Atomic Wallet Was Breached by North Korean Hackers: Elliptic (2024)

Atomic Wallet users might have fallen victim to Lazarus, the infamous North Korean hacking group, said blockchain intelligence firm Elliptic in a blog post on Tuesday.

Early Saturday morning, the team behind Atomic, a non-custodial crypto wallet, announced that some users were compromised and lost the funds from their wallets. According to the company, the number of incidents did not exceed 1% of "monthly active users." The announcement followed multiple reports on Reddit from users complaining their wallets had been drained.

ZachXBT, a pseudonymous blockchain sleuth, estimated that around $35 million in various cryptocurrencies had been stolen, including bitcoin (BTC), ether (ETH), tether (USDT), dogecoin (DOGE), litecoin (LTC), BNB coin (BNB), polygon (MATIC) and Tron-based USDT.

The stolen crypto has been funneled to a mixer called Sindbad.io, Elliptic wrote. This mixer, which Elliptic believes is a successor of the previously sanctioned mixer Blender.io, has been often used to launder money from other hacks attributed to Lazarus, and the usage pattern is the same, Elliptic said. The firm also found connections between the wallets containing the loot from Atomic and some of the Lazarus hacks, the blog post reads.

What was hacked

Last year, security audit company Least Authority warned in a blog post that Atomic Wallet may have been vulnerable to breaches. According to Least Authority, issues included the way Atomic implemented cryptography, that it did not adhere to the best practices for wallet design, a lack of robust project documentation and incorrect use of Electron, a framework for building desktop applications. The firm has since taken down the post.

According to Dyma Budorin, CEO of blockchain security firm Hacken, there are several possible explanations for how the hack happened. One reason could be that Atomic's way to generate recovery phrases (the so-called seed phrases) for wallets did not produce sufficiently random sequences of words, making it easier for hackers to brute-force wallets, Budorin told CoinDesk.

Non-custodial wallets like Atomic allow users to keep their crypto autonomously, without trusting a centralized company, which means if users lose a device or password for their wallet they can only recover funds using the seed phrase. However, anyone who has access to the seed phrase can duplicate the wallet and steal the funds.

Another hypothesis is that hackers could have mathematically derived the users’ private keys from the transactions data visible on the bitcoin blockchain. This kind of attack was described in a freshly published paper by researchers at the University of California, San Diego. Hacken also detected that the Android version of Atomic “relied on an outdated and vulnerable dependency” when signing transactions, Budorin said.

Other possibilities include a supply chain attack on the wallet manufacturer, a hack of Atomic’s website or the intentional or unintentional broadcasting of users’ private keys to Atomic’s centralized server, according to Hacken.

According to ZachXBT, over $1 million in funds stolen from a single have been successfully recovered by Jito Labs, a Solana blockchain scaling startup.

"This hack is very vocal, highlighting the core problems in crypto wallets. The wallets don't pay enough attention to building a strong architecture with security best practices implemented," Budorin added.

Atomic CEO Konstantin Gladych told CoinDesk he couldn’t comment on the possible reason for the hack.

The team is now collecting data from affected users and passing it to the blockchain analysis firms like Chainalysis, Crystal and Elliptic, he said, adding that part of the funds landed on exchanges and has been blocked.

“The attack was definitely organized by a team of professional hackers. They’re using scripts, splitting of the funds, mixers, etc.,” Gladych said.

UPDATE (June 6, 2023, 21:30 UTC): Adds comment from Atomic CEO Konstantin Gladych.

UPDATE (June 7, 2023, 16:40 UTC): Corrects the spelling of Dyma Budorin's name.

Edited by Nikhilesh De.

Atomic Wallet Was Breached by North Korean Hackers: Elliptic (2024)

FAQs

Atomic Wallet Was Breached by North Korean Hackers: Elliptic? ›

Elliptic. Elliptic's analysis suggests that North Korea's Lazarus Group is responsible for the theft of cryptoassets suffered by users of Atomic Wallet. At least $35 million has reportedly been stolen from users of Atomic Wallet, a non-custodial cryptocurrency wallet service with five million users worldwide.

