TraderTraitor / UNC4899
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·2rTWUU…SVKZSummary
TraderTraitor (also tracked as UNC4899, Jade Sleet, Slow Pisces, and PUKCHONG) is a North Korean state-sponsored cyber threat cluster operating under the Reconnaissance General Bureau (RGB), formally designated by the FBI, CISA, and U.S. Treasury as responsible for stealing billions of dollars in cryptocurrency from blockchain companies, exchanges, and developers since at least 2020. The cluster is most prominently attributed to the February 2025 Bybit heist — the largest cryptocurrency theft in history at approximately $1.5 billion — as well as the May 2024 DMM Bitcoin theft ($308 million), the July 2023 JumpCloud supply chain attack, and the April 2022 Ronin Network compromise ($620 million). Chainalysis estimates North Korean actors, dominated by TraderTraitor operations, stole $2.02 billion in 2025 alone, pushing their all-time attributed total to approximately $6.75 billion since 2017.
Connected Entities
1 entities- + 4 more
Timeline(14 events)
18 April 2022
FBI, CISA, and U.S. Treasury issue joint advisory AA22-108A formally naming 'TraderTraitor' as a North Korean state-sponsored APT targeting blockchain companies with trojanized cryptocurrency applications.
CISA / FBI / U.S. Treasury23 March 2022
Ronin Network (Axie Infinity) bridge exploited for approximately $620 million in ETH and USDC. FBI later formally attributed the attack to Lazarus Group / APT38 (overlapping with TraderTraitor). Initial access traced to a fake job offer PDF delivered to a Sky Mavis engineer.
CoinDesk27 June 2023
UNC4899 (TraderTraitor) executes supply chain attack against JumpCloud, injecting malicious Ruby script into JumpCloud's command framework via spear phishing of JumpCloud employees. Fewer than five downstream cryptocurrency customers compromised. An OPSEC slip — direct connection from Pyongyang IP block — confirmed attribution.
Mandiant / Google Cloud Blog28 March 2024
TraderTraitor actor posing as LinkedIn recruiter contacts Ginco employee with malicious Python script disguised as a pre-employment coding test, initiating the attack chain that ultimately leads to the $308 million DMM Bitcoin theft.
FBI / The Record31 May 2024
DMM Bitcoin (Japan) loses 4,502.9 BTC (~$308 million) after TraderTraitor actors use compromised session cookies to access Ginco's communications system and manipulate a legitimate DMM transaction.
CoinDesk18 July 2024
WazirX (India) loses approximately $234.9 million in digital assets from a multi-signature wallet. A joint statement by the U.S., South Korea, and Japan in January 2025 attributed the attack to North Korean Lazarus Group actors.
Wikipedia / Business Standard24 December 2024
FBI, DC3, and Japan's NPA issue joint attribution statement formally linking TraderTraitor to the $308 million DMM Bitcoin theft. This is the first formal government attribution of a specific TraderTraitor incident to a named currency theft.
FBI Press Release21 February 2025
Bybit cold wallet transfer intercepted after TraderTraitor actors compromise a Safe{Wallet} developer machine and inject malicious JavaScript into the Safe{Wallet} AWS S3-hosted frontend. Approximately 400,000 ETH (~$1.5 billion) stolen — the largest cryptocurrency theft in history.
CNBC / IC326 February 2025
FBI issues IC3 PSA I-022625-PSA formally attributing the Bybit theft to North Korea's TraderTraitor, listing 51 Ethereum wallet addresses and urging industry to block related transactions.
FBI / IC3April 2025
Lazarus Group adopts ClickFix social engineering technique to deliver GolangGhost malware to cryptocurrency job seekers, as documented by security researchers. The campaign targets both Windows and macOS users via fake video interview platforms.
The Hacker News18 December 2025
Chainalysis publishes 2025 crypto crime report, attributing $2.02 billion in cryptocurrency theft to North Korean actors — a record high — accounting for approximately 60% of all global crypto theft in 2025. Cumulative DPRK-attributed theft reaches approximately $6.75 billion since 2017.
CoinDesk / Chainalysis9 March 2026
Google Threat Intelligence Group (formerly Mandiant) publishes report on UNC4899's breach of an unnamed cryptocurrency firm after a developer AirDropped a trojanized archive to a corporate device. Attackers used living-off-the-cloud techniques to steal several million dollars via Kubernetes and Cloud SQL tampering.
The Hacker News18 April 2026
KelpDAO exploited for approximately $292 million. TRM Labs attributes the attack to TraderTraitor based on pre-funding analysis traceable to known TraderTraitor laundering networks. Approximately $175 million converted to Bitcoin via THORChain.
TRM Labs30 April 2026
TRM Labs reports that North Korean hackers — including TraderTraitor — account for 76% of all crypto hack losses in the first four months of 2026, with $577 million stolen across two major attacks (KelpDAO and Drift Protocol).
TRM Labs / The BlockDecision Log
- hash: C1JWBPNibTnu2a9APi3sQ4bDwDKkCW7vDiHiQT1uc8RP
- hash: B82QXvVHb2BWTpZKTNUmkKnzLfqhQG7QNTKCTZQo4eZU
- hash: 5yU58t7VvPS6QHGAZ8Say3REydWqv1STx9GwmS1fFcjs
This investigation is cryptographically anchored to the Solana blockchain (3 events). 25 of 26 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 6/3/2026, 12:08:07 AM
last updated: 7/26/2026, 11:10:21 PM
avoid.net — verified advice for a post-truth world