{"id":50858,"date":"2025-10-03T03:01:32","date_gmt":"2025-10-03T03:01:32","guid":{"rendered":"https:\/\/dogewisperer.com\/?p=50858"},"modified":"2025-10-03T03:01:32","modified_gmt":"2025-10-03T03:01:32","slug":"japanese-crypto-firm-sbi-loses-21-million-in-suspected-north-korean-cyberattack","status":"publish","type":"post","link":"https:\/\/dogewisperer.com\/?p=50858","title":{"rendered":"Japanese Crypto Firm SBI Loses $21 Million In Suspected North Korean Cyberattack"},"content":{"rendered":"<div>\n<p>Reports have disclosed that Japanese firm <a href=\"https:\/\/fxnewsgroup.com\/forex-news\/cryptocurrency\/sbi-crypto-confirms-unauthorized-outflow-of-its-crypto-assets\/\" target=\"_blank\" rel=\"noopener nofollow\">SBI Crypto<\/a> saw about $21 million siphoned from company-linked wallets on September 24, 2025.<\/p>\n<p>Blockchain sleuths flagged the movement, and on-chain traces show funds leaving addresses that start with \u201c0x40d7\u201d and \u201cbc1qx0a2k.\u201d<\/p>\n<p>The assets included Bitcoin, Ethereum, Litecoin, Dogecoin, and Bitcoin Cash. As of this report, the money has not been recovered.<\/p>\n<h2>Suspected Lazarus Group Connections<\/h2>\n<p>According to blockchain analysts, the <a href=\"https:\/\/t.me\/investigations\/278\" target=\"_blank\" rel=\"noopener nofollow\">transfers<\/a> followed a clear path: the stolen coins moved through five instant exchanges before being sent into Tornado Cash, the crypto mixer that US authorities sanctioned in 2022.<\/p>\n<p><img data-recalc-dims=\"1\" fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter size-full wp-image-596081\" src=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/10\/A_c28115.png?resize=718%2C701\" alt=\"\" width=\"718\" height=\"701\" srcset=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/10\/A_c28115.png?w=718 718w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/10\/A_c28115.png?w=430 430w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/10\/A_c28115.png?w=676 676w\" sizes=\"(max-width: 718px) 100vw, 718px\"><\/p>\n<p>Based on <a href=\"https:\/\/financefeeds.com\/sbi-crypto-reportedly-suffers-21-million-hack-with-suspected-dprk-links\/\" target=\"_blank\" rel=\"noopener nofollow\">reports<\/a>, the same set of tactics \u2014 wallet fingerprints, timing, and routing \u2014 match other intrusions linked to the Lazarus Group, the state-linked cyber unit from the DPRK.<\/p>\n<p>A US court\u2019s decision earlier this year to lift some restrictions around mixers has raised fresh concerns that these tools can be reused to hide large thefts.<\/p>\n<h2>Infiltration Schemes And Fake Profiles<\/h2>\n<p>Investigations have shown the <a href=\"https:\/\/intellectia.ai\/news\/crypto\/sbi-crypto-hacked-21m-funneled-via-tornado-cash\" target=\"_blank\" rel=\"noopener nofollow\">threat<\/a> is not only technical but social. Reports have disclosed that operatives created dozens of fake identities, bought Social Security numbers, and posed as blockchain developers on platforms such as Upwork and LinkedIn.<\/p>\n<p>Evidence posted on August 13 linked one such fake-developer wallet to a $680,000 exploit of the project Favrr in June 2025. The methods range from phishing and fake job offers to bribery and contractor infiltration, giving attackers ways to penetrate projects from the inside.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full\" src=\"https:\/\/www.tradingview.com\/x\/SBFrHU3z\/\" width=\"2048\" height=\"985\"><\/p>\n<p>A Growing Trail Of Stolen Crypto<\/p>\n<p>Based on compiled forensics data, <a href=\"https:\/\/www.financemagnates.com\/cryptocurrency\/sbi-groups-crypto-arm-reportedly-loses-21-million-in-suspected-north-korean-hack\/\" target=\"_blank\" rel=\"noopener nofollow\">North Korean-linked groups<\/a> stole more than $1.3 billion across 47 incidents in 2024. That figure jumped higher in 2025, with estimates putting thefts at about $2.2 billion in the first half of the year alone.<\/p>\n<p>Malware campaigns have also been used. In June, Cisco Talos documented \u201cPylangGhost,\u201d a campaign that used bogus coding tests and interview sites to deliver malware.<\/p>\n<p>That malware targeted over 80 browser extensions and popular wallets like MetaMask and Phantom.<\/p>\n<p>Law enforcement has made some moves: US agents seized $7.7 million tied to covert networks, and the FBI dismantled front companies such as Blocknovas LLC and Softglide LLC.<\/p>\n<p>The $21 million breach underscores how exposed even major firms remain to state-backed hacking campaigns. For now, the case stands as another warning: Japanese crypto firm SBI lost $21 million in suspected North Korean cyberattack.<\/p>\n<p><em>Featured image from Gemini, chart from TradingView<\/em><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Reports have disclosed that Japanese firm SBI Crypto saw about $21 million siphoned from company-linked wallets on September 24, 2025. Blockchain sleuths flagged the movement, and on-chain traces show funds leaving addresses that start with \u201c0x40d7\u201d and \u201cbc1qx0a2k.\u201d The assets included Bitcoin, Ethereum, Litecoin, Dogecoin, and Bitcoin Cash. As of this report, the money has [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":0,"footnotes":""},"categories":[2],"tags":[3,4,5],"class_list":["post-50858","post","type-post","status-publish","format-standard","hentry","category-news","tag-crypto","tag-doge","tag-news"],"_links":{"self":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/50858","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=50858"}],"version-history":[{"count":0,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/50858\/revisions"}],"wp:attachment":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=50858"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=50858"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=50858"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}