Skip to main content
AVOID.NET

Audit log

Every state-changing event for Lazarus Group / TraderTraitor — DPRK September 2026 Blitz Campaign: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-09-25 17:08:34Z
    Score: ? → ? (no score change)
    anchoranchored
    chain
    ●mainnet-betaslot 450,415,437
    sig
    3d1hetTdgNK9…kE3FqKzuexplorer ↗
    hash
    GdVPAPxf3XyZ…cWV4XTjxsha256 → base58
    verifying row…full verify ↗
    canonical bytes (37167 B) ▸
    {"actor":"system:backfill","investigation_id":"e017af8a-4584-4968-886a-17da7a811d8c","kind":"publish","page_slug":"lazarus-group-tradertraitor-dprk-september-2026-blitz-campaign","published_at":"2026-09-25T17:08:34.508Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Lazarus Group / TraderTraitor — DPRK September 2026 Blitz Campaign","sections":[{"content":"The September 2026 DPRK blitz campaign encompasses two major incidents that investigators have attributed or tentatively linked to North Korea's Lazarus Group and its TraderTraitor sub-actor. The primary incident is the September 24 Bitget exchange hack ($351.6M), which Bitget CEO Gracy Chen described as 'very likely' carried out by a DPRK-linked group based on IP address patterns and behavioral indicators. On-chain analyst Specter provided additional forensic linkage between the Bitget XRP flows and the July 22 AFX Exchange hack ($24.15M), which AFX's post-mortem formally attributed to TraderTraitor (also tracked as UNC4899 by Mandiant). Together these two incidents are alleged to represent a single connected campaign by the same threat actor sub-unit. A third September incident, the Liquid Network $320M exploit on September 7, is included in context but carries no DPRK attribution; its perpetrators self-identified as white-hat researchers and the incident is assessed as unrelated to this campaign.","heading":"Campaign Overview and Scope","severity":"critical","sources":[{"credibility":2,"name":"Bitget CEO suspects North Korea behind $352M hack, citing IP clues — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/bitget-ceo-suspects-north-korea-behind-352m-hack-citing-ip-clues"},{"credibility":2,"name":"Specter: The attacker on Bitget may be the same as AFX — ChainCatcher","type":"research","url":"https://www.chaincatcher.com/en/article/2292176"},{"credibility":2,"name":"AFX schedules Aug. 3 goodwill plan following $24.15M bridge hack — CryptoNews","type":"news_article","url":"https://cryptonews.net/news/security/33229099/"}]},{"content":"At 18:31 UTC on September 24, 2026, Bitget detected unauthorized transfers from its hot and warm wallet infrastructure. CEO Gracy Chen confirmed a total loss of $351.6 million in a public statement posted at 21:30 UTC. A second update at 00:43 UTC on September 25 disclosed that attackers had compromised a backend system used in Bitget's operations and exploited it to spoof transaction data, triggering the exchange's own authorization signing process to move funds outward. Cold wallets were not affected and no private keys were confirmed stolen. The asset breakdown consisted of approximately 102.9 million XRP (~$157.5M), 31,890 ETH (~$85.75M), stablecoins totaling ~$75.48M (subsequently converted to approximately $170M in ETH by the attackers), plus BNB, AVAX, TRX, and Tether Gold. Bitget's $464M User Protection Fund was cited as covering the full loss. Chen stated investigators found 'IP addresses matching virtual private network patterns used by a group from the Democratic People's Republic of Korea' and noted the behavioral profile resembled prior North Korean operations. She acknowledged this attribution is preliminary and no completed forensic report had been published at the time of her statement. An insider-threat scenario had not been fully ruled out at initial disclosure. Circle (at 05:00 UTC September 25) and Tether subsequently blacklisted the wallet labeled 'Bitget Exploiter 8' on Etherscan, freezing approximately $318,000 in stablecoins — a fraction of the total theft, as the attackers had already converted the majority of freezable assets to ETH, which has no issuer-level freeze mechanism. More than 63,000 ETH remained in exploiter addresses not subject to any issuer intervention.","heading":"Bitget Exchange Hack — September 24, 2026 ($351.6M)","severity":"critical","sources":[{"credibility":1,"name":"Crypto platform Bitget suspects North Korea is responsible for $352 million hack — CNBC","type":"news_article","url":"https://www.cnbc.com/2026/09/25/crypto-platform-bitget-suspects-north-korea-in-352-million-hack.html"},{"credibility":1,"name":"North