CryptoReal
CASE FILE — Jul 26, 2023

Suspected Lazarus Group Drains $60M From Payments Processor AlphaPo

AlphaPo, a payment processing service used by gambling platforms, saw roughly $60 million siphoned from its infrastructure across Ethereum, Tron, and Bitcoin over a single weekend.

The scale of the loss only came into focus in stages. Researcher ZachXBT first put the figure at $23 million, before tracing an additional $37 million the following day, bringing the confirmed total to $60 million.

Hypedrop, a platform that relies on AlphaPo for payment processing, paused withdrawals and deposits in response. The platform told users that withdrawals would eventually resume, though it did not directly acknowledge the hack.

Both the method of attack and the way funds moved afterward led investigators toward a familiar suspect. ZachXBT noted that the operation carried hallmarks associated with state-backed hacking crews:

This hack appears to likely have been done by Lazarus as they create a very distinct fingerprint on-chain.

It marks a return to a tactic that had gone quiet for a stretch — a straightforward draining of a centralized platform's hot wallet, rather than the phishing campaigns Lazarus had more recently been running against other targets. Whether this signals a fresh wave of exchange-focused phishing remains to be seen.

The Ethereum-side theft began in the early morning hours (UTC) of Saturday, when AlphaPo's hot wallet, labeled alphapo.eth, started being emptied.

Sums referenced in this case file

The attacker moved 2,464 ETH (worth about $4.6 million) along with numerous other tokens — including more than 6 million USDT — into an address under their control. These assets were swapped into ETH, merged into a second wallet (0x6d2e8a20b8afa88d92406d315b67822c01e53c38), and then spread out further. On the Tron side, some of the stolen assets were funneled directly to centralized exchanges.

Addresses tied to the attacker:

Ethereum:

Tron:

ZachXBT reported that the on-chain fund flows — tracked publicly via this Dune dashboard — closely match known patterns linked to the Lazarus group.

Separately, MistTrack's analysis of the addresses involved found overlap with wallets connected to the earlier Atomic Wallet drain (also attributed to Lazarus), as well as a possible — though unconfirmed — connection to an incident at Coinspaid.

A $60 million loss would have been enough to top the rekt.news all-time leaderboard right up until the Poly Network exploit of August 2021 dwarfed it. These days, however, even losses of this size tend to cycle out of public attention almost immediately — whether from growing numbness to the dollar figures, bear-market fatigue, or simply that most people left in the space are focused elsewhere. Either way, Lazarus shows no sign of slowing down.

AlphaPo
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.