Lazarus Group / TraderTraitor — DPRK September 2026 Blitz Campaign
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·3d1het…qKzuSummary
The September 2026 campaign page documents a cluster of cryptocurrency thefts attributed by multiple investigators and the exchange itself to North Korea's Lazarus Group and its TraderTraitor sub-actor. The largest confirmed incident is the September 24, 2026 Bitget exchange breach ($351.6M), which on-chain analyst Specter linked through XRP bridging patterns to the July 2026 AFX Exchange hack ($24.15M), itself formally attributed to TraderTraitor (UNC4899) in AFX's post-mortem. Elliptic assessed the Bitget theft as highly likely DPRK-linked, pushing North Korea's documented 2026 crypto theft total above $1 billion. A separate September 7 Liquid Network exploit ($320M) was claimed by self-described white-hat researchers and carries no public DPRK attribution. This campaign is distinct from the April 2026 blitz (Drift Protocol + KelpDAO, ~$577M combined) already documented separately in the corpus.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(14 events)
18 April 2022
FBI, CISA, and U.S. Treasury issue joint advisory AA22-108A formally attributing TraderTraitor to North Korea's Lazarus Group, documenting cryptocurrency industry targeting tactics.
CISA Advisory AA22-108A1 December 2024
FBI, Japan NPA, and DC3 issue joint attribution identifying TraderTraitor as responsible for the $308M theft from DMM Bitcoin.
FBI Press Release1 February 2025
Bybit exchange suffers $1.5B theft attributed by the FBI to TraderTraitor via a compromised SafeWallet developer laptop, the largest single crypto theft in history at the time.
Sanctions.io — Lazarus Group 2026 briefing1 April 2026
Drift Protocol loses approximately $285M in a Lazarus Group / TraderTraitor attributed attack.
Wasteland Intel — North Korea Crypto Heist $577M18 April 2026
KelpDAO loses approximately $292M in a Lazarus Group / TraderTraitor attributed attack via LayerZero bridge; LayerZero publishes formal attribution in post-mortem.
CoinDesk — LayerZero blames Kelp's setup for $290 million exploit22 April 2026
CertIK documents the Mach-O Man / ClickFix macOS attack vector used by Lazarus Group, reported by CoinDesk.
CoinDesk — Lazarus Group has a new attack vector — Mach-O Man9 July 2026
TraderTraitor (UNC4899) begins social engineering campaign against AFX Exchange developer via fake Oddium Lab recruiter persona on Telegram.
CryptoNews — AFX schedules Aug. 3 goodwill plan22 July 2026
AFX Exchange custody bridge drained of $24.15M USDC at 21:27 UTC. Post-mortem formally attributes the attack to TraderTraitor (UNC4899).
CryptoNews — AFX schedules Aug. 3 goodwill plan3 August 2026
AFX Exchange announces goodwill recovery plan; no stolen assets publicly reported as recovered.
CryptoNomist — AFX Bridge Exploit Recovery7 September 2026
Liquid Network suffers $320M exploit via unauthorized L-BTC minting through a software bug in Elements. Perpetrators self-identify as white hats; no DPRK attribution made. Approximately 85% of BTC subsequently returned.
The Register — Hackers drain $320M in Bitcoin from Liquid Network24 September 2026
Bitget exchange detects unauthorized transfers at 18:31 UTC; $351.6M drained from hot and warm wallets via backend signing pipeline compromise. Withdrawals suspended. Attackers convert stablecoins to ETH prior to freeze intervention.
CryptoTimes — Bitget Hacked for $351.6M25 September 2026
Bitget CEO Gracy Chen publicly states North Korea is 'very likely' responsible, citing IP address patterns matching DPRK VPN usage. Specter publishes on-chain analysis linking stolen Bitget XRP to the AFX exploiter address cluster via cross-chain bridging.
CNBC — Crypto platform Bitget suspects North Korea25 September 2026
Circle blacklists 'Bitget Exploiter 8' wallet at 05:00 UTC, freezing approximately $318,000 in stablecoins. Tether subsequently blacklists the same wallet. More than 63,000 ETH in other exploiter addresses remains unfreezable.
CoinDesk — Circle and Tether step in to freeze hacker wallet25 September 2026
ZachXBT publicly declines to monitor the Bitget incident, stating he has stopped assisting industry parties who do not support his work.
CryptoTimes — ZachXBT Says He Will Not Monitor the Bitget HackDecision Log
- hash: GdVPAPxf3XyZc1yo1debqbWtT5GmJPHCMfbbcWV4XTjx
This investigation is cryptographically anchored to the Solana blockchain (1 event). 20 of 31 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 9/25/2026, 5:08:22 PM
last updated: 9/25/2026, 7:14:38 PM
avoid.net — verified advice for a post-truth world