Korean hackers suspected in $351M crypto theft, the largest so far this year — TechCrunch","type":"news_article","url":"https://techcrunch.com/2026/09/25/north-korean-hackers-suspected-in-351m-crypto-theft-the-largest-so-far-this-year/"},{"credibility":2,"name":"Bitget Hacked for $351.6M: Withdrawals Frozen as CEO Points to North Korea — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/25/bitget-hacked-for-351-6m-withdrawals-frozen-as-ceo-points-to-north-korea/"},{"credibility":2,"name":"Bitget Hack Confirmed: $350M Drained From Exchange Wallets — AirdropAlert","type":"news_article","url":"https://airdropalert.com/blogs/bitget-hack/"},{"credibility":2,"name":"Bitget hack $351.6M stolen, biggest breach of 2026 — Shattered.io","type":"news_article","url":"https://shattered.io/bitget-hack-351-million-2026/"},{"credibility":2,"name":"Bitget Hack: $157M in Stolen XRP Sits in Wallets No One Can Freeze — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/exchanges/bitget-hack-xrp-157m-cannot-be-frozen/"},{"credibility":2,"name":"Bitget's North Korea-linked $352 million hack could drain 76% of its protection fund — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/bitgets-north-korea-linked-352-million-hack-could-drain-76-of-its-protection-fund/"},{"credibility":1,"name":"North Korea Suspected in $351 Million Bitget Crypto Heist — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/north-korea-suspected-in-351-million-bitget-crypto-heist/"},{"credibility":2,"name":"Circle and Tether step in to freeze hacker wallet after massive Bitget crypto heist — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/25/circle-and-tether-step-in-to-freeze-hacker-wallet-after-massive-bitget-crypto-heist"},{"credibility":1,"name":"Hackers steal $351.6 million in Bitget crypto exchange hack — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/"}]},{"content":"On-chain analyst Specter published findings on or around September 25, 2026, tracing stolen XRP from the Bitget breach through cross-chain bridging to an Ethereum address that had received 68,808 USDT from a wallet previously labeled the 'AFX EXPLOITER' address. Specter stated: 'The stolen XRP from Bitget, after cross-chain transfer, can be directly linked to the stolen funds in the AFX attack.' This constitutes a chain-of-custody linkage suggesting both incidents involved the same actor or infrastructure. AFX's July 22 post-mortem had separately attributed its $24.15M breach to TraderTraitor (UNC4899). The Bitget–AFX link therefore forms the primary evidentiary basis for the TraderTraitor sub-attribution in this campaign page. Bitget itself had not confirmed Specter's specific on-chain connection at the time of its disclosures. This attribution chain should be treated as alleged pending a completed forensic report or independent corroboration from a Tier 1 source such as the FBI or a court filing.","heading":"On-Chain Attribution: Specter Analysis and AFX-Bitget Link","severity":"high","sources":[{"credibility":2,"name":"Specter: The attacker on Bitget may be the same as AFX — ChainCatcher","type":"research","url":"https://www.chaincatcher.com/en/article/2292176"},{"credibility":3,"name":"Stolen XRP from Bitget hack linked to July AFX theft, hinting at Lazarus Group ties — Pluang","type":"news_article","url":"https://pluang.com/en/news-feed/pencurian-bitget-terkait-dana-hack-afx-juli"},{"credibility":2,"name":"Bitget CEO suspects North Korea behind $352M hack, citing IP clues — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/bitget-ceo-suspects-north-korea-behind-352m-hack-citing-ip-clues"}]},{"content":"On July 22, 2026 at 21:27 UTC, approximately $24.15 million in USDC was drained from AFX Exchange's custody bridge. AFX's post-mortem attributed the attack to UNC4899, also tracked as TraderTraitor, a DPRK-backed threat actor tracked by Mandiant, Microsoft Threat Intelligence, the FBI, and CISA. The attack began with a social engineering campaign on July 9 in which an attacker impersonating a recruiter for 'Oddium Lab' convinced an AFX developer to clone a malicious Git repository. The repository contained a hidden payload embedded in a Git configuration that executed during a routine Git workflow, granting the attacker initial access to the developer's workstation. The attacker subsequently escalated privileges through internal development systems, uploaded malicious code to AFX's JFrog artifact repository, and deployed payloads across validator nodes via an Ansible-based management service. Stolen USDC was converted to approximately 12,467 