{"investigation":{"slug":"solareum","entity_name":"Solareum","trust_score":12,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Solareum was a Solana-based Telegram trading bot that shut down on March 30, 2024 following a security exploit that drained approximately $523,000 (2,800+ SOL) from over 300 user wallets. Prosecutors later revealed in a January 2025 court filing that the Solareum team had unknowingly hired a North Korean (DPRK) developer in December 2023, who subsequently facilitated the theft of 6,045 SOL worth roughly $1.4 million; the FBI seized approximately $950,000 in USDT two months after the hack. The project offered no compensation to victims, deleted its website and community channels, and is no longer operational.","sections":[{"content":"Solareum was a Telegram-based automated trading bot operating on the Solana blockchain. It allowed users to import their Solana wallet private keys and execute trades in Solana-based tokens. The platform also issued a native token (XSB) on Solana. Separately, there is an unrelated Solareum Wallet (XSB) project launched in 2021 that operated as a Solana/Ethereum bridge wallet. The Telegram trading bot — the entity at issue — became defunct in late March 2024 following a major security incident and abrupt shutdown.","heading":"Overview","sources":[{"url":"https://decrypt.co/224371/solana-telegram-trading-bot-shut-down-users-drained-523k","name":"decrypt.co","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/telegram-trading-bot-solareum-shutters-after-520k-exploit","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://coinmarketcap.com/academy/article/solareum-telegram-trading-app-shuts-down-following-dollar523k-exploit-bonkbot-users-affected","name":"coinmarketcap.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On March 29, 2024, users began reporting via social media and Solareum's Telegram support channel that their crypto wallets had been drained. Over 300 Solana users lost approximately 2,800 SOL, valued at roughly $523,000 at the time of the incident. BONKbot, a separate Telegram trading bot, initially came under suspicion because some of its users were also affected. However, BONKbot's security analysis determined that the common variable among compromised wallets was the importation of private keys into Solareum: 'the point of absolute correlation so far has been victims importing their private keys into Solareum,' the BONKbot team stated publicly. Solareum acknowledged on March 29 that a possible security breach had occurred. On March 30, crypto security researcher Taylor Monahan was brought in to investigate. Monahan noted that 'onchain flows and indicators had major overlaps with prior thefts involving DPRK IT workers.' Security researchers subsequently convinced Tether to freeze the stolen funds that day, March 30, 2024.","heading":"March 2024 Security Exploit","sources":[{"url":"https://decrypt.co/224371/solana-telegram-trading-bot-shut-down-users-drained-523k","name":"decrypt.co","type":"other","credibility":3},{"url":"https://coinmarketcap.com/academy/article/solareum-telegram-trading-app-shuts-down-following-dollar523k-exploit-bonkbot-users-affected","name":"coinmarketcap.com","type":"other","credibility":3},{"url":"https://www.dlnews.com/articles/regulation/how-a-dprk-developer-tricked-solareum-and-stole-14m/","name":"dlnews.com","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/?id=solana-drain-attacks","name":"web3isgoinggreat.com","type":"other","credibility":3}],"severity":"medium"},{"content":"According to a January 21, 2025 court filing cited by prosecutors, the Solareum team had unknowingly hired a North Korean (DPRK) developer in December 2023 — less than four months before the March 2024 hack. In December 2023, the Solareum team announced in its support channel that it was 'onboarding a new dev.' Prosecutors allege this developer was a North Korean national concealing their identity in line with a broader DPRK state-sponsored scheme. The developer is alleged to have stolen 6,045 SOL from Solareum users, worth approximately $1.4 million at the time of theft. The stolen proceeds were laundered through multiple centralized exchanges including HTX, Binance, MEXC, EasyBit, and