TraderTraitor / UNC4899
Summary
TraderTraitor (also tracked as UNC4899, Jade Sleet, Slow Pisces, and PUKCHONG) is a North Korean state-sponsored cyber threat cluster operating under the Reconnaissance General Bureau (RGB), formally designated by the FBI, CISA, and U.S. Treasury as responsible for stealing billions of dollars in cryptocurrency from blockchain companies, exchanges, and developers since at least 2020. The cluster is most prominently attributed to the February 2025 Bybit heist — the largest cryptocurrency theft in history at approximately $1.5 billion — as well as the May 2024 DMM Bitcoin theft ($308 million), the July 2023 JumpCloud supply chain attack, and the April 2022 Ronin Network compromise ($620 million). Chainalysis estimates North Korean actors, dominated by TraderTraitor operations, stole $2.02 billion in 2025 alone, pushing their all-time attributed total to approximately $6.75 billion since 2017.
Connected Entities
1 entities · 10 linked investigations- + 4 more
Timeline(14 events)
2022-04-18
FBI, CISA, and U.S. Treasury issue joint advisory AA22-108A formally naming 'TraderTraitor' as a North Korean state-sponsored APT targeting blockchain companies with trojanized cryptocurrency applications.
CISA / FBI / U.S. Treasury2022-03-23
Ronin Network (Axie Infinity) bridge exploited for approximately $620 million in ETH and USDC. FBI later formally attributed the attack to Lazarus Group / APT38 (overlapping with TraderTraitor). Initial access traced to a fake job offer PDF delivered to a Sky Mavis engineer.
CoinDesk2023-06-27
UNC4899 (TraderTraitor) executes supply chain attack against JumpCloud, injecting malicious Ruby script into JumpCloud's command framework via spear phishing of JumpCloud employees. Fewer than five downstream cryptocurrency customers compromised. An OPSEC slip — direct connection from Pyongyang IP block — confirmed attribution.
Mandiant / Google Cloud Blog2024-03-28
TraderTraitor actor posing as LinkedIn recruiter contacts Ginco employee with malicious Python script disguised as a pre-employment coding test, initiating the attack chain that ultimately leads to the $308 million DMM Bitcoin theft.
FBI / The Record2024-05-31
DMM Bitcoin (Japan) loses 4,502.9 BTC (~$308 million) after TraderTraitor actors use compromised session cookies to access Ginco's communications system and manipulate a legitimate DMM transaction.
CoinDesk2024-07-18
WazirX (India) loses approximately $234.9 million in digital assets from a multi-signature wallet. A joint statement by the U.S., South Korea, and Japan in January 2025 attributed the attack to North Korean Lazarus Group actors.
Wikipedia / Business Standard2024-12-24
FBI, DC3, and Japan's NPA issue joint attribution statement formally linking TraderTraitor to the $308 million DMM Bitcoin theft. This is the first formal government attribution of a specific TraderTraitor incident to a named currency theft.
FBI Press Release2025-02-21
Bybit cold wallet transfer intercepted after TraderTraitor actors compromise a Safe{Wallet} developer machine and inject malicious JavaScript into the Safe{Wallet} AWS S3-hosted frontend. Approximately 400,000 ETH (~$1.5 billion) stolen — the largest cryptocurrency theft in history.
CNBC / IC32025-02-26
FBI issues IC3 PSA I-022625-PSA formally attributing the Bybit theft to North Korea's TraderTraitor, listing 51 Ethereum wallet addresses and urging industry to block related transactions.
FBI / IC32025-04-01
Lazarus Group adopts ClickFix social engineering technique to deliver GolangGhost malware to cryptocurrency job seekers, as documented by security researchers. The campaign targets both Windows and macOS users via fake video interview platforms.
The Hacker News2025-12-18
Chainalysis publishes 2025 crypto crime report, attributing $2.02 billion in cryptocurrency theft to North Korean actors — a record high — accounting for approximately 60% of all global crypto theft in 2025. Cumulative DPRK-attributed theft reaches approximately $6.75 billion since 2017.
CoinDesk / Chainalysis2026-03-09
Google Threat Intelligence Group (formerly Mandiant) publishes report on UNC4899's breach of an unnamed cryptocurrency firm after a developer AirDropped a trojanized archive to a corporate device. Attackers used living-off-the-cloud techniques to steal several million dollars via Kubernetes and Cloud SQL tampering.
The Hacker News2026-04-18
KelpDAO exploited for approximately $292 million. TRM Labs attributes the attack to TraderTraitor based on pre-funding analysis traceable to known TraderTraitor laundering networks. Approximately $175 million converted to Bitcoin via THORChain.
TRM Labs2026-04-30
TRM Labs reports that North Korean hackers — including TraderTraitor — account for 76% of all crypto hack losses in the first four months of 2026, with $577 million stolen across two major attacks (KelpDAO and Drift Protocol).
TRM Labs / The BlockDecision Log
- hash: 5yU58t7VvPS6QHGAZ8Say3REydWqv1STx9GwmS1fFcjs
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 6/3/2026, 12:08:07 AM
last updated: 6/3/2026, 12:08:12 AM
avoid.net — verified advice for a post-truth world