logo

BitoPro exchange links Lazarus hackers to $11 million crypto heist

ID: 4029983c-9dbd-5a68-a39e-1ea9d07c2609

STIX ID: report--4029983c-9dbd-5a68-a39e-1ea9d07c2609

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-06-20

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

BitoPro disclosed that on May 8, 2025 a Lazarus-attributed intrusion used social engineering and a malware implant on a cloud operator's device to hijack AWS session tokens, bypass MFA, and inject scripts into hot-wallet infrastructure; attackers stole roughly $11 million across Ethereum, Tron, Solana, and Polygon and laundered funds via DEXs and mixers. The compromise occurred during a hot-wallet update, was later detected and remediated by rotating keys and replenishing hot wallets, and an external investigation concluded there was no internal collusion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.