FixedFloat, and converted to USDT. Approximately two months after the hack, the FBI seized approximately $950,000 in USDT related to this case. The Treasury Department has publicly warned that North Korean developers routinely conceal their identities to obtain employment at crypto and technology firms. The UN Security Council has estimated that more than 4,000 North Koreans have been directed to infiltrate tech companies as part of a scheme earning DPRK approximately $600 million annually. Taylor Monahan, who was brought in to assist in the Solareum investigation, stated that identifying the developer was hampered by the Solareum team's subsequent non-cooperation: 'Usually we ID the workers by their resume or payroll address that they give the team, but it requires the team's cooperation.'","heading":"North Korean Developer Infiltration","sources":[{"url":"https://www.dlnews.com/articles/regulation/how-a-dprk-developer-tricked-solareum-and-stole-14m/","name":"dlnews.com","type":"other","credibility":3},{"url":"https://www.justice.gov/usao-ndga/pr/four-north-koreans-charged-nearly-1-million-cryptocurrency-theft-scheme","name":"justice.gov","type":"other","credibility":3},{"url":"https://cyberscoop.com/doj-north-korea-it-worker-scheme-cases-crypto-seized/","name":"cyberscoop.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On March 30, 2024, Solareum announced it was shutting down via Telegram. The team cited 'insufficient funds, evolving market trends, and a recent security breach to our systems' as reasons for the closure, stating they could 'no longer assure the safety of our users.' The shutdown announcement included no compensation plan for affected users. The team stated they would contact authorities to attempt to freeze any stolen assets that had been sent to centralized exchanges, but did not commit to reimbursing victims. Following the shutdown announcement, the Solareum website was deleted and community channels were closed, which complicated investigators' ability to identify the rogue developer and hampered victims' ability to organize. Solareum's Telegram channel was flooded with users demanding answers and threatening legal action. As of the time of reporting, no compensation had been provided to the approximately 300 affected users. It is unconfirmed whether the FBI's subsequent seizure of approximately $950,000 in USDT has been or will be disbursed to victims; a DOJ spokesperson did not respond to requests for comment on that question.","heading":"Project Shutdown and Lack of Victim Compensation","sources":[{"url":"https://decrypt.co/224371/solana-telegram-trading-bot-shut-down-users-drained-523k","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2024/04/02/solareum-shuts-down-following-520000-exploit-on-telegram/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://amlcrypto.io/blog/telegram_trading_bot_on_solana_network_stopped_working","name":"amlcrypto.io","type":"other","credibility":3},{"url":"https://www.dlnews.com/articles/regulation/how-a-dprk-developer-tricked-solareum-and-stole-14m/","name":"dlnews.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the shutdown, members of the community alleged that the Solareum team had executed a deliberate exit scam ('rug pull'). The team issued a public denial via X (formerly Twitter): 'We at #SOLAREUM team can clarify that we DO NOT steal money.' Critics noted that the team's rapid deletion of its website and community channels after the exploit was inconsistent with a team acting in good faith. Taylor Monahan's statement that the Solareum team became uncooperative after the hack further fueled community suspicion. The absence of any compensation plan, combined with the abrupt closure, left the question of the team's culpability disputed in the community. While prosecutors focused on the DPRK developer as the perpetrator of the theft, the team's conduct after the fact — including the destruction of community infrastructure — drew criticism. These allegations remain unverified and no court action has been reported against the Solareum team itself.","heading":"Rug Pull Allegations and Team Conduct","sources":[{"url":"https://www.web3isgoinggreat.com/?id=solana-drain-attacks","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://amlcrypto.io/blog/telegram_trading_bot_on_solana_network_stopped_working","name":"amlcrypto.io","type":"other","credibility":3},{"url":"https://www.dlnews.com/articles/regulation/how-a-dprk-developer-tricked-solareum-and-stole-14m/","name":"dlnews.