Crypto payment gateway CoinsPaid suspects Lazarus Group in $37M hack

27 July 2023

Cointelegraph By Brayden Lindrea

CoinsPaid said it is now working with Estonian law enforcement and several blockchain security firms are assisting to minimize the impact of the July 22 exploit.

News

Join us on social networks

Cryptocurrency payments platform CoinsPaid has pointed the finger at North Korean state-backed Lazarus Group as being behind the hacking of its internal systems, which allowed them to steal $37.3 million on July 22.

“We suspect Lazarus Group, one of the most powerful hacker organisations, is responsible,” CoinsPaid explained in a July 26 post.

While CoinsPaid didn’t explain how the money was stolen exactly, the incident forced the firm to halt operations for four days.

CoinsPaid is back to processing after being hit by a hacker attack. Сlient’s funds were not affected and are fully available.

More details in our blog: https://t.co/XukI4ZTTLw pic.twitter.com/XjkKjjsluE

— CoinsPaid (@coinspaid)

July 26, 2023

CoinsPaid confirmed that operations are back up and running in a new, limited environment.

The firm added that customer funds remain intact but considerable damage was done to the platform and the firm’s balance sheet.

Despite the huge exploit, CoinsPaid believes the cybercrime organization were chasing a much larger sum:

“We believe Lazarus expected the attack on CoinsPaid to be much more successful. In response to the attack, the company’s dedicated team of experts has worked tirelessly to fortify our systems and minimize the impact, leaving Lazarus with a record-low reward.”

CoinsPaid filed a report with Estonian law enforcement three days after the hack to further investigate the exploit. In addition, several blockchain security firms such as Chainalysis, Match Systems and Crystal assisted in CoinsPaid’s preliminary investigation over the first few days.

The firm’s CEO, Max Krupyshev is confident that the Lazarus Group will be held accountable for their actions.

“We have no doubt the hackers won’t escape justice.”

Blockchain security firm SlowMist believes the CoinsPaid hack may be linked to two recent hacks in Atomic Wallet and Alphapo, which were exploited to the tune of $100 million and $60 million respectively.

MistTrack Update

Recently, the crypto community has been stirred by a sequence of incidents involving @coinspaid, @AtomicWallet, and Alphapo.

A veneer of mystery shrouds these incidents, yet there’s a possibility that Lazarus might be behind them all! pic.twitter.com/ppxRk3xtUh

— MistTrack️ (@MistTrack_io)

July 26, 2023

Lazarus Group targeting crypto devs

Online coding platform GitHub believes — with “high confidence” — that Lazarus Group is conducting a social engineering scheme targeted at workers in the cryptocurrency and cybersecurity sectors.

According to a July 26 post by cybersecurity platform Socket.Dev, Lazarus Group’s objective is to lure in these professionals and compromise their GitHub accounts with malware-infected NPM packages to infiltrate their computers.

Related: Era Lend on zkSync exploited for $3.4M in reentrancy attack

The cybersecurity platform said the first point of contact is often on a social media platform like WhatsApp, where the rapport is built before the victims are led to clone malware-laden GitHub repositories.

Socket.Dev urged software developers to review repository invitations closely before collaborating and to be cautious when abruptly approached on social media to install npm packages.

Magazine: $3.4B of Bitcoin in a popcorn tin — The Silk Road hacker’s story

  

You might also like

Stablecoins seen as ideal fit for real-time collateral management  
Stablecoins seen as ideal fit for real-time collateral management  

Cryptocurrencies and stablecoins are gaining recognition in the traditional finance (TradFi) space for their ability to streamline payments and increase efficiency in existing financial systemsIn finance, collateral management refers to the process of managing the underlying collateral securing other financial transactions, such as loans or derivatives, to mitigate credit risks and ensure smooth transactions.Digital assets like stablecoins are the “perfect” financial instrument for real-time collateral management, according to a recent pilot by DTCC Digital Assets, which suggests that digital assets, particularly stablecoins, could modernize and simplify this critical function.“Digital assets really are the perfect use case for collateral management, whether it be uncleared derivatives, clear derivatives, central counterparties, repo, or any other type of collateral,” said Joseph Spiro, product director at DTCC Digital Assets, during a panel at Consensus 2025.From left: Ian Allison, CoinDesk reporter; Jelena DDjuric, CEO of Noble; Kyle Hauptman, chairman of the National Credit Union Administration, and Joseph Spiro, digital assets product director at DTCC Digital Assets. Source: CointelegraphCollateral management requires complicated manual processes due to stringent requirements for locked-up collateral that can only be released to the appropriate parties at pre-set intervals.“All of that can be accomplished better, faster, more efficiently through digital assets and smart contracts,” Spiro said, adding that “all the manual processing can go away.”Related: Top South Korean presidential hopefuls support legalizing Bitcoin ETFsThe pilot, dubbed the “Great Collateral Experiment,” comes as US policymakers work toward clear regulatory frameworks for stablecoins.On May 14, at least 60 of the top crypto founders gathered in Washington, DC, to support the Guiding and Establishing National Innovation for US Stablecoins, or GENIUS Act. The bill initially failed to get enough support from Democrats on May 8.Coinbase CEO in Washington, DC on May 14. Source: Brian ArmstrongThe GENIUS Act seeks to establish collateralization guidelines for stablecoin issuers while requiring full compliance with Anti-Money Laundering laws.The bill stalled on May 8 after failing to gain support from key Democrats, some of whom have voiced concerns about US President Donald Trump potentially profiting from digital assets through his crypto-related ventures.Related: Ukraine strategic Bitcoin reserve bill reportedly in final stagesStablecoins can streamline lending and settlementIncorporating stablecoins into traditional fiat-backed loans could further streamline TradFi processes, according to Kyle Hauptman, chairman of the National Credit Union Administration.The programmability of stablecoins could make the loan repayment process more transparent and streamlined for all participants. It is currently a “clunky process where they settle at the end of the month,” Hauptaman said during the same panel discussion, adding:“Stablecoins and their programmability can make this vastly easier.”“We not only made life easier for credit unions to settle these things up, you could do it for smaller amounts of money, but the borrower should get a better deal here because now this thing has some of the traits of a large bond issuance. It’s now liquid,” he said.Another piece of legislation — the Stablecoin Transparency and Accountability for a Better Ledger Economy (STABLE) Act — passed the House Financial Services Committee on April 2 in a 32–17 vote. The bill awaits scheduling for debate and a floor vote in the House of Representatives. Magazine: Bitcoin to $1M ‘by 2029,’ CIA tips its hat to Bitcoin: Hodler’s Digest, April 27 – May 3

