Github’s Warning: DPRK Hackers Target Crypto and Gambling Sites
In July, Github issued a warning about the targeting of crypto and gambling sites by hackers from North Korea. Now, the Federal Bureau of Investigation (FBI) has confirmed that the Lazarus Group, a hacker collective linked to North Korea, was responsible for the recent attack on Stake, a crypto casino and betting platform.
The FBI revealed that the Lazarus Group managed to steal a staggering $41 million in various cryptocurrencies from Stake.com. This incident serves as a crucial reminder of the constant threat posed by state-sponsored hackers, particularly those from North Korea, to the entire crypto industry.
Known as APT38, the Lazarus Group is notorious for orchestrating attacks on companies, exchanges, DeFi protocols, and bridges, resulting in the theft of hundreds of millions of dollars in crypto. According to US authorities and the United Nations, these illicit activities fund North Korea’s nuclear weapons program.
In the case of Stake.com, the hack carried out by the sophisticated Lazarus Group involved the leakage or theft of a private key to a hot wallet, rather than exploiting a bug in a smart contract. The stolen funds are spread across the Ethereum, BSC, Polygon, and Bitcoin blockchains.
Notably, Github had previously identified North Korean hackers engaging in low-level social engineering campaigns against employees of crypto, blockchain, and gambling-related companies. Additionally, Lazarus was implicated in the Axie Infinity Ronin Bridge hack last year, which resulted in the loss of over $600 million worth of crypto. Prosecutors are currently pursuing legal action against a developer accused of creating a mixer used to launder those funds.
Hot Take
The involvement of the Lazarus Group in the recent crypto hack serves as a stark reminder of the persistent threat posed by state-sponsored hackers. As a crypto reader, it is crucial for you to stay vigilant and take necessary precautions to protect your digital assets. Understanding the tactics employed by hackers, such as social engineering and exploiting vulnerabilities in key management, can help you safeguard your crypto holdings. By staying informed and adopting robust security measures, you can contribute to the resilience of the crypto industry against these malicious actors.