North Korean Hackers Tied to $351 Million Exchange Exploit
A prominent cryptocurrency exchange suffered a severe security breach on Thursday, resulting in the loss of nearly $351 million from its hot and warm wallets. Platform executives and blockchain investigators are currently pointing to North Korea’s Lazarus Group as the prime suspect in the highly coordinated theft.
According to the platform's security team, the perpetrators did not compromise the cold storage infrastructure, nor were any private keys stolen during the intrusion. Instead, the attackers successfully infiltrated a backend wallet system. Once inside the network, they falsified transfer details and manipulated the exchange's standard signing protocols, causing the massive unauthorized outflows to appear as legitimate outgoing transactions.
In response to the exploit, platform leadership immediately suspended user withdrawals to contain the financial damage, though trading operations and user deposits remained active. Chief Executive Officer Gracy Chen assured customers that their digital assets were secure in unaffected wallets. The platform intends to fully cover the financial losses using its dedicated User Protection Fund, which held a balance of more than $464 million at the time of the incident.
Asset Breakdown and Tracing
The single largest digital asset affected by the breach was XRP. Blockchain analytics firm Lookonchain calculated that attackers drained almost 102.9 million tokens of the asset, representing nearly $158 million in extracted value.

The thieves also targeted a wide variety of other digital assets, securing approximately 31,890 Ethereum worth roughly $86 million. The remaining funds were extracted across multiple currencies and tokens, including USDT, USDC, USDT0, tokenized gold (XAUt), BNB, AVAX, and TRX.
On-chain data indicates the hackers rapidly began swapping a large percentage of the stolen EVM-chain assets directly into Ethereum. Analysts at Nansen tracing the money flow identified a primary on-chain cluster where the perpetrators had evenly distributed 40,000 Ethereum across four distinct wallet addresses.
Tracking the Culprits
During a live broadcast detailing the event, Chen noted that specific IP addresses logged during the attack aligned with virtual private network patterns typically associated with the North Korean cyber warfare syndicate, the Lazarus Group. While Chen emphasized that the attribution remains unconfirmed, the collective is widely blamed for numerous high-profile industry exploits, including a $1.5 billion theft from Bybit in 2025.
Independent blockchain researchers are reaching similar conclusions regarding the perpetrators. Onchain Investigator Spector specifically attributed the recent exploit to the TraderTraitor campaign, drawing a direct line between Thursday's event and a previous $24 million hack of the decentralized perpetuals exchange AFX Trade. Spector noted that the XRP taken in the latest attack was bridged and can be linked directly on-chain to the assets stolen during the AFX incident.
Following the breach, the price of the most heavily affected asset fell by more than 1%, trading at $1.53 after previously rebounding over 6% in the preceding 24 hours. Market data from CoinGlass showed derivative selling pressure, with 4-hour futures open interest dropping more than 0.68%, including specific declines of 0.53% on CME and 0.51% on Binance, alongside a 24% drop in overall trading volume ahead of options expiry.



