Japanese Crypto Firm SBI Loses $21 Million In Suspected North Korean Cyberattack

bitcoinistPublished on 2025-10-03Last updated on 2025-10-03

Abstract

Reports have disclosed that Japanese firm SBI Crypto saw about $21 million siphoned from company-linked wallets on September 24, 2025....

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

Reports have disclosed that Japanese firm SBI Crypto saw about $21 million siphoned from company-linked wallets on September 24, 2025.

Blockchain sleuths flagged the movement, and on-chain traces show funds leaving addresses that start with “0x40d7” and “bc1qx0a2k.”

The assets included Bitcoin, Ethereum, Litecoin, Dogecoin, and Bitcoin Cash. As of this report, the money has not been recovered.

Suspected Lazarus Group Connections

According to blockchain analysts, the transfers followed a clear path: the stolen coins moved through five instant exchanges before being sent into Tornado Cash, the crypto mixer that US authorities sanctioned in 2022.

Source: ZachXBT

Based on reports, the same set of tactics — wallet fingerprints, timing, and routing — match other intrusions linked to the Lazarus Group, the state-linked cyber unit from the DPRK.

A US court’s decision earlier this year to lift some restrictions around mixers has raised fresh concerns that these tools can be reused to hide large thefts.

Infiltration Schemes And Fake Profiles

Investigations have shown the threat is not only technical but social. Reports have disclosed that operatives created dozens of fake identities, bought Social Security numbers, and posed as blockchain developers on platforms such as Upwork and LinkedIn.

Evidence posted on August 13 linked one such fake-developer wallet to a $680,000 exploit of the project Favrr in June 2025. The methods range from phishing and fake job offers to bribery and contractor infiltration, giving attackers ways to penetrate projects from the inside.

BTCUSD trading at $118,960 on the 24-hour chart: TradingView

A Growing Trail Of Stolen Crypto

Based on compiled forensics data, North Korean-linked groups stole more than $1.3 billion across 47 incidents in 2024. That figure jumped higher in 2025, with estimates putting thefts at about $2.2 billion in the first half of the year alone.

Malware campaigns have also been used. In June, Cisco Talos documented “PylangGhost,” a campaign that used bogus coding tests and interview sites to deliver malware.

That malware targeted over 80 browser extensions and popular wallets like MetaMask and Phantom.

Law enforcement has made some moves: US agents seized $7.7 million tied to covert networks, and the FBI dismantled front companies such as Blocknovas LLC and Softglide LLC.

The $21 million breach underscores how exposed even major firms remain to state-backed hacking campaigns. For now, the case stands as another warning: Japanese crypto firm SBI lost $21 million in suspected North Korean cyberattack.

Featured image from Gemini, chart from TradingView

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

Christian, a journalist and editor with leadership roles in Philippine and Canadian media, is fueled by his love for writing and cryptocurrency. Off-screen, he's a cook and cinephile who's constantly intrigued by the size of the universe.

Related Reads

Trump's 'Bitcoin Retirement Plan' Hits Roadblock: Democrats Claim It Endangers American Workers' Pensions?

Democratic Senators Bernie Sanders (I-VT) and Elizabeth Warren (D-MA), along with Rep. Bobby Scott (D-VA), are urging the Labor Department to repeal a proposed rule that would open U.S. retirement savings accounts, like 401(k) plans, to investments in Bitcoin and other cryptocurrencies. In a letter to Acting Labor Secretary Keith Sonderling, they argue the rule would endanger workers' financial futures and contradicts long-standing legal precedents under the Employee Retirement Income Security Act (ERISA). The rule, stemming from a Trump executive order, would shift the legal standard for plan fiduciaries. Instead of requiring them to prove they conducted due diligence on volatile assets, it would presume prudence if they followed a specified process. The lawmakers warn this exposes the $14.2 trillion in 401(k) savings to highly volatile and less-regulated assets, citing FINRA warnings on crypto's risks and FBI data on massive crypto scam losses. The letter also alleges a conflict of interest, noting that President Trump's adult children manage the family's crypto business, which has raised billions. They claim the rule could allow the Trump family to profit at the expense of workers and retirees. Consumer advocates echo concerns that it could turn retirement savings into a lifeline for a risky industry. The Trump administration defends the rule as expanding worker choice, with officials stating it ends the department "picking winners and losers" and requires fiduciaries to follow a prudent process.

