13 Jan 2025

Investigating the CoinsPaid Hack!

Investigating the CoinsPaid Hack!

The audacious breach of crypto payment giant CoinsPaid appears to bear the hallmark of Lazarus – the elusive North Korean faction known for navigating the Web3 waters in pursuit of Kim Jong-un’s military endeavors. Shockingly, they allegedly siphoned off $37 million from CoinsPaid on July 22.

On this page

While some might be tempted to view North Koreans as somewhat naive or undereducated, it's impossible to dismiss the cunning and expertise of the Lazarus group. This crew was breaking into digital fortresses long before the buzz of cryptocurrencies echoed through the mainstream corridors of the multi-billion-dollar tech world.

The allure of crypto brought a renewed sense of purpose to their digital escapades. Given the extensive sanctions against North Korea, turning to cyber heists for easy-to-convert currency was more than just profitable—it became a lifeline. Their not-so-enviable resume boasts major infiltrations like those of Axie Infinity, valued at $625 million, Horizon Bridge at $100 million, and the breach of Atomic Wallet, also at $100 million.

After suffering their own cyber debacle, the CoinsPaid team was swift to dive into the breach's anatomy. It became clear that Lazarus' playbook hadn't deviated much since the Atomic Wallet incident. This raises a dual-edged revelation: firstly, the digital realm is yet to craft an effective defense against these virtual buccaneers. Yet, it's unfair to dub CoinsPaid as an easy target. The hackers had been weaving their intricate web for 6 months, tirelessly hunting for a chink in the armor. Their arsenal? A cocktail of DDos attacks, BruteForce techniques, relentless spam, crafty phishing schemes, and even audacious plans to covertly rope in the platform's key experts.

But their ultimate weapon? Crafty social engineering. A few weeks before the breach, on a particularly ominous July 7, 2023, CoinsPaid's defenses were blitzed. The digital onslaught was staggering, mobilizing over 150,000 unique IP addresses. The objective was sinisterly simple: trick a pivotal staffer into downloading a rogue application. Once executed, the hackers seized remote control of his workstation, granting them a backstage pass to CoinsPaid's digital sanctum.

To get a sense of the breadth and depth of Lazarus' operations, consider this: in the same month, they pulled off a heist on the JumpCloud platform—a hub that facilitates authentication processes for corporations. With this ace up their sleeve, the group had the leverage to make some unexpected, and undoubtedly crafty, moves on CoinsPaid.

Just before the breach, several CoinsPaid staff, while using what they believed to be the safe realm of LinkedIn, started getting enticing job proposals from cryptocurrency company recruiters. These pitches dangled the carrot of high salaries, anywhere between $16,000 to $24,000 a month. The catch? During the preliminary stages of their interview process, these individuals were prompted to download and install the JumpCloud Agent software for a test assignment. One employee took the bait, thinking it was a genuine offer from the Crypto Com exchange. Importantly, CoinsPaid doesn't place blame on their employee, acknowledging that the attackers showcased a high level of expertise and precision.

After securing access to CoinsPaid's systems, these adversaries set up a backdoor, draining the company's operational funds storage. And the fallout from that action was considerable.

To counteract this violation, CoinsPaid collaborated with Match Systems, a cybersecurity powerhouse that boasts a track record of recovering more than $70 million in assets. In a bid to trace and potentially freeze the absconded funds, the hackers' addresses were put on a comprehensive blockchain analyzer blacklist. Additionally, top crypto exchanges and AML service personnel received immediate alerts about these specific identifiers. It was this exact strategy that spotlighted Lazarus's involvement when an address linked to the Atomic Wallet's breach was identified.

CoinsPaid views this incident as a valuable lesson and is determined to seek resolution. It's unlikely that the bold North Korean crypto culprits will voluntarily return the stolen funds. Hence, the response will have to be as cunning and calculated as the hack itself.

For those keeping tabs, GNcrypto has previously had an in-depth conversation with CoinsPaid's CEO, Max Krupyshev.

The content on The Coinomist is for informational purposes only and should not be interpreted as financial advice. While we strive to provide accurate and up-to-date information, we do not guarantee the accuracy, completeness, or reliability of any content. Neither we accept liability for any errors or omissions in the information provided or for any financial losses incurred as a result of relying on this information. Actions based on this content are at your own risk. Always do your own research and consult a professional. See our Terms, Privacy Policy, and Disclaimers for more details.

Articles by this author

Latest News

MORE
The Future of Crypto in 2025: Fidelity’s Predictions

The Future of Crypto in 2025: Fidelity’s Predictions

What’s next for the biggest cryptocurrencies in 2025? Fidelity Digital Assets analyst Chris Kuiper shares insights on how Bitcoin will navigate volatility, Ethereum will address scaling challenges, and stablecoins will adapt to evolving regulations.

13 Jan 2025
The Crypto Rollercoaster of 2024 — Wins and Woes

The Crypto Rollercoaster of 2024 — Wins and Woes

The crypto sector evolved at breakneck speed in 2024. With major wins and notable setbacks, it’s time to reflect on the year’s key developments and their implications for the future.

31 Dec 2024
OpenSea Token: Release Date and How to Qualify for the Airdrop

OpenSea Token: Release Date and How to Qualify for the Airdrop

The NFT marketplace OpenSea, a pioneer in the space for the past seven years, is expected to launch its native token in 2025. A significant portion of the tokens will likely be distributed through a retroactive airdrop—a common way to reward the community for their past activity and support.