ETH. AFX announced a goodwill plan on August 3, 2026; no stolen assets were publicly reported as recovered. This incident is a formally attributed prior act in the same campaign chain per Specter's Bitget analysis.","heading":"AFX Exchange Hack — July 22, 2026 ($24.15M) — Prior Connected Incident","severity":"critical","sources":[{"credibility":2,"name":"AFX schedules Aug. 3 goodwill plan following $24.15M bridge hack — CryptoNews","type":"news_article","url":"https://cryptonews.net/news/security/33229099/"},{"credibility":2,"name":"AFX Bridge Exploit Recovery: $24 Million USDC Attack Insights — CryptoNomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/07/31/afx-bridge-exploit-recovery/"},{"credibility":2,"name":"North Korean Hackers 'Very Likely' Drained $350 Million From Bitget, CEO Says — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/north-korean-hackers-very-likely-052019025.html"}]},{"content":"Security researchers documented a new Lazarus Group / TraderTraitor attack vector in April 2026 designated 'Mach-O Man,' a macOS-targeted campaign using a social engineering technique called ClickFix. Targets — typically executives at crypto, fintech, or Web3 firms — receive messages impersonating contacts on Telegram or similar platforms containing invitations to video conference sessions. The link redirects to a fake collaboration platform displaying a simulated connection error that instructs the user to paste and execute a terminal command to 'fix' the issue. The command launches a staged macOS binary (Mach-O format) that retrieves additional payloads and injects the macrasv2 credential-stealer. Secondary modules conduct system profiling including OS details, host identifiers, network configuration, and browser extension data. The malware is modular and self-deletes before victims commonly detect the intrusion. CertIK reported on this vector for CoinDesk in April 2026. The Mach-O Man toolkit has been linked to Lazarus Group infrastructure through C2 overlaps and is assessed as an evolution of the group's long-running fake-recruiter and fake-meeting social engineering playbook. Whether this specific vector was used in the Bitget or AFX intrusions has not been confirmed in public reporting.","heading":"Mach-O Man / ClickFix Attack Vector (First Documented April 2026)","severity":"high","sources":[{"credibility":2,"name":"Lazarus Group has a new attack vector — Mach-O Man — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/22/lazarus-group-has-become-especially-dangerous-with-new-mach-o-man-attack-certik"},{"credibility":2,"name":"New Mach-O Man malware tapped by Lazarus in macOS-targeted ClickFix attacks — SC Media","type":"news_article","url":"https://www.scworld.com/brief/new-mach-o-man-malware-tapped-by-lazarus-in-macos-targeted-clickfix-attacks"},{"credibility":2,"name":"Lazarus Hackers Attacking macOS Users With 'Mach-O Man' Malware Kit — CyberSecurityNews","type":"news_article","url":"https://cybersecuritynews.com/mach-o-man-macos-malware-lazarus/"},{"credibility":2,"name":"Lazarus 'Mach-O Man' Malware: What CISOs Need to Know — ANY.RUN","type":"research","url":"https://any.run/cybersecurity-blog/lazarus-macos-malware-mach-o-man/"}]},{"content":"Separate from the exchange heists, the lazarus.day tracker documented two supply chain poisoning campaigns active in September 2026 attributed to North Korean actors. The PolinRider campaign involved the compromise of Packagist package development branches, specifically targeting `visanduma/nova-two-factor`, with C2 addresses derived from Ethereum transaction data — a technique enabling covert, on-chain command delivery. The related GHAPPIER Loader operation saw 65 repositories compromised across 22 accounts, with infrastructure connected to the PolinRider campaign. These operations indicate ongoing developer-targeted activity running in parallel with the exchange-level thefts and consistent with TraderTraitor's established supply chain compromise tactics (as documented in the Bybit SafeWallet developer workstation attack in February 2025 and the AFX JFrog repository compromise in July 2026).","heading":"September 2026 Supply Chain Operations: PolinRider and GHAPPIER","severity":"high","sources":[{"credibility":2,"name":"Reports in 2026 — lazarus.day tracker","type":"research","url":"https://lazarus.day/reports/2026/"}]},{"content":"On September 7, 2026, approximately 4,000 BTC (roughly $320M) were withdrawn from the Liquid Network sidechain developed by Blockstream, representing approximately 95% of all bitcoin pegged into the network. The exploit