Skip to main content
AVOID.NET

Lazarus Group / TraderTraitor — DPRK September 2026 Blitz Campaign

avoid.net/lazarus-group-tradertraitor-dprk-september-2026-blitz-campaign→0/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·3d1het…qKzu

Summary

The September 2026 campaign page documents a cluster of cryptocurrency thefts attributed by multiple investigators and the exchange itself to North Korea's Lazarus Group and its TraderTraitor sub-actor. The largest confirmed incident is the September 24, 2026 Bitget exchange breach ($351.6M), which on-chain analyst Specter linked through XRP bridging patterns to the July 2026 AFX Exchange hack ($24.15M), itself formally attributed to TraderTraitor (UNC4899) in AFX's post-mortem. Elliptic assessed the Bitget theft as highly likely DPRK-linked, pushing North Korea's documented 2026 crypto theft total above $1 billion. A separate September 7 Liquid Network exploit ($320M) was claimed by self-described white-hat researchers and carries no public DPRK attribution. This campaign is distinct from the April 2026 blitz (Drift Protocol + KelpDAO, ~$577M combined) already documented separately in the corpus.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about Lazarus Group / TraderTraitor — DPRK September 2026 Blitz Campaign?

Timeline(14 events)

18 April 2022

FBI, CISA, and U.S. Treasury issue joint advisory AA22-108A formally attributing TraderTraitor to North Korea's Lazarus Group, documenting cryptocurrency industry targeting tactics.

CISA Advisory AA22-108A

1 December 2024

FBI, Japan NPA, and DC3 issue joint attribution identifying TraderTraitor as responsible for the $308M theft from DMM Bitcoin.

FBI Press Release

1 February 2025

Bybit exchange suffers $1.5B theft attributed by the FBI to TraderTraitor via a compromised SafeWallet developer laptop, the largest single crypto theft in history at the time.

Sanctions.io — Lazarus Group 2026 briefing

1 April 2026

Drift Protocol loses approximately $285M in a Lazarus Group / TraderTraitor attributed attack.

Wasteland Intel — North Korea Crypto Heist $577M

18 April 2026

KelpDAO loses approximately $292M in a Lazarus Group / TraderTraitor attributed attack via LayerZero bridge; LayerZero publishes formal attribution in post-mortem.

CoinDesk — LayerZero blames Kelp's setup for $290 million exploit

22 April 2026

CertIK documents the Mach-O Man / ClickFix macOS attack vector used by Lazarus Group, reported by CoinDesk.

CoinDesk — Lazarus Group has a new attack vector — Mach-O Man

9 July 2026

TraderTraitor (UNC4899) begins social engineering campaign against AFX Exchange developer via fake Oddium Lab recruiter persona on Telegram.

CryptoNews — AFX schedules Aug. 3 goodwill plan

22 July 2026

AFX Exchange custody bridge drained of $24.15M USDC at 21:27 UTC. Post-mortem formally attributes the attack to TraderTraitor (UNC4899).

CryptoNews — AFX schedules Aug. 3 goodwill plan

3 August 2026

AFX Exchange announces goodwill recovery plan; no stolen assets publicly reported as recovered.

CryptoNomist — AFX Bridge Exploit Recovery

7 September 2026

Liquid Network suffers $320M exploit via unauthorized L-BTC minting through a software bug in Elements. Perpetrators self-identify as white hats; no DPRK attribution made. Approximately 85% of BTC subsequently returned.

The Register — Hackers drain $320M in Bitcoin from Liquid Network

24 September 2026

Bitget exchange detects unauthorized transfers at 18:31 UTC; $351.6M drained from hot and warm wallets via backend signing pipeline compromise. Withdrawals suspended. Attackers convert stablecoins to ETH prior to freeze intervention.

CryptoTimes — Bitget Hacked for $351.6M

25 September 2026

Bitget CEO Gracy Chen publicly states North Korea is 'very likely' responsible, citing IP address patterns matching DPRK VPN usage. Specter publishes on-chain analysis linking stolen Bitget XRP to the AFX exploiter address cluster via cross-chain bridging.

CNBC — Crypto platform Bitget suspects North Korea

25 September 2026

Circle blacklists 'Bitget Exploiter 8' wallet at 05:00 UTC, freezing approximately $318,000 in stablecoins. Tether subsequently blacklists the same wallet. More than 63,000 ETH in other exploiter addresses remains unfreezable.

CoinDesk — Circle and Tether step in to freeze hacker wallet

25 September 2026

ZachXBT publicly declines to monitor the Bitget incident, stating he has stopped assisting industry parties who do not support his work.

CryptoTimes — ZachXBT Says He Will Not Monitor the Bitget Hack
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 20 of 31 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 9/25/2026, 5:08:22 PM

last updated: 9/25/2026, 7:14:38 PM

avoid.net — verified advice for a post-truth world