30 Dec 2024
5 Most Exciting Token Launches to Watch in 2025

5 Most Exciting Token Launches to Watch in 2025

In 2024, we saw a number of hot airdrops and token launches, from AI-powered projects to the rise of memecoins. Now, as we head into 2025, the crypto space is set to expand even further with an increasing number of cryptocurrencies.

27 Dec 2024

Latest News Alt

MORE
Weekly Analysis of BTC, ETH, and the Stock Market (Jan 6, 2025)

Weekly Analysis of BTC, ETH, and the Stock Market (Jan 6, 2025)

An overview of BTC, ETH, XAUT, and S&P500 charts, along with the current cryptocurrency market dynamics.

06 Jan 2025
Weekly Analysis of BTC, ETH, and the Stock Market (Dec 30, 2024)

Weekly Analysis of BTC, ETH, and the Stock Market (Dec 30, 2024)

An overview of BTC, ETH, XAUT, and S&P500 charts, and the current cryptocurrency market dynamics.

30 Dec 2024
Weekly Analysis of BTC, ETH, and the Stock Market (Dec 23, 2024)

Weekly Analysis of BTC, ETH, and the Stock Market (Dec 23, 2024)

An overview of BTC, ETH, XAUT, and S&P500 charts, and the current cryptocurrency market dynamics.

23 Dec 2024

Might Be Interesting

MORE
Mining Farms Uncovered — How Crypto Is Mined at Scale

Mining Farms Uncovered — How Crypto Is Mined at Scale

As a cornerstone of the crypto industry, mining farms drive blockchain networks. But how do they work? Uncover the mechanics behind these cutting-edge hubs and their role in the crypto landscape.

07 Jan 2025
William Quigley, WAX/Tether: Stablecoins’ Role in Global Payments

William Quigley, WAX/Tether: Stablecoins’ Role in Global Payments

William Quigley, co-founder of WAX and Tether, firmly believes that stablecoins are more than a tool for traders—they’re the key to transforming the global economy. Already central to crypto trading and cross-border payments, their future potential is even more exciting.

04 Jan 2025
Why Blockchain Is Different from Traditional Databases

Why Blockchain Is Different from Traditional Databases

In the world of business and finance, information is everything. Traditional databases have been reliable tools for decades, but blockchain presents a groundbreaking alternative. What sets it apart, and could it lead to a paradigm shift?

03 Jan 2025
How Does Multisig Works and Protect Your Assets?

How Does Multisig Works and Protect Your Assets?

As threats to digital assets evolve, multisig technology provides a highly effective security layer. By requiring multiple signatures for transactions, it significantly reduces risks such as hacking and access loss.

02 Jan 2025
Crypto Price Gaps: Why Platforms Show Different Prices

Crypto Price Gaps: Why Platforms Show Different Prices

The crypto market has nuances you may not have noticed at first glance. For example, when you want to check the Bitcoin price, you probably Google it without thinking to compare the results. But when you monitor the market regularly and engage in trading, you notice the prices aren’t the same on all platforms.

24 Dec 2024
The Czech Republic and Its Crypto-Friendly Policies

The Czech Republic and Its Crypto-Friendly Policies

The Czech Republic is emerging as a crypto-friendly nation, recognizing cryptocurrencies as legitimate payment methods and encouraging their use in business. But its regulatory framework is still taking shape. Here’s how crypto is managed today.

23 Dec 2024

Opinions

8 Commandments for Crypto Exchange Users

8 Commandments for Crypto Exchange Users

While cryptocurrency exchanges offer many security features, they are still vulnerable to hacks, fraud, and other criminal activity. Remember, no online platform can guarantee 100% protection for your funds. Follow these eight key rules to reduce your risks. Rule #1: Don’t Believe in the Myth of Absolute Exchange Security Even the largest and most seemingly […]

12 Jan 2025
10 Key Investment Trends to Watch in 2025: Green Crypto, Regulations, and More

10 Key Investment Trends to Watch in 2025: Green Crypto, Regulations, and More

Donald Trump is back, Germany’s economy is in trouble, while U.S. economic indicators seem to have a robust momentum, and interest rates are sliding downhill. Sounds dramatic? It is. But 2025 isn’t all doom and gloom—it’s full of opportunities for investors who know where to look. Whether you’re a seasoned pro or someone still figuring […]

12 Jan 2025
MORE

Interviews

Dmytro Gordon and Volodymyr Nosov: A Sensational Interview

Dmytro Gordon and Volodymyr Nosov: A Sensational Interview

Volodymyr Nosov, CEO of Europe’s largest crypto exchange WhiteBIT, sat down with Dmytro Gordon, one of Ukraine’s most prominent journalists. The interview touched on Bitcoin, crypto, WhiteBIT, cars, keys to success, and business vision.

18 Dec 2024
WhiteBIT CEO: Standing Strong Against Russian Aggression

WhiteBIT CEO: Standing Strong Against Russian Aggression

In an interview with BTC-ECHO, Volodymyr Nosov, the founder and CEO of WhiteBIT, discussed the impact of Russian aggression on the crypto exchange’s business, how WhiteBIT stays a top competitor in the industry, and when he believes our financial system will be completely transformed.

04 Oct 2024
MORE