Remitano Hot Wallets Drained for $2.7M, But Tether Freeze Limits Damage to $260K
Remitano became the third centralized exchange in a matter of weeks to suffer a major hot-wallet breach, following the earlier Stake and CoinEx incidents — a pattern that has led some observers to wonder whether the Lazarus Group is running through a September hit list.
Roughly $2.7M was pulled from Remitano's Ethereum and Tron hot wallets. On-chain sleuths at Cyvers were first to flag the suspicious withdrawals, though Remitano did not confirm the incident publicly until roughly 20 hours after the attack had already started.

There was, at least, a partial silver lining this time. Tether moved quickly to freeze stablecoins tied to the theft, and that intervention cut the attacker's realized take from the initial $2.7M down to approximately $260K.
Credit: PeckShield, Cyvers
On-chain data shows the attack began at 12:47 PM UTC the day before the announcement. As with the two other recent cases, this wasn't a smart-contract exploit — it was a plain hot-wallet drain traceable to a compromised private key. Given how closely it mirrors the other two high-profile breaches from the prior two weeks, speculation has again turned toward the Lazarus Group, the DPRK-linked state hacking outfit known for this style of operation.
Remitano's official statement stops short of explaining exactly how the hot wallet keys were obtained, pinning the root cause on "a data breach from a third-party source." According to the post, once the breach was identified the team shifted remaining balances from its other hot wallets into cold storage and began coordinating with Tether to freeze the stolen stablecoins.
That coordination resulted in a combined 1.9M USDT frozen across both chains. The Ethereum-side funds that weren't frozen were converted into ETH and sent on to an exchange — believed to be either HitBTC or Changelly. The Tron-side proceeds, by contrast, are still sitting untouched in the attacker's wallet.
Attacker addresses:
ETH: 0x74530e81e9f4715c720b6b237f682cd0e298b66c
TRON: TEDNf1aqk8YJEUdNH9NRd4MqibZmdP49Fm
Stolen on Ethereum:
1.36M USDT
210K USDC
34.4 ETH
100K ANKR
Stolen on Tron:
540K USDT

3.75M TRX
Tether's turnaround this time was fast enough to preserve most of the funds, and Cyvers has called on other exchanges to screen incoming deposits and block whatever hasn't already been frozen.
That said, the broader industry pattern remains one of slow, half-measure responses to these events. Custodians clearly need to do better at securing wallets in the first place, but the aftermath often reveals just as glaring a gap.
Even wallets with documented ties to Lazarus continue to move without obstruction through major exchanges, with blockchain investigators reduced to watching transfers unfold in real time rather than stopping them. Even well-known, reputable platforms have shown little inclination to intervene — an odd choice given that cooperating would seem to serve their own reputational interests at a moment like this.
The tools to do far better already exist within the industry's own technology stack. The open question is how much longer platforms will keep declining to use them.
Get new scam files the moment we publish them — usually 2–3 emails a week.