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On March 30, 2024, security researchers including Taylor Monahan convinced Tether to freeze the stolen USDT derived from the laundered Solareum exploit proceeds. Approximately two months after the March 2024 hack, the FBI seized approximately $950,000 in USDT connected to the theft. On January 21, 2025, a court filing by prosecutors in the Northern District of Georgia detailed the DPRK developer's role in the Solareum theft as part of a broader charging action against four North Korean nationals for cryptocurrency theft schemes. This case was one of several DOJ actions announced in early 2025 targeting North Korean IT worker infiltration schemes. It remains unclear whether seized funds will be returned to victims.","heading":"Law Enforcement and Regulatory Response","sources":[{"url":"https://www.justice.gov/usao-ndga/pr/four-north-koreans-charged-nearly-1-million-cryptocurrency-theft-scheme","name":"justice.gov","type":"other","credibility":3},{"url":"https://www.dlnews.com/articles/regulation/how-a-dprk-developer-tricked-solareum-and-stole-14m/","name":"dlnews.com","type":"other","credibility":3},{"url":"https://cyberscoop.com/doj-north-korea-it-worker-scheme-cases-crypto-seized/","name":"cyberscoop.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The Solareum incident is part of a documented pattern of North Korean state-sponsored IT workers infiltrating cryptocurrency and technology companies. The U.S. Treasury Department has issued public warnings that DPRK developers hide their identities to obtain employment at crypto firms, and the United Nations Security Council has reported that over 4,000 North Koreans have been directed to embed themselves in tech companies globally. ZachXBT, the pseudonymous blockchain investigator, has flagged multiple Solana DeFi projects as having hired DPRK IT workers, including ElementalDeFi in April 2026. The FBI maintains an active page listing DPRK IT fraud threats. Security researcher Taylor Monahan has noted that detecting DPRK IT workers prior to theft is difficult, as they often pass technical interviews and perform legitimate work before executing the theft.","heading":"Broader Context: DPRK IT Worker Threat in Crypto","sources":[{"url":"https://www.fbi.gov/wanted/cyber/dprk-it-workers","name":"fbi.gov","type":"other","credibility":3},{"url":"https://www.banklesstimes.com/articles/2026/04/07/zachxbt-solana-defi-app-elementaldefi-hired-dprk-it-worker-for-years/","name":"banklesstimes.com","type":"other","credibility":3},{"url":"https://www.dlnews.com/articles/regulation/how-a-dprk-developer-tricked-solareum-and-stole-14m/","name":"dlnews.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023-12","event":"Solareum team publicly announces in its Telegram support channel that it is 'onboarding a new dev' — later identified by prosecutors as a North Korean (DPRK) national operating under a false identity.","source":""},{"date":"2024-03-29","event":"Exploit begins: over 300 Solana users report their wallets have been drained. Approximately 2,800 SOL (~$523,000) is stolen. Solareum acknowledges a possible security breach. BONKbot analysis identifies private key importation into Solareum as the common factor among victims.","source":""},{"date":"2024-03-30","event":"Security researcher Taylor Monahan is brought in to investigate; identifies DPRK IT worker fingerprints in the onchain activity. Tether freezes stolen funds after researchers provide evidence. Solareum announces project shutdown via Telegram, citing 'insufficient funds, evolving market trends, and a recent security breach.' Website is deleted and community channels are closed. No compensation plan is announced for affected users.","source":""},{"date":"2024-05","event":"Approximately two months after the March hack, the FBI seizes approximately $950,000 in USDT connected to the laundered Solareum exploit