Japanese Crypto Firm SBI Loses $21 Million In Suspected North Korean Cyberattack

bitcoinist发布于2025-10-03更新于2025-10-03

文章摘要

Reports have disclosed that Japanese firm SBI Crypto saw about $21 million siphoned from company-linked wallets on September 24, 2025....

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

Reports have disclosed that Japanese firm SBI Crypto saw about $21 million siphoned from company-linked wallets on September 24, 2025.

Blockchain sleuths flagged the movement, and on-chain traces show funds leaving addresses that start with “0x40d7” and “bc1qx0a2k.”

The assets included Bitcoin, Ethereum, Litecoin, Dogecoin, and Bitcoin Cash. As of this report, the money has not been recovered.

Suspected Lazarus Group Connections

According to blockchain analysts, the transfers followed a clear path: the stolen coins moved through five instant exchanges before being sent into Tornado Cash, the crypto mixer that US authorities sanctioned in 2022.

Source: ZachXBT

Based on reports, the same set of tactics — wallet fingerprints, timing, and routing — match other intrusions linked to the Lazarus Group, the state-linked cyber unit from the DPRK.

A US court’s decision earlier this year to lift some restrictions around mixers has raised fresh concerns that these tools can be reused to hide large thefts.

Infiltration Schemes And Fake Profiles

Investigations have shown the threat is not only technical but social. Reports have disclosed that operatives created dozens of fake identities, bought Social Security numbers, and posed as blockchain developers on platforms such as Upwork and LinkedIn.

Evidence posted on August 13 linked one such fake-developer wallet to a $680,000 exploit of the project Favrr in June 2025. The methods range from phishing and fake job offers to bribery and contractor infiltration, giving attackers ways to penetrate projects from the inside.

BTCUSD trading at $118,960 on the 24-hour chart: TradingView

A Growing Trail Of Stolen Crypto

Based on compiled forensics data, North Korean-linked groups stole more than $1.3 billion across 47 incidents in 2024. That figure jumped higher in 2025, with estimates putting thefts at about $2.2 billion in the first half of the year alone.

Malware campaigns have also been used. In June, Cisco Talos documented “PylangGhost,” a campaign that used bogus coding tests and interview sites to deliver malware.

That malware targeted over 80 browser extensions and popular wallets like MetaMask and Phantom.

Law enforcement has made some moves: US agents seized $7.7 million tied to covert networks, and the FBI dismantled front companies such as Blocknovas LLC and Softglide LLC.

The $21 million breach underscores how exposed even major firms remain to state-backed hacking campaigns. For now, the case stands as another warning: Japanese crypto firm SBI lost $21 million in suspected North Korean cyberattack.

Featured image from Gemini, chart from TradingView

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

Christian, a journalist and editor with leadership roles in Philippine and Canadian media, is fueled by his love for writing and cryptocurrency. Off-screen, he's a cook and cinephile who's constantly intrigued by the size of the universe.

你可能也喜欢

55TB 变 28TB?Rubin 内存要砍半背后的谣言与恐慌

6月4日,半导体研究机构SemiAnalysis发布报告,指出英伟达下一代AI超算平台Vera Rubin NVL72的内存配置可能低于预期:每机架CPU侧采用的SOCAMM DRAM容量或从预期的约55TB降至约28TB,主要因多数系统将安装96GB模块而非192GB。此消息引发市场对内存需求“腰斩”的恐慌,导致美光(MU)股价单日一度暴跌超10%,市值蒸发超千亿美元。 然而,文章分析认为市场解读存在误区。首先,Rubin平台采用的SOCAMM2模块为可插拔设计,允许后续灵活升级,初始配置降低不等于永久需求收缩。其次,降配主因是2026年LPDDR5X供应链极度紧张,英伟达为保障机架交付和算力尽快上线而采取的务实策略,实际反映的是需求压倒供给。再者,在同等内存供给下,降低单机架配置反而可能使英伟达组装并出货更多机架,对内存厂商的总订单量影响有限。 美光当日大跌,也被认为更多是受半导体板块整体情绪拖累——博通(Broadcom)因未上调全年AI芯片收入指引而股价重挫,叠加SemiAnalysis报告提供的叙事催化,共同触发了高位获利回吐。 文章最后指出,美光当前的核心风险在于其在Rubin平台HBM4订单中的份额偏低,而非SOCAMM配置变化。此次市场恐慌更多是基于对标题的片面解读,忽视了模块化架构的升级弹性与行业供不应求的背景。

marsbit23分钟前

55TB 变 28TB?Rubin 内存要砍半背后的谣言与恐慌

marsbit23分钟前

“老登股”变“新贵”:从戴尔到诺基亚,AI如何重估旧基础设施?

过去被视为增长缓慢的“老牌科技股”,如戴尔、诺基亚、思科、康宁、西部数据等,近期因AI热潮而表现亮眼。这并非简单的市场炒作,而是AI发展进入实际部署阶段的必然结果。 此前,AI投资焦点集中在英伟达等算力核心和模型上。但随着AI从理论走向实践,大规模建设数据中心和部署应用需要完整的系统工程能力。这恰恰是老牌科技公司的优势所在。它们凭借几十年积累的客户、供应链、系统集成和交付经验,在AI基础设施建设中找到了新角色。 具体而言,市场主要从三条线重估这些公司:一是服务器与系统集成(如戴尔、HPE),它们扮演着将GPU等核心部件整合成完整AI服务器并交付的“总包商”角色;二是网络与连接(如康宁、诺基亚、思科),AI算力集群的高效运行极度依赖高速互联和光纤网络;三是存储(如西部数据、希捷),AI产生的海量数据(包括训练数据、日志、冷数据)催生了对高性价比大容量硬盘的持续需求。 真正的重估需要满足几个条件:明确的AI相关订单和收入增长、公司因此上调业绩指引、以及利润质量的同步改善。AI并不会让所有传统公司重生,它只筛选出那些真正卡位关键基础设施环节、并能将新需求转化为可持续利润的企业。这轮行情标志着AI进入真实建设期,市场开始为“谁能把AI基建建起来”的能力定价。

marsbit43分钟前

“老登股”变“新贵”:从戴尔到诺基亚,AI如何重估旧基础设施?

marsbit43分钟前

交易

现货
合约
活动图片