Japanese Crypto Firm SBI Loses $21 Million In Suspected North Korean Cyberattack

bitcoinistPublished on 2025-10-03Last updated on 2025-10-03

Abstract

Reports have disclosed that Japanese firm SBI Crypto saw about $21 million siphoned from company-linked wallets on September 24, 2025....

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

Reports have disclosed that Japanese firm SBI Crypto saw about $21 million siphoned from company-linked wallets on September 24, 2025.

Blockchain sleuths flagged the movement, and on-chain traces show funds leaving addresses that start with “0x40d7” and “bc1qx0a2k.”

The assets included Bitcoin, Ethereum, Litecoin, Dogecoin, and Bitcoin Cash. As of this report, the money has not been recovered.

Suspected Lazarus Group Connections

According to blockchain analysts, the transfers followed a clear path: the stolen coins moved through five instant exchanges before being sent into Tornado Cash, the crypto mixer that US authorities sanctioned in 2022.

Source: ZachXBT

Based on reports, the same set of tactics — wallet fingerprints, timing, and routing — match other intrusions linked to the Lazarus Group, the state-linked cyber unit from the DPRK.

A US court’s decision earlier this year to lift some restrictions around mixers has raised fresh concerns that these tools can be reused to hide large thefts.

Infiltration Schemes And Fake Profiles

Investigations have shown the threat is not only technical but social. Reports have disclosed that operatives created dozens of fake identities, bought Social Security numbers, and posed as blockchain developers on platforms such as Upwork and LinkedIn.

Evidence posted on August 13 linked one such fake-developer wallet to a $680,000 exploit of the project Favrr in June 2025. The methods range from phishing and fake job offers to bribery and contractor infiltration, giving attackers ways to penetrate projects from the inside.

BTCUSD trading at $118,960 on the 24-hour chart: TradingView

A Growing Trail Of Stolen Crypto

Based on compiled forensics data, North Korean-linked groups stole more than $1.3 billion across 47 incidents in 2024. That figure jumped higher in 2025, with estimates putting thefts at about $2.2 billion in the first half of the year alone.

Malware campaigns have also been used. In June, Cisco Talos documented “PylangGhost,” a campaign that used bogus coding tests and interview sites to deliver malware.

That malware targeted over 80 browser extensions and popular wallets like MetaMask and Phantom.

Law enforcement has made some moves: US agents seized $7.7 million tied to covert networks, and the FBI dismantled front companies such as Blocknovas LLC and Softglide LLC.

The $21 million breach underscores how exposed even major firms remain to state-backed hacking campaigns. For now, the case stands as another warning: Japanese crypto firm SBI lost $21 million in suspected North Korean cyberattack.

Featured image from Gemini, chart from TradingView

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

Christian, a journalist and editor with leadership roles in Philippine and Canadian media, is fueled by his love for writing and cryptocurrency. Off-screen, he's a cook and cinephile who's constantly intrigued by the size of the universe.

Related Reads

Bitcoin's 'Rally Ends,' Officially Entering the Later Stage of a Bear Market?

Bitcoin prices declined 13% this week, reversing the recent rebound and signaling a likely transition into the later stages of a bear market. Key on-chain metrics deteriorated, with the short-term holder cost basis falling below the Realized Price—a pattern last seen in early 2022, characteristic of bear market maturity. The rally to ~$82k proved to be a bear market bounce, as evidenced by the 90-day realized profit/loss ratio failing to sustain above the bullish threshold of 2. Daily realized losses surged to $1.35B, including significant selling from long-term holders who accumulated near cycle tops, indicating ongoing supply redistribution. Price was rejected almost precisely at the aggregate US spot ETF cost basis of ~$83k, turning that level into resistance and leaving the average ETF investor underwater again. Spot market selling pressure intensified, with the 7-day volume delta turning significantly negative to its weakest level since February. While a major long liquidation event cleared over $400M in leverage, spot demand has not yet stepped in to absorb the resulting supply. Options markets continue pricing in higher future volatility (elevated volatility risk premium) and maintain a skew toward put options, reflecting persistent demand for downside protection, though not yet panic. Overall, market structure remains fragile. Sustained recovery likely requires a reclaim of the ETF cost basis, a shift back to positive spot demand, and a slowdown in realized loss-taking. Until then, the market risks further downside or extended consolidation within the broader bear trend.

Foresight News55m ago

Bitcoin's 'Rally Ends,' Officially Entering the Later Stage of a Bear Market?

Foresight News55m ago

How Risky is the "Death Spiral" of MSTR and STRC?

Summary: This article explores the perceived "death spiral" risk between MicroStrategy (MSTR), its Bitcoin holdings, and its perpetual preferred stock (STRC), drawing comparisons to the LUNA-UST collapse. While both systems feature price anchors, high yields for holders, and potential feedback loops, their core mechanisms differ fundamentally. The MSTR-STRC structure relies on continuous financing to sustain its high dividend payouts, primarily through stock ATM offerings. A negative feedback cycle could occur: falling MSTR stock price makes raising equity capital harder, increasing pressure to sell Bitcoin, which undermines STRC confidence and further depresses MSTR. However, unlike LUNA-UST's automated, direct linkage, the MSTR-STRC loop is weaker and has brakes: STRC dividends can be deferred or rates lowered, and STRC holders have a $100/share liquidation preference in bankruptcy, providing a price floor. The company's sustainability hinges on its ability to continue financing. Its current ~$900 million USD reserves cover only about 6.3 months of its ~$1.71 billion annual interest/dividend burden. The next six months are critical, aligning with both the potential bottom in Bitcoin's four-year cycle and the depletion timeline of its reserves. While a LUNA-style catastrophic collapse is deemed highly unlikely due to structural differences, the key question is whether MicroStrategy can navigate this period through healthy deleveraging to restart its capital engine.

Foresight News1h ago

How Risky is the "Death Spiral" of MSTR and STRC?

Foresight News1h ago

Trading

Spot
Futures
活动图片