Atomic Wallet Hack
What happened
On June 3, 2023, attackers drained cryptocurrency from a subset of Atomic Wallet users across multiple chains after obtaining access to affected wallet credentials or keys. The FBI later attributed approximately $100 million in theft to DPRK TraderTraitor-affiliated actors. Atomic Wallet did not publish a confirmed technical root cause: it identified several possible vectors, including local-device malware and infrastructure or code compromise, but said none had been verified.
The incident was a wallet/key-compromise event, not a smart-contract exploit.
Case & protocol details
How it happened
Affected wallets were emptied through unauthorized transactions signed with credentials that attackers had obtained. Atomic Wallet is non-custodial and says encrypted private keys remain on users' devices, but the public investigation did not establish how the attacker accessed the affected keys or seed phrases. Consequently, the incident should not be mapped to a particular contract vulnerability or technical attack class.
Funds Recovery
Recovered
$1.2M
Net Loss
$98,800,000
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report twitter.com
- analysis Website reference coindesk.com
- analysis Website reference twitter.com
- analysis Website reference twitter.com
- analysis June 3rd Event Statement atomicwallet.io
- analysis FBI Identifies Cryptocurrency Funds Stolen by DPRK fbi.gov
- analysis DPRK-related cryptocurrency thefts and laundering analysis chainalysis.com
- analysis North Korea's Lazarus Group likely responsible for Atomic crypto theft elliptic.co
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.