proceeds.","source":""},{"date":"2025-01-21","event":"Prosecutors file a court filing in the Northern District of Georgia detailing how a DPRK developer infiltrated Solareum and stole 6,045 SOL (~$1.4 million) as part of a broader action charging four North Koreans with cryptocurrency theft schemes.","source":""}],"sources_used":[{"url":"https://decrypt.co/224371/solana-telegram-trading-bot-shut-down-users-drained-523k","name":"decrypt.co","type":"other","archive_url":"https://web.archive.org/web/20260830000027/https://decrypt.co/224371/solana-telegram-trading-bot-shut-down-users-drained-523k","credibility":3,"archive_timestamp":"2026-08-30T00:00:27+00:00"},{"url":"https://cointelegraph.com/news/telegram-trading-bot-solareum-shutters-after-520k-exploit","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260316060318/https://cointelegraph.com/news/telegram-trading-bot-solareum-shutters-after-520k-exploit","credibility":3,"archive_timestamp":"2026-03-16T06:03:18+00:00"},{"url":"https://coinmarketcap.com/academy/article/solareum-telegram-trading-app-shuts-down-following-dollar523k-exploit-bonkbot-users-affected","name":"coinmarketcap.com","type":"other","archive_url":"https://web.archive.org/web/20260829125537/https://coinmarketcap.com/academy/article/solareum-telegram-trading-app-shuts-down-following-dollar523k-exploit-bonkbot-users-affected","credibility":3,"archive_timestamp":"2026-08-29T12:55:37+00:00"},{"url":"https://www.dlnews.com/articles/regulation/how-a-dprk-developer-tricked-solareum-and-stole-14m/","name":"dlnews.com","type":"other","archive_url":"http://web.archive.org/web/20260701190906/https://www.dlnews.com/articles/regulation/how-a-dprk-developer-tricked-solareum-and-stole-14m/","credibility":3,"archive_timestamp":"2026-07-01T19:09:06+00:00"},{"url":"https://www.web3isgoinggreat.com/?id=solana-drain-attacks","name":"web3isgoinggreat.com","type":"other","archive_url":"http://web.archive.org/web/20260310104612/https://www.web3isgoinggreat.com/?id=solana-drain-attacks","credibility":3,"archive_timestamp":"2026-03-10T10:46:12+00:00"},{"url":"https://www.justice.gov/usao-ndga/pr/four-north-koreans-charged-nearly-1-million-cryptocurrency-theft-scheme","name":"justice.gov","type":"other","archive_url":"http://web.archive.org/web/20260816065931/https://www.justice.gov/usao-ndga/pr/four-north-koreans-charged-nearly-1-million-cryptocurrency-theft-scheme","credibility":3,"archive_timestamp":"2026-08-16T06:59:31+00:00"},{"url":"https://cyberscoop.com/doj-north-korea-it-worker-scheme-cases-crypto-seized/","name":"cyberscoop.com","type":"other","archive_url":"http://web.archive.org/web/20260712054056/https://cyberscoop.com/doj-north-korea-it-worker-scheme-cases-crypto-seized/","credibility":3,"archive_timestamp":"2026-07-12T05:40:56+00:00"},{"url":"https://www.cryptotimes.io/2024/04/02/solareum-shuts-down-following-520000-exploit-on-telegram/","name":"cryptotimes.io","type":"other","archive_url":"https://web.archive.org/web/20260829151155/https://www.cryptotimes.io/2024/04/02/solareum-shuts-down-following-520000-exploit-on-telegram/","credibility":3,"archive_timestamp":"2026-08-29T15:11:55+00:00"},{"url":"https://amlcrypto.io/blog/telegram_trading_bot_on_solana_network_stopped_working","name":"amlcrypto.io","type":"other","archive_url":"http://web.archive.org/web/20260312193528/https://amlcrypto.io/blog/telegram_trading_bot_on_solana_network_stopped_working","credibility":3,"archive_timestamp":"2026-03-12T19:35:28+00:00"},{"url":"https://www.fbi.gov/wanted/cyber/dprk-it-workers","name":"fbi.gov","type":"other","archive_url":"http://web.archive.org/web/20260704171724/https://www.fbi.gov/wanted/cyber/dprk-it-workers","credibility":3,"archive_timestamp":"2026-07-04T17:17:24+00:00"},{"url":"https://www.banklesstimes.com/articles/2026/04/07/zachxbt-solana-defi-app-elementaldefi-hired-dprk-it-worker-for-years/","name":"banklesstimes.com","type":"other","archive_url":"http://web.archive.org/web/20260528034346/https://www.banklesstimes.com/articles/2026/04/07/zachxbt-solana-defi-app-elementaldefi-hired-dprk-it-worker-for-years/","credibility":3,"archive_timestamp":"2026-05-28T03:43:46+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:33.626224+00:00","updated_at":"2026-08-30T01:16:27.746132+00:00"}}