FBI blames North Korea’s Lazarus Group for $40M Stake hack

While it’s unclear how they made the determination, the FBI has concluded the Lazarus Group is responsible for the Stake hack

article-image

Dzelat/Shutterstock modified by Blockworks

share

The Federal Bureau of Investigation announced their finding in a press release on Wednesday that the notorious North Korean-funded Lazarus Group is responsible for the $41 million exploit of gambling platform Stake.com. It is unclear how the FBI made this determination. 

The announcement included a list of associated blockchain addresses. The agency wrote that “private sector entities are encouraged to review the previously released Cyber Security Advisory on TraderTraitor and examine the blockchain data associated with the above-referenced virtual currency addresses and be vigilant in guarding against transactions directly with, or derived from, those addresses.”

Stake was exploited for over $40 million across three different blockchains on Sept. 4. Hackers swapped various assets, spread them between addresses, and eventually sent large sums to the Avalanche blockchain via bridges, before converting synthetic BTC on Avalanche to native BTC – a conversion process that can potentially anonymize the transactions and make them more difficult to trace. 

The Stake team has been notably quiet about the incident. There has been a lone Tweet from the official Stake account in which the team stated that “user funds are safe.” The company’s CEO, Ed “Eddie” Craven, joined a popular Twitch streamer earlier today to suggest that the streamer travel to North Korea to negotiate a return of funds. 

Loading Tweet..

It is not immediately apparent how the FBI came to the conclusion that Lazarus was the entity behind the attack. While Lazarus is known to use mixers, it is not uncommon for other hackers to deploy the same tools in order to cover their tracks. 

A Stake representative did not respond to a request for comment by press time. 

Various government entities have been staking claim to greater on-chain analytical sophistication in recent months. In July, representatives for the SDNY bragged in a press release about tracking assets across various blockchains, saying “none of those actions covered the defendant’s tracks or fooled law enforcement, and they certainly didn’t stop my Office or our law enforcement partners from following the money.”


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Old Billingsgate

Mon - Wed, October 13 - 15, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Research Report Templates (20).png

Research

The dynamic between Ethena, Pendle and Aave exhibits a mutually-beneficial relationship, where the offerings of each business grows the top lines of every party in this exchange. Pendle sits at the intersection of YBA issuers (Ethena) and money markets (Aave), demonstrating heightened utilization rates of YBAs, where the PTs then exhibit profound utilization as collateral. YBA issuers see Pendle as a premier go-to-market venue, often underwriting incentives for liquidity on the market and solving for Pendle’s supply side, while money markets view PTs as attractive collateral types to lend against, solving for Pendle’s demand side. PTs represent a highly profitable collateral listing for Aave, with depositors maxing out the available borrow capacity. Pendle’s recent launch of Boros may now present the most material growth vector beyond what is currently exhibited on V2 markets, offering the ability to price yield, spreads, and duration risk across various points in time out into the future.

article-image

Ether-focused BitMine Immersion saw its daily trading volumes surge this week

article-image

From Ronin’s classic L2 pivot to Taiko’s based rollup and Puffer’s ultra-low-latency appchain testnet, Ethereum-aligned architectures are multiplying

article-image

The Gemini Wallet and Onchain hub are great for total beginners, but have a lot of room to grow

article-image

Airlines defend their rewards moat, Binance courts favor over breakfast, DAT fees pile up and systematic thinking

article-image

ETF flows slow, REV stagnates, Pump strikes back and Drift punches up