{"investigation":{"slug":"stakecom","entity_name":"Stake.com","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"Stake.com is a Curaçao-licensed cryptocurrency gambling and sports betting platform co-founded in 2017 by Australians Ed Craven and Bijan Tehrani, operating as one of the largest crypto casinos globally with reported 2024 revenue of $4.7 billion. On September 4, 2023, the platform suffered a critical security breach in which approximately $41.35 million in cryptocurrency was drained from its hot wallets across Ethereum, BNB Smart Chain, and Polygon networks; the FBI formally attributed the attack to North Korea's Lazarus Group (APT38) within 48 hours. Stake.com restored full operations within five hours of the incident and stated that user funds were not affected, though the root cause — a likely hot wallet private key compromise — has never been officially confirmed by the company.","sections":[{"content":"Stake.com is an online cryptocurrency casino and sports betting platform founded in August 2017 and operated by Medium Rare N.V., incorporated in Curaçao. The platform's co-founders, Ed Craven and Bijan Tehrani, are Australian entrepreneurs who previously built Primedice (a crypto dice game, 2013) and Easygo (a casino games studio, 2016). Both founders have traced their collaboration to a shared history in the online game RuneScape, where they were allegedly banned for operating an in-game casino as teenagers. Stake.com holds a Curaçao Gaming Authority license (OGL/2024/1451/0918) and maintains offices in Serbia, Australia, and Cyprus. The platform operates in most global jurisdictions but is explicitly blocked in the United States, United Kingdom, and parts of Europe including Italy and Denmark. Despite these restrictions, multiple reports have alleged that U.S. residents can and do access Stake.com via VPNs. The platform is also the parent company of the live streaming platform Kick. Stake.com reported approximately $4.7 billion in revenue in 2024, making it one of the largest crypto gambling operations in existence. Curaçao's regulatory environment has historically been criticized for minimal enforcement and limited cross-border authority, though a new National Ordinance on Games of Chance (LOK) entered into force on December 24, 2024, introducing direct licensing and ongoing supervision by the Curaçao Gaming Authority.","heading":"Background","sources":[{"url":"https://en.wikipedia.org/wiki/Ed_Craven","name":"","type":"other","credibility":3},{"url":"https://en.wikipedia.org/wiki/Bijan_Tehrani_(entrepreneur)","name":"","type":"other","credibility":3},{"url":"https://fincrimecentral.com/stake-multi-billion-gambling-empire/","name":"","type":"other","credibility":3},{"url":"https://coincub.com/blog/curacao-gaming-license/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On September 4, 2023, Stake.com's hot wallets across Ethereum, BNB Smart Chain (BSC), and Polygon were drained in a rapid, multi-chain attack. The breach was detected internally within approximately 20 minutes of the first unauthorized transaction. Total losses were calculated by blockchain security firm Beosin at approximately $41.35 million: $15.7 million on Ethereum, $17.8 million on BSC, and $7.8 million on Polygon. Assets stolen on Ethereum included approximately 6,001 ETH, 3.9 million USDT, 1.1 million USDC, and 900,000 DAI. BSC losses included approximately 12,000 BNB, 7.35 million BSC-USD, 83.9 billion SHIB, and various other tokens. Polygon losses included MATIC, DAI, USDT, and USDC. The attack vector involved no interaction with smart contracts; funds were moved through direct transfers from hot wallets, strongly indicating a private key or signing credential compromise. Stake co-founder Ed Craven stated publicly that 'private keys were not compromised but the attacker was able to make several unauthorised transactions from our hot wallets,' a characterization disputed by multiple security researchers who identified private key leakage or unauthorized signing as the only technically coherent explanation. Stake.com restored full deposit and withdrawal operations approximately five hours after the breach and stated that user funds held in the platform were