involved the unauthorized minting of L-BTC tokens that were unbacked — the Liquid Network accepted them as valid despite no corresponding BTC being locked. The withdrawal occurred through the SideSwap trading platform. Blockstream attributed the incident to a software bug in the Elements codebase rather than compromised cryptographic keys or phishing. The perpetrators embedded messages in Bitcoin transactions self-identifying as 'whitehats' and offered to return the funds after the vulnerability was fixed. Blockstream deployed updated software and the actors reportedly returned approximately 85% of the withdrawn BTC. No public attribution to DPRK, Lazarus Group, or any state-sponsored actor has been made for this incident. It is included here for temporal context as the largest single loss event in September 2026 prior to the Bitget hack, but it is not assessed as part of the DPRK campaign.","heading":"Liquid Network Exploit — September 7, 2026 ($320M) — Unrelated Incident","severity":"medium","sources":[{"credibility":2,"name":"$320 million bitcoin exploit hits Liquid Network — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/07/bitcoin-network-used-by-exchanges-hit-by-usd320-million-exploit-hackers-claim-they-re-the-good-guys"},{"credibility":1,"name":"Hackers drain $320M in Bitcoin from Liquid Network, claim they're the good guys — The Register","type":"news_article","url":"https://www.theregister.com/security/2026/09/07/hackers-drain-320m-in-bitcoin-from-liquid-network-claim-theyre-the-good-guys/5294770"},{"credibility":2,"name":"Explained: The Liquid Network Hack (September 2026) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-liquid-network-hack-september-2026"},{"credibility":2,"name":"How The $320M Exploit of Liquid Network Went Down — Chainalysis","type":"research","url":"https://www.chainalysis.com/blog/320m-exploit-liquid-network/"}]},{"content":"TraderTraitor (also tracked as UNC4899 by Mandiant, Jade Sleet by Microsoft, and Slow Pisces by Unit 42) is a sub-actor of North Korea's Lazarus Group / APT38 complex. In April 2022, the FBI, CISA, and U.S. Treasury issued joint advisory AA22-108A formally attributing TraderTraitor to North Korea's state apparatus and documenting its campaigns targeting cryptocurrency companies through trojanized trading applications built with Node.js and the Electron framework. In December 2024, the FBI, Japan's National Police Agency, and DC3 issued a joint attribution formally identifying TraderTraitor as responsible for the $308M theft from DMM Bitcoin. The Bybit $1.5B theft in February 2025 was also attributed by the FBI to TraderTraitor. The group's known tactics include spearphishing of DevOps and system administration staff via fake recruitment pitches, supply chain poisoning of developer tools and artifact repositories, and manipulation of wallet signing pipelines without obtaining underlying private keys — a technique observed in both the Bybit and Bitget breaches.","heading":"TraderTraitor: Background and Official Government Attribution","severity":"critical","sources":[{"credibility":1,"name":"TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies — CISA Advisory AA22-108A","type":"regulatory","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-108a"},{"credibility":1,"name":"FBI, DC3, and NPA Identification of North Korean Cyber Actors Tracked as TraderTraitor Responsible for Theft of $308M from Bitcoin.DMM.com — FBI","type":"regulatory","url":"https://www.fbi.gov/news/press-releases/fbi-dc3-and-npa-identification-of-north-korean-cyber-actors-tracked-as-tradertraitor-responsible-for-theft-of-308-million-from-bitcoindmmcom"},{"credibility":2,"name":"Don't Call Us, We'll Call Your APIs — TraderTraitor Backdoors Resurface — SentinelOne","type":"research","url":"https://www.sentinelone.com/labs/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties/"},{"credibility":2,"name":"TraderTraitor: Deep Dive — Wiz Blog","type":"research","url":"https://www.wiz.io/blog/north-korean-tradertraitor-crypto-heist"}]},{"content":"Through September 2026, North Korean actors have been attributed to over $1 billion in confirmed or highly likely cryptocurrency theft, per Elliptic's assessment following the Bitget breach. The previously documented April 2026 campaign (Drift Protocol ~$285M on April 1 and KelpDAO ~$292M on April 18, combined ~$577M) was attributed to the same TraderTraitor sub-actor by LayerZero in its post-mortem. Including the AFX Exchange breach ($24.15M, July 22, formally attributed) and the Bitget breach ($351.6M, September 24, assessed highly