Original Article Text

Click to Toggle View

CoinStats says North Korean hackers breached 1,590 crypto wallets. CoinStats suffered a massive security breach that compromised 1,590 cryptocurrency wallets, with the attack suspected to have been carried out by North Korean threat actors. CoinStats is a comprehensive cryptocurrency portfolio management app with 1,500,000 users. It is used for investment tracking, real-time data, news aggregation, and custom alerts. It also allows users to create CoinStats wallets, which are hosted by the platform. For users who want to use the portfolio management features, the platform requires read-only access to connected external crypto wallets and were not affected by the breach. However, those users who hosted their wallets on CoinStats were potentially impacted by the hack. In an announcement on X yesterday, CoinStats told users they suffered a cyberattack that affected 1,590, or 1.3%, of all hosted wallets on the platform. The company shared a list of impacted wallets on this spreadsheet, but some users reported that funds were stolen from wallets that were not on this list. Therefore, the actual scope of the incident might be more significant than what CoinStats has verified. Those who find their wallet address on the list and still contain funds are urged to transfer them immediately to an external wallet. While the hack is underway, the CoinStats website and the app remain unavailable as the company investigates and mitigates the attack. The attack did not impact users' connected wallets and centralized exchanges, so it's safe for people to continue using those. Although the investigation is ongoing, CoinStats' CEO stated on X that they hold significant evidence suggesting that North Korean hackers carried out the attack, sharing a CISA document about the North Korean Lazarus hacking group. The Lazarus Group is believed to be a state-sponsored hacking group notorious for carrying out massive crypto heists over the years, targeting cryptocurrency platforms. In late 2023, Recorded Future estimated that North Korean state-backed hackers had stolen $3 billion worth of crypto since January 2017, which equates to roughly $500,000,000/year. Scammers are already attempting to take advantage of the CoinStats breach by promoting fake refund programs in responses under the official announcement on X, using unverified accounts with typosquatting handles, such as '@CoinStals'. The scammers attempt to trick users into visiting a cloned site that requests them to connect their wallets to receive a refund, which is then drained of all assets. At the time of writing this, the official CoinStats platform has not announced a refund program, so all related claims should be seen as scams and ignored.

Daily Brief Summary

NATION STATE ACTIVITY // North Korean Hackers Suspected in CoinStats Wallet Breach

CoinStats, a cryptocurrency portfolio management app, reported a security breach affecting 1,590 of its hosted wallets, which is about 1.3% of all such wallets on their platform.

The breach, suspected to be executed by North Korean hackers, potentially linked to the notorious Lazarus Group, did not affect the externally connected wallets or centralized exchanges.

Users whose wallets were hosted directly on CoinStats and appeared on the compromised list were advised to immediately transfer remaining funds to external wallets.

Despite sharing a list of compromised wallets, there are reports from users indicating unauthorized withdrawals from wallets not included in the initial list, hinting at a possibly larger impact.

Scammers are exploiting the situation by promoting fake refund programs through social media, aiming to deceive users into giving away access to their cryptocurrencies.

CoinStats has currently shut down its website and app as it continues to investigate and address the security breach.