unaffected. The company absorbed the $41.35 million loss internally, asserting it did not materially affect platform operations.","heading":"The Lazarus Hack","sources":[{"url":"https://hacken.io/discover/stake-com-hack-sep-2023/","name":"","type":"other","credibility":3},{"url":"https://www.bleepingcomputer.com/news/security/crypto-casino-stakecom-loses-41-million-to-hot-wallet-hackers/","name":"","type":"other","credibility":3},{"url":"https://www.dlnews.com/articles/defi/stake-co-founder-says-hacker-did-not-compromise-private-keys/","name":"","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/crypto-casino-stake-resume-services-hours-after-hack","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-stake-com-hack-september-2023","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Blockchain forensics firms including Hacken, TRM Labs, and Merkle Science traced the stolen funds across multiple chains from the moment of compromise. Three primary attacker-controlled wallets were identified: 0x3130662aece32f05753d00a7b95c0444150bcd3c (Ethereum), 0x4464e91002c63a623a8a218bd5dd1f041b61ec04 (BSC), and 0xfe3f568d58919b14aff72bd3f14e6f55bec6c4e0 (Polygon). From these wallets, assets were distributed to multiple externally owned accounts (EOAs). Within approximately two days of the attack, funds began laundering operations: Polygon assets were bridged to Avalanche via Squid Router and converted to wrapped Bitcoin, which was then bridged to the Bitcoin network. TRM Labs identified the laundering pattern as consistent with known Lazarus Group techniques, including multi-chain asset hopping, use of cross-chain bridges (Avalanche Bridge), and rotation through mixers. TRM noted that the 2023 Lazarus Group laundering methodology had evolved from the 2022 approach (Tornado Cash → Ren Bridge → Bitcoin → ChipMixer) to a newer pattern (Avalanche Bridge → Sinbad mixer → Tron via SWFT Bridge → USDT liquidated through suspected OTC brokers). As of post-attack reporting, approximately 72 BTC had been laundered with remaining assets still held in attacker-controlled addresses. The FBI's flash alert published 40 specific addresses across Ethereum and Bitcoin networks associated with the theft.","heading":"On-Chain Evidence","sources":[{"url":"https://hacken.io/discover/stake-com-hack-sep-2023/","name":"","type":"other","credibility":3},{"url":"https://www.trmlabs.com/resources/blog/fbi-confirms-that-north-korea-was-behind-41-million-stake-com-exploit","name":"","type":"other","credibility":3},{"url":"https://medium.com/@0xscope_labs/0xscope-research-tracking-the-stake-com-hack-f73ffe52270b","name":"","type":"other","credibility":3},{"url":"https://blog.merklescience.com/hacktrack/stake-suffers-38-million-hack","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On September 6, 2023, the Federal Bureau of Investigation issued a formal press release identifying the Lazarus Group (also designated APT38), a cyber unit operating under the direction of the Democratic People's Republic of Korea (DPRK), as responsible for the $41 million theft from Stake.com. This attribution was issued within approximately 48 hours of the initial breach, reflecting the speed at which U.S. law enforcement had been tracking Lazarus Group activity across the crypto sector throughout 2023. The FBI noted that DPRK cyber actors had stolen more than $200 million in cryptocurrency in 2023 alone, with prior attacks including approximately $100 million from Atomic Wallet (June 2, 2023) and approximately $60 million from Alphapo and CoinsPaid (July 22, 2023). The FBI's alert included a list of 40 blockchain addresses across Ethereum and Bitcoin used by Lazarus Group actors in connection with the Stake.com theft. The FBI advised cryptocurrency businesses and financial institutions to monitor these addresses and exercise caution regarding any transactions linked to them. The Stake.com attribution is part of a documented pattern of North Korean state-sponsored hacking operations targeting cryptocurrency platforms to fund state activities, a campaign that the U.S. government, UN panels, and private blockchain analytics firms have tracked since at least 2018.","heading":"FBI