likely), the 2026 attributed total exceeds $950M in confirmed or formally attributed incidents, with Elliptic placing the crossed-$1B marker at the time of the Bitget disclosure. Through April 2026, DPRK-attributed losses represented approximately 76% of all crypto hack value year-to-date, per multiple security firm reports. The total 2026 DeFi/crypto hack loss figure through the first eight months stood at approximately $1.3 billion per crypto.news, with a separate figure of approximately $2.2 billion across 281 incidents through September citing a broader all-incident scope. North Korea's $2.02 billion in 2025 theft (including the $1.5B Bybit hack) brought their all-time cumulative to approximately $6.75 billion per Bex.co research. UN Panel of Experts reports have assessed that crypto theft proceeds fund a material proportion of North Korea's ballistic missile and nuclear weapons development programs.","heading":"2026 Year-to-Date Scale and DPRK Attribution Rate","severity":"critical","sources":[{"credibility":2,"name":"The Lazarus Group and DPRK Crypto Theft in 2026: What Compliance Teams Need to Know — Sanctions.io","type":"research","url":"https://www.sanctions.io/blog/the-lazarus-group-and-dprk-crypto-theft-in-2026"},{"credibility":2,"name":"DeFi has lost $1.3 billion to hacks in 2026 and the same attack keeps working — crypto.news","type":"news_article","url":"https://crypto.news/defi-hacks-2026-billion-lost-same-attack-keeps-working/"},{"credibility":2,"name":"North Korean Lazarus Group steals $635 million from crypto protocols in April 2026 — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/north-korean-lazarus-group-steals-635m-from-crypto-protocols-in-april-2026"},{"credibility":2,"name":"Reports in 2026 — lazarus.day tracker (Elliptic assessment cited)","type":"research","url":"https://lazarus.day/reports/2026/"},{"credibility":2,"name":"The Lazarus Group Playbook: Inside North Korea's $6.75B All-Time Crypto Theft Operation — Bex.co","type":"research","url":"https://bex.co/blog/2026/02/03/lazarus-group-playbook-north-korea-crypto-theft-6-75-billion"},{"credibility":2,"name":"Lazarus Group: The North Korean Hacking Syndicate's On-Chain Footprint — Arkham Intelligence","type":"research","url":"https://info.arkm.com/research/lazarus-group-the-north-korean-hacking-syndicates-on-chain-footprint"},{"credibility":2,"name":"Lazarus Group has been funding North Korea's entire nuclear program with stolen crypto — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/lazarus-group-north-korea-nuclear-crypto/"}]},{"content":"On September 25, 2026, independent on-chain investigator ZachXBT posted publicly: 'Have no current plans to monitor the Bitget exploit by DPRK. I stopped wasting my time on helping people in the industry who are not supporters of my work (donors, clients, longtime followers, etc).' The investigator framed the decision as a resource allocation choice rather than a comment on the validity of the DPRK attribution or Bitget's security practices. ZachXBT is among the most widely followed independent investigators in the crypto space and his public monitoring threads on major exchange hacks have historically constituted a parallel informal record of incident documentation. His stated decision to withhold monitoring in this case reduces the informal investigative coverage available to the public and industry participants tracking the Bitget incident. The absence of ZachXBT's thread does not affect the underlying evidence or the quality of the formal investigations being conducted by Mandiant, SlowMist, and blockchain foundations working with Bitget.","heading":"ZachXBT Declines to Monitor Bitget Incident","severity":"low","sources":[{"credibility":2,"name":"Security Researcher ZachXBT Says He Will Not Monitor the Bitget Hack Incident — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/25/security-researcher-zachxbt-says-he-will-not-monitor-bitget-hack-incident/"}]},{"content":"Post-incident fund movements in DPRK-attributed hacks follow a documented four-stage laundering typology identified by compliance researchers: rapid cross-chain movement immediately post-theft to fragment on-chain trails; use of alternative mixing services following the 2022 OFAC sanctioning of Tornado Cash; chain-hopping across multiple networks to obscure origin; and OTC conversion through informal brokers concentrated in Southeast Asia and the Middle East. In the Bitget case, attackers were observed converting stablecoins to ETH prior to or concurrent with the freeze action by Circle and Tether, consistent