Atomic Wallet Users Lose Over $100M as Lazarus Group Exploits an Unconfirmed Flaw
Atomic Wallet suffered a major breach earlier in June 2023. While much of the crypto news cycle stayed fixed on the ongoing SEC enforcement battles, North Korea's Lazarus Group kept working in the background, and the losses have continued to climb.
Elliptic estimates the total at over $100 million so far, with the single worst-hit victim losing $8 million in USDT. The actual figure could turn out to be considerably higher.

The situation echoes a comparable attack that ran through Solana the previous August, about which we wrote at the time: "Panic, chaos, suspicion. All are inevitable reactions to an indiscriminate attack, where nobody knows who's safe, and who's next." With Atomic Wallet still offering no real clarification, that observation holds just as true now.
Much of the criticism aimed at the team stems from its track record on security. In 2021, Atomic Wallet was alerted to vulnerabilities in its product but chose not to engage with the auditors, Least Authority, who eventually felt they had no choice but to publish a public warning to users after being ignored.
Draining of Atomic Wallet addresses began just before 10pm UTC on Friday, June 2, starting with a theft of 304 ETH worth over $500,000. Atomic Wallet acknowledged the problem the next day, directing affected users to reach out by email. Beyond downplaying the scale of the incident — stating that "less than 1% of our monthly active users have been affected/reported" — the team has still not disclosed what actually caused the breach, and it's unclear whether they even know themselves.
Both desktop and mobile users were hit, with compromised addresses spanning 13 different blockchains. The theft followed a consistent three-step pattern: funds moved first into a new address, were then swapped for that chain's native token, and were finally consolidated into a third wallet.
ZachXBT and Tayvano led the effort to trace the stolen funds, a painstaking process built largely on individual victim reports and on connecting the draining pattern to the addresses that had supplied gas to the compromised accounts. Roughly $1 million has reportedly been recovered, though the method used remains undisclosed. Meanwhile, some opportunists have tried to prey on victims further by promoting a fake "refund" airdrop.
The laundering trail has shown patterns consistent with the Lazarus Group, with funds funneled toward the Sinbad Bitcoin mixer — the rebranded successor to Blender, and a service long favored by North Korean actors.

The precise root cause is still unconfirmed, though the hack may be connected to a BGP hijacking of Atomic Wallet's network traffic. BGP hijacking has factored into a number of past crypto incidents, and while it's unlikely to be enough on its own, it could plausibly have been combined with the unspecified vulnerabilities Least Authority had alluded to — the same firm that faced legal pressure to take down its disclosure post. Another possibility raised is a leak of logged sensitive user data, similar to what occurred in the Slope wallet incident on Solana. Hacken CEO Dyma Budorin has also laid out several potential scenarios for how the breach might have happened.
Whatever the ultimate cause, Tayvano captured the prevailing sentiment toward the Atomic Wallet team: "Your security posture sucks, you refuse to listen to people, you aggressively silence people, and your products and services facilitate theft on a daily basis and have for years."
Without a confirmed root cause, other wallet providers have no clear way to check whether they're exposed to the same attack vector. Given how many dubious wallet products already exist, users are better off treating any red flag as reason enough to look elsewhere — and Atomic Wallet, at this point, has accumulated no shortage of them.
Get new scam files the moment we publish them — usually 2–3 emails a week.