Summary
Solareum was a Solana-based Telegram trading bot that shut down on March 30, 2024 following a security exploit that drained approximately $523,000 (2,800+ SOL) from over 300 user wallets. Prosecutors later revealed in a January 2025 court filing that the Solareum team had unknowingly hired a North Korean (DPRK) developer in December 2023, who subsequently facilitated the theft of 6,045 SOL worth roughly $1.4 million; the FBI seized approximately $950,000 in USDT two months after the hack. The project offered no compensation to victims, deleted its website and community channels, and is no longer operational.
Connected Entities
1 entitiesTimeline(5 events)
2023-12
Solareum team publicly announces in its Telegram support channel that it is 'onboarding a new dev' — later identified by prosecutors as a North Korean (DPRK) national operating under a false identity.
2024-03-29
Exploit begins: over 300 Solana users report their wallets have been drained. Approximately 2,800 SOL (~$523,000) is stolen. Solareum acknowledges a possible security breach. BONKbot analysis identifies private key importation into Solareum as the common factor among victims.
2024-03-30
Security researcher Taylor Monahan is brought in to investigate; identifies DPRK IT worker fingerprints in the onchain activity. Tether freezes stolen funds after researchers provide evidence. Solareum announces project shutdown via Telegram, citing 'insufficient funds, evolving market trends, and a recent security breach.' Website is deleted and community channels are closed. No compensation plan is announced for affected users.
2024-05
Approximately two months after the March hack, the FBI seizes approximately $950,000 in USDT connected to the laundered Solareum exploit proceeds.
2025-01-21
Prosecutors file a court filing in the Northern District of Georgia detailing how a DPRK developer infiltrated Solareum and stole 6,045 SOL (~$1.4 million) as part of a broader action charging four North Koreans with cryptocurrency theft schemes.
Decision Log
- hash: 2sniDep4rngrLL8uRxDZtBSn73yJ6nrjZcpz1nQXoRuN
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:33 AM
last updated: 5/27/2026, 5:32:26 PM
avoid.net — verified advice for a post-truth world