with this typology's first stage of eliminating freezable assets. The XRP identified by Specter as bridging to the AFX exploiter address cluster represents a detected fragment of the cross-chain movement stage.","heading":"DPRK Laundering Typology","severity":"high","sources":[{"credibility":2,"name":"The Lazarus Group and DPRK Crypto Theft in 2026: What Compliance Teams Need to Know — Sanctions.io","type":"research","url":"https://www.sanctions.io/blog/the-lazarus-group-and-dprk-crypto-theft-in-2026"},{"credibility":2,"name":"How The $320M Exploit of Liquid Network Went Down — Chainalysis","type":"research","url":"https://www.chainalysis.com/blog/320m-exploit-liquid-network/"}]}],"sources_used":[{"credibility":1,"name":"Crypto platform Bitget suspects North Korea is responsible for $352 million hack — CNBC","type":"news_article","url":"https://www.cnbc.com/2026/09/25/crypto-platform-bitget-suspects-north-korea-in-352-million-hack.html"},{"credibility":1,"name":"North Korean hackers suspected in $351M crypto theft — TechCrunch","type":"news_article","url":"https://techcrunch.com/2026/09/25/north-korean-hackers-suspected-in-351m-crypto-theft-the-largest-so-far-this-year/"},{"credibility":1,"name":"North Korea Suspected in $351 Million Bitget Crypto Heist — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/north-korea-suspected-in-351-million-bitget-crypto-heist/"},{"credibility":1,"name":"Hackers steal $351.6 million in Bitget crypto exchange hack — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/"},{"credibility":2,"name":"Bitget CEO suspects North Korea behind $352M hack, citing IP clues — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/bitget-ceo-suspects-north-korea-behind-352m-hack-citing-ip-clues"},{"credibility":2,"name":"Bitget Hacked for $351.6M: Withdrawals Frozen as CEO Points to North Korea — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/25/bitget-hacked-for-351-6m-withdrawals-frozen-as-ceo-points-to-north-korea/"},{"credibility":2,"name":"Circle and Tether step in to freeze hacker wallet after massive Bitget crypto heist — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/25/circle-and-tether-step-in-to-freeze-hacker-wallet-after-massive-bitget-crypto-heist"},{"credibility":2,"name":"Security Researcher ZachXBT Says He Will Not Monitor the Bitget Hack Incident — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/25/security-researcher-zachxbt-says-he-will-not-monitor-bitget-hack-incident/"},{"credibility":2,"name":"Bitget's North Korea-linked $352 million hack could drain 76% of its protection fund — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/bitgets-north-korea-linked-352-million-hack-could-drain-76-of-its-protection-fund/"},{"credibility":2,"name":"Specter: The attacker on Bitget may be the same as AFX — ChainCatcher","type":"research","url":"https://www.chaincatcher.com/en/article/2292176"},{"credibility":2,"name":"AFX schedules Aug. 3 goodwill plan following $24.15M bridge hack — CryptoNews","type":"news_article","url":"https://cryptonews.net/news/security/33229099/"},{"credibility":1,"name":"Hackers drain $320M in Bitcoin from Liquid Network, claim they're the good guys — The Register","type":"news_article","url":"https://www.theregister.com/security/2026/09/07/hackers-drain-320m-in-bitcoin-from-liquid-network-claim-theyre-the-good-guys/5294770"},{"credibility":2,"name":"$320 million bitcoin exploit hits Liquid Network — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/07/bitcoin-network-used-by-exchanges-hit-by-usd320-million-exploit-hackers-claim-they-re-the-good-guys"},{"credibility":2,"name":"How The $320M Exploit of Liquid Network Went Down — Chainalysis","type":"research","url":"https://www.chainalysis.com/blog/320m-exploit-liquid-network/"},{"credibility":2,"name":"Explained: The Liquid Network Hack (September 2026) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-liquid-network-hack-september-2026"},{"credibility":1,"name":"TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies — CISA Advisory AA22-108A","type":"regulatory","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-108a"},{"credibility":1,"name":"FBI, DC3, and NPA Identification of North Korean Cyber Actors Tracked as TraderTraitor — FBI","type":"regulatory","url":"https://www.fbi.gov/news/press-releases/fbi-dc3-and-npa-identification-of-north-korean-cyber-actors-tracked-as-tradertraitor-responsible-for-theft-of-308-million-from-bitcoindmmcom"},{"credibility":2,"name":"The Lazarus Group and DPRK Crypto Theft in 2026: What Compliance Teams Need to Know — Sanctions.io","type":"research","url":"https://www.sanctions.io/blog/the-lazarus-group-and-dprk-crypto-theft-in-2026"},{"credibility":2,"name":"DeFi has lost $1.3 billion to hacks in 2026 and the same attack keeps working — crypto.news","type":"news_article","url":"https://crypto.news/defi-hacks-2026-billion-lost-same-attack-keeps-working/"},{"credibility":2,"name":"Reports in 2026 — lazarus.day tracker","type":"research","url":"https://lazarus.day/reports/2026/"},{"credibility":2,"name":"North Korean Lazarus Group steals $635 million from crypto protocols in April 2026 — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/north-korean-lazarus-group-steals-635m-from-crypto-protocols-in-april-2026"},{"credibility":2,"name":"Lazarus Group has a new attack vector — Mach-O Man — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/22/lazarus-group-has-become-especially-dangerous-with-new-mach-o-man-attack-certik"},{"credibility":2,"name":"New Mach-O Man malware tapped by Lazarus in macOS-targeted ClickFix attacks — SC Media","type":"news_article","url":"https://www.scworld.com/brief/new-mach-o-man-malware-tapped-by-lazarus-in-macos-targeted-clickfix-attacks"},{"credibility":2,"name":"Don't Call Us, We'll Call Your APIs — TraderTraitor Backdoors Resurface — SentinelOne","type":"research","url":"https://www.sentinelone.com/labs/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties/"},{"credibility":2,"name":"TraderTraitor: Deep Dive — Wiz Blog","type":"research","url":"https://www.wiz.io/blog/north-korean-tradertraitor-crypto-heist"},{"credibility":2,"name":"LayerZero blames Kelp's setup for $290 million exploit, attributes it to North Korea's Lazarus — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/20/layerzero-blames-kelp-s-setup-for-usd290-million-exploit-attributes-it-to-north-korea-s-lazarus"},{"credibility":2,"name":"North Korean Hackers 'Very Likely' Drained $350 Million From Bitget, CEO Says — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/north-korean-hackers-very-likely-052019025.html"},{"credibility":2,"name":"The Lazarus Group Playbook: Inside North Korea's $6.75B All-Time Crypto Theft Operation — Bex.co","type":"research","url":"https://bex.co/blog/2026/02/03/lazarus-group-playbook-north-korea-crypto-theft-6-75-billion"},{"credibility":2,"name":"Lazarus Group: The North Korean Hacking Syndicate's On-Chain Footprint — Arkham Intelligence","type":"research","url":"https://info.arkm.com/research/lazarus-group-the-north-korean-hacking-syndicates-on-chain-footprint"},{"credibility":2,"name":"Bitget Hack: $157M in Stolen XRP Sits in Wallets No One Can Freeze — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/exchanges/bitget-hack-xrp-157m-cannot-be-frozen/"},{"credibility":2,"name":"Lazarus Group has been funding North Korea's entire nuclear program with stolen crypto — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/lazarus-group-north-korea-nuclear-crypto/"}],"summary":"The September 2026 campaign page documents a cluster of cryptocurrency thefts attributed by multiple investigators and the exchange itself to North Korea's Lazarus Group and its TraderTraitor sub-actor. The largest confirmed incident is the September 24, 2026 Bitget exchange breach ($351.6M), which on-chain analyst Specter linked through XRP bridging patterns to the July 2026 AFX Exchange hack ($24.15M), itself formally attributed to TraderTraitor (UNC4899) in AFX's post-mortem. Elliptic assessed the Bitget theft as highly likely DPRK-linked, pushing North Korea's documented 2026 crypto theft total above $1 billion. A separate September 7 Liquid Network exploit ($320M) was claimed by self-described white-hat researchers and carries no public DPRK attribution. This campaign is distinct from the April 2026 blitz (Drift Protocol + KelpDAO, ~$577M combined) already documented separately in the corpus.","timeline":[{"date":"2022-04-18","event":"FBI, CISA, and U.S. Treasury issue joint advisory AA22-108A formally attributing TraderTraitor to North Korea's Lazarus Group, documenting cryptocurrency industry targeting tactics.","source":"CISA Advisory AA22-108A","source_url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-108a"},{"date":"2024-12-01","event":"FBI, Japan NPA, and DC3 issue joint attribution identifying TraderTraitor as responsible for the $308M theft from DMM Bitcoin.","source":"FBI Press Release","source_url":"https://www.fbi.gov/news/press-releases/fbi-dc3-and-npa-identification-of-north-korean-cyber-actors-tracked-as-tradertraitor-responsible-for-theft-of-308-million-from-bitcoindmmcom"},{"date":"2025-02-01","event":"Bybit