The FBI blamed North Korea's Lazarus Group for Stake.com's $41M theft
Days after a crypto casino's hot wallets were emptied in September 2023, U.S. investigators publicly named the DPRK-linked crew — a rare, fast attribution where thieves usually stay anonymous.
On or about September 4, 2023, roughly $41 million in cryptocurrency drained out of Stake.com, an online crypto casino. Within days the FBI publicly attributed the theft to the Lazarus Group — the North Korean state-linked outfit also tracked as APT38 — as reported by CoinDesk.
The stolen funds were spread across the Ethereum, BSC (BNB Chain), Polygon and Bitcoin blockchains, CoinDesk reported. The intrusion appeared to involve a private key to a hot wallet being leaked or otherwise stolen, rather than any smart-contract exploit.
Stake.com was not an isolated hit. The Lazarus Group has been tied to hundreds of millions of dollars in crypto stolen across exchanges and protocols, CoinDesk reported, making it one of the most prolific forces behind 2023's platform thefts.
Why the attribution matters
Public, specific government attribution is both unusual and unusually fast here: the FBI named Lazarus within days, CoinDesk noted. It fit a documented pattern. North Korean operators have run low-level social-engineering campaigns against employees of crypto, blockchain and gambling firms — a tactic GitHub publicly warned about in mid-2023, per CoinDesk.
The mechanics are worth internalizing. A stolen key does not announce itself; it can be captured through a booby-trapped job offer or a fake app aimed at an insider, then held until the moment funds are moved. By the time withdrawals appear on-chain, the decision to steal was made long before.
That reframes the threat for ordinary readers. The weak point in many 2023 exchange thefts was not code but people and the keys they hold: an employee phished, a credential reused, a hot-wallet key quietly exposed.
Lessons for readers
- Social engineering is the real exploit. State crews target staff, and the same lures — fake jobs, fake apps, unsolicited DMs — reach ordinary users too.
- Hot wallets are convenience, not safety. Money a platform keeps online to pay out quickly is money one leaked key can take.
- Attribution is not recovery. Naming Lazarus does not return the funds; stolen crypto is rarely clawed back.
- Treat high-volume gambling and 'yield' sites as prime targets. Their busy hot wallets make them magnets for professional crews.
Stake.com kept operating, but the FBI's notice was the real signal. The most capable crypto thieves of 2023 were a nation-state's hackers, and their way in was a stolen key — the very same door that guards your own funds.
— Sources: [CoinDesk](https://www.coindesk.com/policy/2023/09/07/north-koreas-lazarus-hackers-stoke-41-million-from-crypto-gambling-site-fbi-says)
NOT FINANCIAL ADVICE · VERIFY EVERYTHING