"_blank\" rel=\"noreferrer noopener\">North Korean state-backed Lazarus group<\/a> is allegedly behind the Alphapo hack on July 22 due to the group\u2019s &#8220;very distinct fingerprint on-chain.&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"496\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/image-49-1024x496.png\" alt=\"Lazarus Group Allegedly Behind $60M Alphapo Hack - ZachXBT\" class=\"wp-image-55363\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/image-49-1024x496.png 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/image-49-300x145.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/image-49-768x372.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/image-49-750x364.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/image-49.png 1114w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Lazarus Group Allegedly Behind $60M Alphapo Hack &#8211; ZachXBT<\/figcaption><\/figure>\n\n\n\n<p>Lazarus, the notorious North Korean hacker group, has been linked to yet another multimillion-dollar hack, this time affecting Alphapo, a large payment processor associated with gambling sites and e-commerce platforms.<\/p>\n\n\n\n<p>Several hot wallets associated with Alphapo were emptied of more than $23 million in Ethereum (ETH), Bitcoin (BTC), and Tron (TRX) on July 22, according to <a href=\"https:\/\/twitter.com\/zachxbt\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">crypto investigator ZachXBT<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>.<\/p>\n\n\n\n<p>The initial breach, allegedly carried out by Lazarus, resulted in $6 million in USDT tokens, $108,000 in USDC, 2,500 ETH, and several other tokens being drained and exchanged for various stablecoins and Bitcoin via Avalanche.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/hashtag\/PeckShieldAlert?src=hash&ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">#PeckShieldAlert<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> <a href=\"https:\/\/twitter.com\/zachxbt?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@zachxbt<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> has detected that <a href=\"https:\/\/twitter.com\/hashtag\/Alphapo?src=hash&ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">#Alphapo<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> hot wallets were drained for $23M+ worth of cryptos.<br>~6.074M <a href=\"https:\/\/twitter.com\/search?q=%24USDT&src=ctag&ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">$USDT<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>, $108K <a href=\"https:\/\/twitter.com\/search?q=%24USDC&src=ctag&ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">$USDC<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>, 100.2M <a href=\"https:\/\/twitter.com\/search?q=%24FTN&src=ctag&ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">$FTN<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>, 430K <a href=\"https:\/\/twitter.com\/search?q=%24TFL&src=ctag&ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">$TFL<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>, 2.5K <a href=\"https:\/\/twitter.com\/search?q=%24ETH&src=ctag&ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">$ETH<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>, and ~1.7K <a href=\"https:\/\/twitter.com\/search?q=%24DAI&src=ctag&ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">$DAI<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> were drained from <a href=\"https:\/\/twitter.com\/hashtag\/Alphapo?src=hash&ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">#Alphapo<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> to 0x040a&#8230;0d17.<br>The drainer then swapped stablecoins and some other\u2026 <a href=\"https:\/\/t.co\/PGrk9QK2Cr\" target=\"_blank\">https:\/\/t.co\/PGrk9QK2Cr<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> <a href=\"https:\/\/t.co\/obK8qAel3Z\" target=\"_blank\">pic.twitter.com\/obK8qAel3Z<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; PeckShieldAlert (@PeckShieldAlert) <a href=\"https:\/\/twitter.com\/PeckShieldAlert\/status\/1683034275489382401?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">July 23, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>ZachXBT tweeted, &#8220;It remains unclear at this time how much BTC was stolen.&#8221;<\/p>\n\n\n\n<p>Earlier this week, Alphapo suffered a second exploit when <a href=\"https:\/\/coinscreed.com\/staging\/dune-analytics-an-eth-data-firm-raises-8m-from-union-square-and-others.html\" target=\"_blank\" rel=\"noreferrer noopener\">on-chain analytic tools<\/a> identified an additional $37 million in stolen Bitcoin and Tron, bringing the total to $60 million.<\/p>\n\n\n\n<p>ZachXBT reported that Lazarus typically &#8220;creates a distinct fingerprint on-chain,&#8221; indicating that the North Korean group is likely behind the theft.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-north-korean-lazarus-group\">North Korean Lazarus Group<\/h2>\n\n\n\n<p>The Lazarus group is a well-known North Korean cyber organization whose exploits have kept crypto on its toes in recent years.<\/p>\n\n\n\n<p>In the past, the group posed as a venture capital fund in an attempt to disseminate malware, according to blockchain analytics firm Elliptic. The group allegedly stole over $2 billion.<\/p>\n\n\n\n<p>Lazarus stole over $100 million from Atomic Wallet in early June.<\/p>\n\n\n\n<p>The cybercrime syndicate is also linked to the June 2022<a href=\"https:\/\/coinscreed.com\/staging\/north-koreas-lazarus-group-behind-100-million-horizon-hack-as-harmony-begins-manhunt.html\" target=\"_blank\" rel=\"noreferrer noopener\"> $100 million Harmony bridge hack<\/a> and the July 2022 $190 million Nomad bridge breach.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A report from crypto investigator ZachXBT states that the North Korean state-backed Lazarus group is allegedly behind the Alphapo hack on July 22 due to the group\u2019s &#8220;very distinct fingerprint on-chain.&#8221; Lazarus, the notorious North Korean hacker group, has been linked to yet another multimillion-dollar hack, this time affecting Alphapo, a large payment processor associated [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":55363,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[6115,15475,1496,9168,14584],"class_list":["post-55354","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-hackers-2","tag-alphapo","tag-hack","tag-lazarus-group","tag-zachxbt"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/image-49.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/55354","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=55354"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/55354\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/55363"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=55354"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=55354"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=55354"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}