Atomic Wallet Hack

REPORTED LOSS $100.0M
Critical Unauthorized transfers using compromised wallet credentials or keys avalanche bitcoin bsc ethereum polkadot tron

What happened

On June 3, 2023, attackers drained cryptocurrency from a subset of Atomic Wallet users across multiple chains after obtaining access to affected wallet credentials or keys. The FBI later attributed approximately $100 million in theft to DPRK TraderTraitor-affiliated actors. Atomic Wallet did not publish a confirmed technical root cause: it identified several possible vectors, including local-device malware and infrastructure or code compromise, but said none had been verified.

The incident was a wallet/key-compromise event, not a smart-contract exploit.

Case & protocol details

Classification Operational wallet compromise; root cause publicly unconfirmed
Protocol Type Wallets
Official Website atomicwallet.io/
Protocol Twitter/X @AtomicWallet

How it happened

Affected wallets were emptied through unauthorized transactions signed with credentials that attackers had obtained. Atomic Wallet is non-custodial and says encrypted private keys remain on users' devices, but the public investigation did not establish how the attacker accessed the affected keys or seed phrases. Consequently, the incident should not be mapped to a particular contract vulnerability or technical attack class.

Funds Recovery

1.2%

Recovered

$1.2M

Net Loss

$98,800,000

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.