Attribution","sources":[{"url":"https://www.fbi.gov/news/press-releases/fbi-identifies-lazarus-group-cyber-actors-as-responsible-for-theft-of-41-million-from-stakecom","name":"","type":"other","credibility":3},{"url":"https://www.coindesk.com/policy/2023/09/07/north-koreas-lazarus-hackers-stoke-41-million-from-crypto-gambling-site-fbi-says","name":"","type":"other","credibility":3},{"url":"https://decrypt.co/155360/fbi-says-north-koreas-lazarus-group-was-behind-41-million-stake-hack","name":"","type":"other","credibility":3},{"url":"https://www.securityweek.com/fbi-blames-north-korean-hackers-for-41-million-stake-com-heist/","name":"","type":"other","credibility":3},{"url":"https://www.trmlabs.com/resources/blog/fbi-confirms-that-north-korea-was-behind-41-million-stake-com-exploit","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Stake.com restored deposit and withdrawal functionality within approximately five hours of the September 4, 2023 breach. Bitcoin, Litecoin, XRP, and EVM wallets unaffected by the hack remained operational throughout the incident. Ed Craven stated publicly via the platform's official channels and in a post-incident Medium essay that the platform had absorbed the loss, that player funds remained safe, and that Stake was 'back and running exactly as it was' before the attack. Craven noted that Stake's practice of holding only a small fraction of total reserves in hot wallets at any given time was a deliberate risk-mitigation measure that limited the scale of the loss. The company did not disclose the exact mechanism of compromise, and the precise technical root cause — whether a private key theft, insider threat, supply chain compromise, or unauthorized signing credential leak — was never officially confirmed. No law enforcement action or formal criminal charges against specific individuals have been publicly announced in connection with the Stake.com breach as of the time of this investigation. The stolen funds, attributed to Lazarus Group, are believed to have been substantially laundered through cross-chain bridging and mixing services, with final liquidation suspected through OTC brokers identified by TRM Labs.","heading":"Recovery","sources":[{"url":"https://cointelegraph.com/news/crypto-casino-stake-resume-services-hours-after-hack","name":"","type":"other","credibility":3},{"url":"https://casinobeats.com/2023/09/05/stake-resumes-operations-41m-hack/","name":"","type":"other","credibility":3},{"url":"https://medium.com/@edcraven22/always-moving-forward-reflections-on-the-recent-stake-com-exploit-431105710a2e","name":"","type":"other","credibility":3},{"url":"https://www.dlnews.com/articles/defi/stake-co-founder-says-hacker-did-not-compromise-private-keys/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Stake.com presents several material risk factors for users of cryptocurrency gambling platforms. First, the platform suffered the largest publicly attributed crypto gambling hack in history as of 2023, with $41.35 million stolen in a single attack traced to a state-sponsored adversary (DPRK Lazarus Group). The root cause of the breach — most likely a private key or signing credential compromise — was never officially disclosed, raising questions about transparency and the completeness of any post-incident remediation. Second, Stake.com operates under a Curaçao Gaming Authority license, a jurisdiction historically associated with minimal enforcement capacity and limited consumer protection. While regulatory reforms (LOK, effective December 2024) have introduced more structured oversight, the practical impact on platforms like Stake.com is not yet established. Third, the platform is blocked in the United States, United Kingdom, Italy, Denmark, and other major jurisdictions; multiple reports allege that Stake.com is accessible to users in blocked jurisdictions via VPN, raising potential compliance and legal exposure for users. Fourth, the concentration of hot wallet exposure across multiple major blockchain networks (Ethereum, BSC, Polygon) in a single incident demonstrates systemic custody risk inherent to high-volume crypto gambling platforms. Fifth, the speed and sophistication of the Lazarus Group attack — completed in minutes across multiple chains with laundering