How more than $100 million drained from Atomic Wallet
In June 2023, thousands of non-custodial wallets emptied within days. Elliptic and the FBI traced the theft to North Korea's Lazarus Group — but the way in was never confirmed.
In the first days of June 2023, users of Atomic Wallet — a non-custodial crypto wallet, meaning its holders control their own private keys — began watching balances vanish. The company acknowledged the incident on June 3. What looked at first like scattered, isolated losses would become one of the year's largest thefts of individual crypto holdings.
Blockchain-analytics firm Elliptic initially put losses near $35 million on June 6, then revised the figure sharply upward. After analyzing more than 5,500 affected wallets, Elliptic concluded on June 13 — and reaffirmed on August 2 — that the theft exceeded $100 million. At least 10 addresses each lost more than $1 million, and 164 each lost more than $100,000, according to Elliptic. Atomic Wallet, for its part, publicly stated that fewer than 1% of its users were affected.
Attribution: North Korea's Lazarus Group
Elliptic linked the drain to North Korea's Lazarus Group on June 6, citing laundering patterns that matched prior DPRK operations. Per Elliptic, the stolen funds moved through the Sinbad mixer — a North Korean favorite — and the OFAC-sanctioned Russian exchange Garantex, and the destination wallets overlapped with proceeds of earlier Lazarus thefts.
The FBI publicly confirmed DPRK responsibility on August 22, 2023, attributing the roughly $100 million Atomic Wallet theft to actors affiliated with TraderTraitor — also tracked as APT38, or Lazarus. According to the FBI, the statement came as investigators traced about 1,580 bitcoin moved from several 2023 heists.
The way in was never confirmed
The most unsettling detail is what investigators still cannot say: how the attackers got in. Elliptic noted there was no explanation from Atomic Wallet regarding the root cause, and the company never disclosed a definitive breach mechanism. For a non-custodial wallet, that gap matters — the whole premise is that only you can move your funds, so a mass drain implies that something reached across thousands of devices or the signing path itself.
Recovery has been minimal. Elliptic and exchange partners froze over $1 million of the stolen assets, according to Elliptic, but the vast majority remains gone. A 21-plaintiff class action filed in U.S. federal court in Colorado was dismissed on September 10, 2024, when Judge Philip Brimmer found that Atomic Wallet, an Estonia-based operation, lacked sufficient U.S. ties for jurisdiction; plaintiffs were given a short window to argue for keeping one shareholder-defendant in the case. As of the latest confirmed reporting, no funds have been returned and no perpetrator has been prosecuted.
What this means for trusting wallet software
A non-custodial wallet removes the exchange as a single point of failure, but it does not remove the software as one. When the code that stores or signs for your keys is compromised — whether through a malicious update, a supply-chain implant, or a flaw never made public — self-custody offers no refuge on its own. Treat the wallet application itself as part of your attack surface, and reduce what any single compromised app can reach.
- Keep signing devices offline. Store meaningful balances on a hardware wallet or an air-gapped device, so a compromised app on an internet-connected machine cannot sign transactions by itself.
- Verify app sources every time. Download and update wallet software only from the official vendor site or a verified app-store listing; check signatures or checksums where offered, and never install from a link someone sent you.
- Limit hot-wallet balances. Keep only what you can afford to lose in any always-online 'hot' wallet, and move the rest to cold storage.
- Segment and watch. Use separate wallets for spending and savings, and monitor high-value addresses so an unexpected outflow is caught early.
— Sources: [Elliptic](https://www.elliptic.co/blog/analysis/north-korea-linked-atomic-wallet-heist-tops-100-million) · [The Record](https://therecord.media/north-korea-lazarus-behind-crypto-heists) · [Cointelegraph](https://cointelegraph.com/news/us-court-dismiss-atomic-wallet-class-suit-lack-jurisdiction)
NOT FINANCIAL ADVICE · VERIFY EVERYTHING