exchange suffers $1.5B theft attributed by the FBI to TraderTraitor via a compromised SafeWallet developer laptop, the largest single crypto theft in history at the time.","source":"Sanctions.io — Lazarus Group 2026 briefing","source_url":"https://www.sanctions.io/blog/the-lazarus-group-and-dprk-crypto-theft-in-2026"},{"date":"2026-04-01","event":"Drift Protocol loses approximately $285M in a Lazarus Group / TraderTraitor attributed attack.","source":"Wasteland Intel — North Korea Crypto Heist $577M","source_url":"https://wasteland.me/intel/north-korea-crypto-heist-577m"},{"date":"2026-04-18","event":"KelpDAO loses approximately $292M in a Lazarus Group / TraderTraitor attributed attack via LayerZero bridge; LayerZero publishes formal attribution in post-mortem.","source":"CoinDesk — LayerZero blames Kelp's setup for $290 million exploit","source_url":"https://www.coindesk.com/tech/2026/04/20/layerzero-blames-kelp-s-setup-for-usd290-million-exploit-attributes-it-to-north-korea-s-lazarus"},{"date":"2026-04-22","event":"CertIK documents the Mach-O Man / ClickFix macOS attack vector used by Lazarus Group, reported by CoinDesk.","source":"CoinDesk — Lazarus Group has a new attack vector — Mach-O Man","source_url":"https://www.coindesk.com/tech/2026/04/22/lazarus-group-has-become-especially-dangerous-with-new-mach-o-man-attack-certik"},{"date":"2026-07-09","event":"TraderTraitor (UNC4899) begins social engineering campaign against AFX Exchange developer via fake Oddium Lab recruiter persona on Telegram.","source":"CryptoNews — AFX schedules Aug. 3 goodwill plan","source_url":"https://cryptonews.net/news/security/33229099/"},{"date":"2026-07-22","event":"AFX Exchange custody bridge drained of $24.15M USDC at 21:27 UTC. Post-mortem formally attributes the attack to TraderTraitor (UNC4899).","source":"CryptoNews — AFX schedules Aug. 3 goodwill plan","source_url":"https://cryptonews.net/news/security/33229099/"},{"date":"2026-08-03","event":"AFX Exchange announces goodwill recovery plan; no stolen assets publicly reported as recovered.","source":"CryptoNomist — AFX Bridge Exploit Recovery","source_url":"https://en.cryptonomist.ch/2026/07/31/afx-bridge-exploit-recovery/"},{"date":"2026-09-07","event":"Liquid Network suffers $320M exploit via unauthorized L-BTC minting through a software bug in Elements. Perpetrators self-identify as white hats; no DPRK attribution made. Approximately 85% of BTC subsequently returned.","source":"The Register — Hackers drain $320M in Bitcoin from Liquid Network","source_url":"https://www.theregister.com/security/2026/09/07/hackers-drain-320m-in-bitcoin-from-liquid-network-claim-theyre-the-good-guys/5294770"},{"date":"2026-09-24","event":"Bitget exchange detects unauthorized transfers at 18:31 UTC; $351.6M drained from hot and warm wallets via backend signing pipeline compromise. Withdrawals suspended. Attackers convert stablecoins to ETH prior to freeze intervention.","source":"CryptoTimes — Bitget Hacked for $351.6M","source_url":"https://www.cryptotimes.io/2026/09/25/bitget-hacked-for-351-6m-withdrawals-frozen-as-ceo-points-to-north-korea/"},{"date":"2026-09-25","event":"Bitget CEO Gracy Chen publicly states North Korea is 'very likely' responsible, citing IP address patterns matching DPRK VPN usage. Specter publishes on-chain analysis linking stolen Bitget XRP to the AFX exploiter address cluster via cross-chain bridging.","source":"CNBC — Crypto platform Bitget suspects North Korea","source_url":"https://www.cnbc.com/2026/09/25/crypto-platform-bitget-suspects-north-korea-in-352-million-hack.html"},{"date":"2026-09-25","event":"Circle blacklists 'Bitget Exploiter 8' wallet at 05:00 UTC, freezing approximately $318,000 in stablecoins. Tether subsequently blacklists the same wallet. More than 63,000 ETH in other exploiter addresses remains unfreezable.","source":"CoinDesk — Circle and Tether step in to freeze hacker wallet","source_url":"https://www.coindesk.com/markets/2026/09/25/circle-and-tether-step-in-to-freeze-hacker-wallet-after-massive-bitget-crypto-heist"},{"date":"2026-09-25","event":"ZachXBT publicly declines to monitor the Bitget incident, stating he has stopped assisting industry parties who do not support his work.","source":"CryptoTimes — ZachXBT Says He Will Not Monitor the Bitget Hack","source_url":"https://www.cryptotimes.io/2026/09/25/security-researcher-zachxbt-says-he-will-not-monitor-bitget-hack-incident/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision a454d32a-9b15-4eaa-978d-9c9d5a419b81
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.