How was Atomic Wallet hacked? ›

The attackers were able to exploit a vulnerability in the Atomic Wallet code to steal users' private keys. Private keys are used to sign cryptocurrency transactions, so once the attackers had users' private keys, they were able to steal their cryptocurrency.

What happened to the Atomic Wallet? ›

Concerns regarding security vulnerabilities

Atomic Wallet was the target of a hacking attack in June 2023. The attack affected at least 5,500 accounts on the platform and caused over $100 million in losses.

Is the Atomic Wallet legitimate? ›

Atomic Wallet allows users to safely store, send, and receive cryptocurrencies. It is considered one of the best non-custodial wallets for diversified portfolios. In addition to Bitcoin, Ethereum, and Cardano, Atomic Wallet supports Binance Smart Chain, Monero, Fantom, and other popular networks.

What cryptocurrency did North Korea steal? ›

UNITED NATIONS, May 14 (Reuters) - North Korea laundered $147.5 million through virtual currency platform Tornado Cash in March after stealing it last year from a cryptocurrency exchange, according to confidential work by United Nations sanctions monitors seen by Reuters on Tuesday.

Which country owns Atomic Wallet? ›

Atomic Wallet is a cryptocurrency wallet that was founded in 2017 and headquartered in Tallinn, Estonia.

How do I get my money back from Atomic Wallet? ›

If you want to withdraw money from this wallet to a fiat currency, like US dollars, Euros, or Pounds, you'll have to first transfer your crypto to Zengo (or another wallet or exchange that supports a fiat offramp gateway). You can then withdraw directly from Zengo to your bank account in fiat currency.

Top Articles
Our 2024 Home Chef Review After Cooking the Meals
Fastest-Growing Cities | USA Wealth Report 2024
Katie Pavlich Bikini Photos
Gamevault Agent
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Free Atm For Emerald Card Near Me
Craigslist Mexico Cancun
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Doby's Funeral Home Obituaries
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Select Truck Greensboro
How To Cut Eelgrass Grounded
Craigslist In Flagstaff
Shasta County Most Wanted 2022
Energy Healing Conference Utah
Testberichte zu E-Bikes & Fahrrädern von PROPHETE.
Aaa Saugus Ma Appointment
Geometry Review Quiz 5 Answer Key
Walgreens Alma School And Dynamite
Bible Gateway passage: Revelation 3 - New Living Translation
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Dmv In Anoka
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Pixel Combat Unblocked
Umn Biology
Obituaries, 2001 | El Paso County, TXGenWeb
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Rogold Extension
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Colin Donnell Lpsg
Teenbeautyfitness
Weekly Math Review Q4 3
Facebook Marketplace Marrero La
Nobodyhome.tv Reddit
Topos De Bolos Engraçados
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Holzer Athena Portal
Hampton In And Suites Near Me
Stoughton Commuter Rail Schedule
Bedbathandbeyond Flemington Nj
Free Carnival-themed Google Slides & PowerPoint templates
Otter Bustr
San Pedro Sula To Miami Google Flights
Selly Medaline
Latest Posts
Article information

Author: Arielle Torp

Last Updated:

Views: 5851

Rating: 4 / 5 (61 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Arielle Torp

Birthday: 1997-09-20

Address: 87313 Erdman Vista, North Dustinborough, WA 37563

Phone: +97216742823598

Job: Central Technology Officer

Hobby: Taekwondo, Macrame, Foreign language learning, Kite flying, Cooking, Skiing, Computer programming

Introduction: My name is Arielle Torp, I am a comfortable, kind, zealous, lovely, jolly, colorful, adventurous person who loves writing and wants to share my knowledge and understanding with you.