Atomic Wallet hack
More than $100M was drained from users of the non-custodial Atomic Wallet beginning June 3, 2023, affecting 5,000+ wallets. Elliptic attributed the theft to North Korea's Lazarus Group based on laundering patterns; the root cause was never fully disclosed.
Also known as: Atomic Wallet
Summary
Atomic Wallet is a non-custodial (self-custody) crypto wallet. Beginning around June 3, 2023, more than $100 million in assets was drained from users' wallets; Elliptic said it was tracking over 5,000 compromised addresses. The company said fewer than 1% of users were affected. [1][2]
Attribution and cause
Blockchain-analytics firm Elliptic attributed the theft "with a high level of confidence" to North Korea's Lazarus Group, citing laundering steps (including use of the Sinbad mixer and Garantex) that matched prior Lazarus thefts. Atomic Wallet did not publicly disclose a definitive root cause; analysts speculated about a possible flaw exposing private keys or a supply-chain/malware compromise. [1][2]
Bracketed numbers refer to the numbered sources listed below.
Sources (2)
See also
AmanKesar11 Frozen Bitcoin CaseOtherIn June 2026, blockchain investigator reports highlighted a case involving approximately 5.73 BTC (worth roughly $475,000 at the time of freezing) that had been frozen by cryptocurrency exchange Changelly in March 2025. The individual associated with the funds, using the online alias AmanKesar11, reportedly contacted investigators seeking assistance in recovering the frozen assets. During discussions, multiple and conflicting explanations were provided regarding the origin of the funds.
Gala Games exploitTokensOn May 20, 2024 an attacker abused a privileged minter account on the GALA token contract to mint 5 billion GALA (≈$200M+ nominal) and dumped ~600M of them for ~$22M of ETH before Gala froze the address. Gala Games called it an internal access-control failure; the attacker later returned the ~$22M.
This page was last updated on Jun 15, 2026. View revision history.
