{"id":59189,"date":"2023-09-13T08:27:06","date_gmt":"2023-09-13T12:27:06","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=59189"},"modified":"2023-09-13T08:27:09","modified_gmt":"2023-09-13T12:27:09","slug":"lazarus-group-reportedly-behind-55m-coinex-hack","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/lazarus-group-reportedly-behind-55m-coinex-hack\/","title":{"rendered":"Lazarus Group Reportedly Behind $55M CoinEx Hack"},"content":{"rendered":"\n<p>According to blockchain security firm SlowMist and <a href=\"https:\/\/coinscreed.com\/staging\/lazarus-group-allegedly-behind-60m-alphapo-hack-zachxbt.html\">on-chain investigator ZachXBT<\/a>, the attack on cryptocurrency exchange CoinEx that siphoned at least $55 million was conducted by the North Korean hacker group Lazarus. <\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1023\" height=\"617\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/image-36.png\" alt=\"Lazarus Group Reportedly Behind $55M CoinEx Hack\" class=\"wp-image-59192\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/image-36.png 1023w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/image-36-300x181.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/image-36-768x463.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/image-36-18x12.png 18w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/image-36-750x452.png 750w\" sizes=\"(max-width: 1023px) 100vw, 1023px\" \/><figcaption class=\"wp-element-caption\">Lazarus Group Reportedly Behind $55M CoinEx Hack<\/figcaption><\/figure>\n\n\n\n<p>The cyber group was identified after their address was mistakenly linked to the recent Stake and Optimism breaches.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">It appears North Korea is also responsible for the $54M <a href=\"https:\/\/twitter.com\/coinexcom?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@coinexcom<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> hack from yesterday after they accidentally connected their address to the $41M Stake hack on OP & Polygon. <br><br>0x75497999432b8701330fb68058bd21918c02ac59 <a href=\"https:\/\/t.co\/9qZPdc3yhT\" target=\"_blank\">pic.twitter.com\/9qZPdc3yhT<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; ZachXBT (@zachxbt) <a href=\"https:\/\/twitter.com\/zachxbt\/status\/1701905899034390574?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">September 13, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>On September 12, CoinEx observed significant outflows of funds to an address without prior activity. Security experts immediately suspected the exchange had been compromised, with initial estimates of approximately $27 million. <\/p>\n\n\n\n<p>At the time of writing, security firm SlowMist noted that the losses from the exploit had reached more than $55 million.<\/p>\n\n\n\n<p>After the theft, <a href=\"https:\/\/coinscreed.com\/staging\/coinex-exchange-plans-to-remove-all-mainland-china-users-in-october.html\" target=\"_blank\" rel=\"noreferrer noopener\">CoinEx Global<\/a> reassured users that their assets were safe and that affected parties would be &#8220;fully compensated&#8221; for any losses incurred due to the breach. <\/p>\n\n\n\n<p>In addition, the exchange temporarily halted deposits and withdrawals for security reasons. The exchange continued monitoring the situation and promised to disseminate a comprehensive incident report soon.<\/p>\n\n\n\n<p>Based on their on-chain behavior, the hackers appear connected to the recent $41 million breach of the crypto-gambling website Stake. <a href=\"https:\/\/www.usa.gov\/agencies\/federal-bureau-of-investigation\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">The United States Federal Bureau of Investigation <span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>(FBI) concluded on September 7 that the Lazarus Group of North Korea attacked Stake.<\/p>\n\n\n\n<p>The recent attack on CoinEx Global adds enormous sums to the losses caused by crypto space exploits, hacks, and scams. The cybersecurity firm CertiK reported on September 1 that, as of August 2023, nearly $1 billion had been lost to such incidents since January of this year. In August, roughly $45 million was stolen from various evil attacks.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>According to blockchain security firm SlowMist and on-chain investigator ZachXBT, the attack on cryptocurrency exchange CoinEx that siphoned at least $55 million was conducted by the North Korean hacker group Lazarus. The cyber group was identified after their address was mistakenly linked to the recent Stake and Optimism breaches. On September 12, CoinEx observed significant [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":59192,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[4727,1496,16144],"class_list":["post-59189","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-coinex","tag-hack","tag-north-korea-lazarus-group"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/image-36.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/59189","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=59189"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/59189\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/59192"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=59189"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=59189"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=59189"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}