initiated within 48 hours — underscores that crypto gambling platforms remain high-priority targets for state-level threat actors. Users should be aware that crypto gambling platforms operate outside most regulatory frameworks designed to protect consumer funds, and losses from hacks or insolvency may carry no legal recourse.","heading":"Risk Assessment","sources":[{"url":"https://www.fbi.gov/news/press-releases/fbi-identifies-lazarus-group-cyber-actors-as-responsible-for-theft-of-41-million-from-stakecom","name":"","type":"other","credibility":3},{"url":"https://fincrimecentral.com/stake-multi-billion-gambling-empire/","name":"","type":"other","credibility":3},{"url":"https://www.elliptic.co/blog/how-the-lazarus-group-is-stepping-up-crypto-hacks-and-changing-its-tactics","name":"","type":"other","credibility":3},{"url":"https://coincub.com/blog/curacao-gaming-license/","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2013","event":"Ed Craven and Bijan Tehrani launch Primedice, a cryptocurrency dice game, establishing their first crypto gambling venture.","source":"","date_original":"2013-01-01"},{"date":"2016","event":"Craven and Tehrani found Easygo, an online casino games studio, as the corporate precursor to Stake.com.","source":"","date_original":"2016-01-01"},{"date":"2017-08","event":"Stake.com launched as a crypto casino and sports betting platform under Curaçao license, operated by Medium Rare N.V.","source":"","date_original":"2017-08-01"},{"date":"2023-09-04","event":"Stake.com hot wallets on Ethereum, BNB Smart Chain, and Polygon drained of approximately $41.35 million in a multi-chain attack detected internally within 20 minutes.","source":""},{"date":"2023-09-04","event":"Stake.com restores full deposit and withdrawal operations approximately five hours after the breach; Ed Craven states user funds are safe.","source":""},{"date":"2023-09-06","event":"FBI issues formal press release attributing the $41 million theft to North Korea's Lazarus Group (APT38), publishing 40 associated blockchain addresses.","source":""},{"date":"2023-09-07","event":"TRM Labs publishes on-chain analysis corroborating FBI attribution, documenting multi-chain laundering patterns consistent with Lazarus Group TTPs.","source":""},{"date":"2023-09-10","event":"Ed Craven publishes post-incident reflections on Medium; states private keys were not directly compromised and that Stake absorbed the loss without material operational impact.","source":""},{"date":"2024-12-24","event":"Curaçao's new National Ordinance on Games of Chance (LOK) enters into force, replacing the sublicense model and introducing direct CGA supervision of operators including Stake.com.","source":""}],"sources_used":[{"url":"https://en.wikipedia.org/wiki/Ed_Craven","name":"","type":"other","archive_url":"http://web.archive.org/web/20260819095550/https://en.wikipedia.org/wiki/Ed_Craven","credibility":3,"archive_timestamp":"2026-08-19T09:55:50+00:00"},{"url":"https://en.wikipedia.org/wiki/Bijan_Tehrani_(entrepreneur)","name":"","type":"other","archive_url":"http://web.archive.org/web/20260822005350/https://en.wikipedia.org/wiki/Bijan_Tehrani_(entrepreneur)","credibility":3,"archive_timestamp":"2026-08-22T00:53:50+00:00"},{"url":"https://fincrimecentral.com/stake-multi-billion-gambling-empire/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260510235038/https://fincrimecentral.com/stake-multi-billion-gambling-empire/","credibility":3,"archive_timestamp":"2026-05-10T23:50:38+00:00"},{"url":"https://coincub.com/blog/curacao-gaming-license/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260517183213/https://coincub.com/blog/curacao-gaming-license/","credibility":3,"archive_timestamp":"2026-05-17T18:32:13+00:00"},{"url":"https://hacken.io/discover/stake-com-hack-sep-2023/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260420195144/https://hacken.io/discover/stake-com-hack-sep-2023/","credibility":3,"archive_timestamp":"2026-04-20T19:51:44+00:00"},{"url":"https://www.bleepingcomputer.com/news/security/crypto-casino-stakecom-loses-41-million-to-hot-wallet-hackers/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260801135146/https://www.bleepingcomputer.com/news/security/crypto-casino-stakecom-loses-41-million-to-hot-wallet-hackers/","credibility":3,"archive_timestamp":"2026-08-01T13:51:46+00:00"},{"url":"https://www.dlnews.com/articles/defi/stake-co-founder-says-hacker-did-not-compromise-private-keys/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260624204142/https://www.dlnews.com/articles/defi/stake-co-founder-says-hacker-did-not-compromise-private-keys/","credibility":3,"archive_timestamp":"2026-06-24T20:41:42+00:00"},{"url":"https://cointelegraph.com/news/crypto-casino-stake-resume-services-hours-after-hack","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829130145/https://cointelegraph.com/news/crypto-casino-stake-resume-services-hours-after-hack","credibility":3,"archive_timestamp":"2026-08-29T13:01:45+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-stake-com-hack-september-2023","name":"","type":"other","archive_url":"http://web.archive.org/web/20260516231737/https://www.halborn.com/blog/post/explained-the-stake-com-hack-september-2023","credibility":3,"archive_timestamp":"2026-05-16T23:17:37+00:00"},{"url":"https://www.trmlabs.com/resources/blog/fbi-confirms-that-north-korea-was-behind-41-million-stake-com-exploit","name":"","type":"other","archive_url":"http://web.archive.org/web/20260509162550/https://www.trmlabs.com/resources/blog/fbi-confirms-that-north-korea-was-behind-41-million-stake-com-exploit","credibility":3,"archive_timestamp":"2026-05-09T16:25:50+00:00"},{"url":"https://medium.com/@0xscope_labs/0xscope-research-tracking-the-stake-com-hack-f73ffe52270b","name":"","type":"other","archive_url":"http://web.archive.org/web/20251201060537/https://medium.com/@0xscope_labs/0xscope-research-tracking-the-stake-com-hack-f73ffe52270b","credibility":3,"archive_timestamp":"2025-12-01T06:05:37+00:00"},{"url":"https://blog.merklescience.com/hacktrack/stake-suffers-38-million-hack","name":"","type":"other","archive_url":"https://web.archive.org/web/20260901070401/https://www.merklescience.com/blog/stake-suffers-38-million-hack","credibility":3,"archive_timestamp":"2026-09-01T07:04:01+00:00"},{"url":"https://www.fbi.gov/news/press-releases/fbi-identifies-lazarus-group-cyber-actors-as-responsible-for-theft-of-41-million-from-stakecom","name":"","type":"other","archive_url":"http://web.archive.org/web/20260823023924/https://www.fbi.gov/news/press-releases/fbi-identifies-lazarus-group-cyber-actors-as-responsible-for-theft-of-41-million-from-stakecom","credibility":3,"archive_timestamp":"2026-08-23T02:39:24+00:00"},{"url":"https://www.coindesk.com/policy/2023/09/07/north-koreas-lazarus-hackers-stoke-41-million-from-crypto-gambling-site-fbi-says","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://decrypt.co/155360/fbi-says-north-koreas-lazarus-group-was-behind-41-million-stake-hack","name":"","type":"other","archive_url":"http://web.archive.org/web/20260512102735/https://decrypt.co/155360/fbi-says-north-koreas-lazarus-group-was-behind-41-million-stake-hack","credibility":3,"archive_timestamp":"2026-05-12T10:27:35+00:00"},{"url":"https://www.securityweek.com/fbi-blames-north-korean-hackers-for-41-million-stake-com-heist/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260830082343/https://www.securityweek.com/fbi-blames-north-korean-hackers-for-41-million-stake-com-heist/","credibility":3,"archive_timestamp":"2026-08-30T08:23:43+00:00"},{"url":"https://casinobeats.com/2023/09/05/stake-resumes-operations-41m-hack/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260428034558/https://casinobeats.com/2023/09/05/stake-resumes-operations-41m-hack/","credibility":3,"archive_timestamp":"2026-04-28T03:45:58+00:00"},{"url":"https://medium.com/@edcraven22/always-moving-forward-reflections-on-the-recent-stake-com-exploit-431105710a2e","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.elliptic.co/blog/how-the-lazarus-group-is-stepping-up-crypto-hacks-and-changing-its-tactics","name":"","type":"other","archive_url":"http://web.archive.org/web/20260511085148/https://www.elliptic.co/blog/how-the-lazarus-group-is-stepping-up-crypto-hacks-and-changing-its-tactics","credibility":3,"archive_timestamp":"2026-05-11T08:51:48+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:38.35+00:00","updated_at":"2026-09-01T07:15:38.138055+00:00"}}