Skip to main content
Sign in

TraderTraitor / UNC4899

avoid.net/tradertraitor-unc48990/100·97% conf.
[AI-DRAFTED · AWAITING VERIFICATION]
anchored·2rTWUU…SVKZ

Summary

TraderTraitor (also tracked as UNC4899, Jade Sleet, Slow Pisces, and PUKCHONG) is a North Korean state-sponsored cyber threat cluster operating under the Reconnaissance General Bureau (RGB), formally designated by the FBI, CISA, and U.S. Treasury as responsible for stealing billions of dollars in cryptocurrency from blockchain companies, exchanges, and developers since at least 2020. The cluster is most prominently attributed to the February 2025 Bybit heist — the largest cryptocurrency theft in history at approximately $1.5 billion — as well as the May 2024 DMM Bitcoin theft ($308 million), the July 2023 JumpCloud supply chain attack, and the April 2022 Ronin Network compromise ($620 million). Chainalysis estimates North Korean actors, dominated by TraderTraitor operations, stole $2.02 billion in 2025 alone, pushing their all-time attributed total to approximately $6.75 billion since 2017.

Connected Entities

1 entities · 10 linked investigations
Organizations
TraderTraitor / UNC4899
Relationships
  • + 4 more
Have evidence about TraderTraitor / UNC4899?

Timeline(14 events)

2022-04-18

FBI, CISA, and U.S. Treasury issue joint advisory AA22-108A formally naming 'TraderTraitor' as a North Korean state-sponsored APT targeting blockchain companies with trojanized cryptocurrency applications.

CISA / FBI / U.S. Treasury

2022-03-23

Ronin Network (Axie Infinity) bridge exploited for approximately $620 million in ETH and USDC. FBI later formally attributed the attack to Lazarus Group / APT38 (overlapping with TraderTraitor). Initial access traced to a fake job offer PDF delivered to a Sky Mavis engineer.

CoinDesk

2023-06-27

UNC4899 (TraderTraitor) executes supply chain attack against JumpCloud, injecting malicious Ruby script into JumpCloud's command framework via spear phishing of JumpCloud employees. Fewer than five downstream cryptocurrency customers compromised. An OPSEC slip — direct connection from Pyongyang IP block — confirmed attribution.

Mandiant / Google Cloud Blog

2024-03-28

TraderTraitor actor posing as LinkedIn recruiter contacts Ginco employee with malicious Python script disguised as a pre-employment coding test, initiating the attack chain that ultimately leads to the $308 million DMM Bitcoin theft.

FBI / The Record

2024-05-31

DMM Bitcoin (Japan) loses 4,502.9 BTC (~$308 million) after TraderTraitor actors use compromised session cookies to access Ginco's communications system and manipulate a legitimate DMM transaction.

CoinDesk

2024-07-18

WazirX (India) loses approximately $234.9 million in digital assets from a multi-signature wallet. A joint statement by the U.S., South Korea, and Japan in January 2025 attributed the attack to North Korean Lazarus Group actors.

Wikipedia / Business Standard

2024-12-24

FBI, DC3, and Japan's NPA issue joint attribution statement formally linking TraderTraitor to the $308 million DMM Bitcoin theft. This is the first formal government attribution of a specific TraderTraitor incident to a named currency theft.

FBI Press Release

2025-02-21

Bybit cold wallet transfer intercepted after TraderTraitor actors compromise a Safe{Wallet} developer machine and inject malicious JavaScript into the Safe{Wallet} AWS S3-hosted frontend. Approximately 400,000 ETH (~$1.5 billion) stolen — the largest cryptocurrency theft in history.

CNBC / IC3

2025-02-26

FBI issues IC3 PSA I-022625-PSA formally attributing the Bybit theft to North Korea's TraderTraitor, listing 51 Ethereum wallet addresses and urging industry to block related transactions.

FBI / IC3

2025-04-01

Lazarus Group adopts ClickFix social engineering technique to deliver GolangGhost malware to cryptocurrency job seekers, as documented by security researchers. The campaign targets both Windows and macOS users via fake video interview platforms.

The Hacker News

2025-12-18

Chainalysis publishes 2025 crypto crime report, attributing $2.02 billion in cryptocurrency theft to North Korean actors — a record high — accounting for approximately 60% of all global crypto theft in 2025. Cumulative DPRK-attributed theft reaches approximately $6.75 billion since 2017.

CoinDesk / Chainalysis

2026-03-09

Google Threat Intelligence Group (formerly Mandiant) publishes report on UNC4899's breach of an unnamed cryptocurrency firm after a developer AirDropped a trojanized archive to a corporate device. Attackers used living-off-the-cloud techniques to steal several million dollars via Kubernetes and Cloud SQL tampering.

The Hacker News

2026-04-18

KelpDAO exploited for approximately $292 million. TRM Labs attributes the attack to TraderTraitor based on pre-funding analysis traceable to known TraderTraitor laundering networks. Approximately $175 million converted to Bitcoin via THORChain.

TRM Labs

2026-04-30

TRM Labs reports that North Korean hackers — including TraderTraitor — account for 76% of all crypto hack losses in the first four months of 2026, with $577 million stolen across two major attacks (KelpDAO and Drift Protocol).

TRM Labs / The Block
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.

model: claude-sonnet-4-6

generated: 6/3/2026, 12:08:07 AM

last updated: 6/3/2026, 12:08:12 AM

avoid.net — verified advice for a post-truth world