Coinbase refuses $20M ransom after support agent data breach  
Coinbase refuses $20M ransom after support agent data breach  

Coinbase, the world’s third-largest cryptocurrency exchange, was hit by a $20 million ransom demand as cyber criminals attempted to steal sensitive user data from the exchange.Cyber criminals have bribed and recruited a “group of overseas support agents” to steal Coinbase customer data to facilitate social engineering schemes such as phishing attacks.“These insiders abused their access to customer support systems to steal the account data for a small subset of customers,” wrote Coinbase in a May 15 X post, adding that no passwords, private keys, funds, or Coinbase Prime accounts were affected.Less than 1% of Coinbase’s monthly transacting users’ data was affected by the attack.Source: CoinbaseAfter stealing the data, the attackers “tried to extort Coinbase for $20 million to cover this up,” which the exchange refused.Related: Ukraine strategic Bitcoin reserve bill reportedly in final stagesInstead, Coinbase will establish a $20 million reward for information leading to the arrest and conviction of these attackers.Scammers often masquerade as the most recognized brands to inspire a fake sense of trust in their victims.U.S. brands impersonated by scammers the most. Source: MailsuiteIn 2024, Coinbase was the most impersonated cryptocurrency brand by scammers, but the Meta platform was targeted by over 25 times as many scammers as the crypto exchange, Cointelegraph reported in June 2024.Related: Top South Korean presidential hopefuls support legalizing Bitcoin ETFs

Ukraine strategic Bitcoin reserve bill reportedly in final stages  
Ukraine strategic Bitcoin reserve bill reportedly in final stages  

Ukraine is reportedly moving closer to adopting Bitcoin as a national reserve asset, a move that could bolster its financial resilience amid the ongoing war with Russia. Lawmakers are reportedly working on a Bitcoin (BTC) national reserve proposal, with a draft bill in its final stages, according to Yaroslav Zhelezniak, a member of parliament who confirmed the plan to local media outlet Incrypted.The proposal was announced during the CRYPTO 2025 conference in Kyiv on Feb. 6. “We will soon submit a draft law from the industry allowing the creation of crypto reserves,” Zhelezniak said.Cointelegraph reached out to Zhelezniak for comment on the bill’s status but had not received a response by publication.Related: Bitcoin treasury firms driving $200T hyperbitcoinization — Adam BackBitcoin has gained international attention as a national reserve asset since the election of US President Donald Trump in November 2024. On March 7, Trump signed an executive order to establish a national Bitcoin reserve seeded with BTC confiscated from criminal cases.Source: Margo MartinA month later, Swedish MP Rickard Nordin issued an open letter urging Finance Minister Elisabeth Svantesson to consider adopting Bitcoin as a national reserve asset, citing its growing recognition as a “hedge against inflation,” Cointelegraph reported on April 11.Related: Satoshi Nakamoto turns 50 as Bitcoin becomes US reserve assetLegal challenges may delay adoptionWhile Ukraine’s push for a national Bitcoin reserve marks a potentially historic shift in crypto policy, it may require “significant legal change,” according to Kyrylo Khomiakov, regional head of CEE, Central Asia and Africa, at crypto exchange Binance.“We commend Ukraine’s ambition to establish a strategic crypto reserve,” he told Cointelegraph. “Implementing such a reserve would necessitate significant legal changes, indicating that this process will not be swift.”He added, “Another positive aspect is that this initiative will likely lead to greater regulatory clarity in Ukraine, as the government will need to articulate its stance more clearly.”Ukraine was reportedly planning to legalize cryptocurrencies in early 2025 with the finalization of a draft bill in coordination with the National Bank of Ukraine (NBU) and the International Monetary Fund (IMF), according to Daniil Getmantsev, head of the tax committee of the Verkhovna Rada.On April 8, Ukraine’s financial regulator proposed taxing certain crypto transactions as personal income with a rate of up to 23%, excluding crypto-to-crypto transactions and stablecoins.Not all voices in Ukraine’s crypto industry are optimistic about the timing of the proposal. ” The country is broke. More than 50% of the budget is in grants and loans from the European Union,” said Michael Chobanian, the founder of Ukraine-based Kuna exchange. “The population is decreasing at the fastest rate in the world. Men are kidnapped and sent to the army against their will.”“What kind of BTC reserves are we talking about here? This is done only to divert your attention,” Chobanian claimed.Magazine: Helping Ukraine without donating: Laura’s DeFi staking plan

Open chat
1
BlockFo Chat
Hello 👋, How can we help you?
📱 When you've pressed the BlockFo button, we automatically transfer to WhatsApp 🔝🔐
🖥️ Or, if you use a PC or Mac, then we'll open a new window to load your desktop app.