FBI blames North Korea’s Lazarus Group for $40M Stake hack

While it’s unclear how they made the determination, the FBI has concluded the Lazarus Group is responsible for the Stake hack

article-image

Dzelat/Shutterstock modified by Blockworks

share

The Federal Bureau of Investigation announced their finding in a press release on Wednesday that the notorious North Korean-funded Lazarus Group is responsible for the $41 million exploit of gambling platform Stake.com. It is unclear how the FBI made this determination. 

The announcement included a list of associated blockchain addresses. The agency wrote that “private sector entities are encouraged to review the previously released Cyber Security Advisory on TraderTraitor and examine the blockchain data associated with the above-referenced virtual currency addresses and be vigilant in guarding against transactions directly with, or derived from, those addresses.”

Stake was exploited for over $40 million across three different blockchains on Sept. 4. Hackers swapped various assets, spread them between addresses, and eventually sent large sums to the Avalanche blockchain via bridges, before converting synthetic BTC on Avalanche to native BTC – a conversion process that can potentially anonymize the transactions and make them more difficult to trace. 

The Stake team has been notably quiet about the incident. There has been a lone Tweet from the official Stake account in which the team stated that “user funds are safe.” The company’s CEO, Ed “Eddie” Craven, joined a popular Twitch streamer earlier today to suggest that the streamer travel to North Korea to negotiate a return of funds. 

Loading Tweet..

It is not immediately apparent how the FBI came to the conclusion that Lazarus was the entity behind the attack. While Lazarus is known to use mixers, it is not uncommon for other hackers to deploy the same tools in order to cover their tracks. 

A Stake representative did not respond to a request for comment by press time. 

Various government entities have been staking claim to greater on-chain analytical sophistication in recent months. In July, representatives for the SDNY bragged in a press release about tracking assets across various blockchains, saying “none of those actions covered the defendant’s tracks or fooled law enforcement, and they certainly didn’t stop my Office or our law enforcement partners from following the money.”


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Old Billingsgate

Mon - Wed, October 13 - 15, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Research Report Templates.png

Research

Pipe Network is a decentralized content delivery network (dCDN) that replaces the sparse, capital intensive data center footprint of traditional CDNs with a permissionless mesh of independent node operators. By orchestrating under-utilized resources that already exist at the edge, rather than purchasing or leasing thousands of servers, Pipe slashes capital intensity while letting supply expand autonomously in the places where bandwidth is scarcest and most expensive.

article-image

The new SVM chain Zink uses zk tech and promises universal account profiles

article-image

DATs contributed to the increase in funding in July, which topped levels not seen since 2021

article-image

An SEC commissioner walks into a cypherpunk meetup…

article-image

Maple’s syrupUSDC will let traders earn passive income while using it to back perp positions on Solana

article-image

The platform’s bitcoin treasury gives it “competitive positioning” in spot and derivatives markets, VanEck portfolio manager says

article-image

Founder Michael Egorov reflects on the mystery, CRV’s role in DeFi, and what’s next