foresightnews_api1m ago

Trump's 'Bitcoin Retirement Plan' Hits Roadblock: Democrats Claim It Endangers American Workers' Pensions?

foresightnews_api1m ago

Rules Change Mid-Game, Polymarket’s Billion-Dollar Bitcoin Prediction Market Mired in Settlement Controversy

A nearly $150 million prediction market contract on Polymarket is in turmoil after the platform refused to settle in favor of traders who correctly predicted that MicroStrategy (now Strategy) would sell Bitcoin. The core dispute revolves around a sale of 32 BTC, which occurred between May 26-31 but was officially disclosed in an SEC 8-K filing on June 1. The original contract stated it would resolve to "Yes" if Strategy sold any Bitcoin before May 31, 11:59 PM ET, using public disclosures and on-chain data as proof. After the filing on June 1, traders who saw the disclosure rushed to buy "Yes" contracts, believing it was conclusive evidence. However, Polymarket's operators later added a rule that the disclosure itself must occur by the deadline, not just the transaction, invalidating the filing as proof. This retroactive rule change has sparked accusations of market manipulation, leaving traders like "willo2," who invested $527,000, facing total losses. The controversy highlights a deeper structural flaw in Polymarket's decentralized settlement system, which relies on UMA's optimistic oracle. Disputed resolutions are ultimately decided by a vote among UMA token holders, a mechanism critics say is vulnerable to manipulation by large holders ("whales") who can vote in their own financial interest rather than on objective facts. Data suggests a high concentration of voting power and significant overlap between voters and Polymarket traders. The dispute emerges as prediction markets like Polymarket and Kalshi are experiencing massive growth and seeking mainstream financial legitimacy, having recently secured regulatory approval from the U.S. CFTC. However, the incident underscores the unresolved tension between decentralized, token-vote-based settlement and the need for transparent, rules-based outcomes in high-stakes financial contracts.

foresightnews_api4m ago

Rules Change Mid-Game, Polymarket’s Billion-Dollar Bitcoin Prediction Market Mired in Settlement Controversy

foresightnews_api4m ago

Ethereum Foundation Researcher: Quantum Day Is Approaching, Plans to Complete Quantum-Resistant Migration by 2029

Ethereum Foundation researcher Justin Drake discusses the implications of a recent quantum computing breakthrough by Google’s quantum AI team, which demonstrated a 10x efficiency improvement in Shor’s algorithm against the secp256k1 elliptic curve used in Bitcoin and Ethereum. Notably, Google kept key algorithmic details confidential, using zero-knowledge proofs to verify the result without disclosure—a first in academia. Shortly after, the core optimization was independently reproduced, and an open-source competition (ecdsa.fail) emerged, further improving the algorithm by 8.4%. Meanwhile, startup Oratomic published research suggesting that neutral-atom quantum architectures could break secp256k1 with only 10,000 physical qubits, accelerating the timeline for "Q-Day"—the day quantum computers can break widely used cryptography. Drake estimates a 50% probability of Q-Day by 2032 and a 10% chance by 2030, contrasting with the U.S. government’s more conservative 2035 forecast. He warns against panic but stresses timely migration to post-quantum cryptography. Ethereum plans to complete its migration by 2029, covering consensus, data, and execution layers with hash-based systems. The Foundation is also developing leanVM, a formally verifiable zkVM, and has launched two $1 million initiatives to advance SNARK-friendly cryptography.

foresightnews_api5m ago

Ethereum Foundation Researcher: Quantum Day Is Approaching, Plans to Complete Quantum-Resistant Migration by 2029

foresightnews_api5m ago

Trading

Spot
Futures
活动图片