TraderTraitor
A North Korea-linked threat cluster (part of the Lazarus umbrella) that the FBI blames for several of the largest exchange thefts, including Bybit ($1.5B), DMM Bitcoin ($305M), and the Ronin/Axie bridge. It favors social-engineering of employees and supply-chain compromises.
Also known as: TraderTraitor, Jade Sleet, UNC4899, Slow Pisces
On attribution: TraderTraitor is a North Korea-linked cluster within the broader Lazarus/RGB umbrella. Attributions are those of the cited authorities (FBI and partner agencies).
Overview
TraderTraitor is the name U.S. agencies use for a North Korea-linked cyber actor (overlapping with the Lazarus umbrella; also tracked by industry as Jade Sleet, UNC4899, and Slow Pisces). It specializes in high-value cryptocurrency theft via targeted social engineering — often impersonating recruiters or business contacts to compromise employees — and via software supply-chain attacks. The name originally referred to a 2022 campaign pushing trojanized crypto trading apps. [1][2]
Tactics
The group frequently contacts employees of crypto firms (developers, operations, finance) with fake job offers, "coding tests," or partnership pitches, then delivers malware or harvests credentials/session tokens. It has also poisoned software dependencies (e.g. npm packages) to reach downstream targets. A recurring hallmark is targeting several employees of the same company at once. [1][2]
Notable incidents
- Bybit (Feb 2025, ~$1.5B) — the largest crypto heist on record; the actor compromised the Safe{Wallet} signing interface so signers approved a malicious transaction. [1]
- DMM Bitcoin (May 2024, ~$305M) — compromised an employee at wallet vendor Ginco via a fake "pre-employment test," then manipulated a legitimate transaction. [2]
- Ronin / Axie Infinity bridge (2022, ~$625M) — the cluster is also linked to this theft, which began with a fake job lure to a Sky Mavis engineer.
Bracketed numbers refer to the numbered sources listed below.
Sources (2)
See also
- Ledger Connect Kit hackWallet drainersA December 2023 software supply-chain attack: a phished former Ledger employee's npm key let attackers publish malicious versions of Ledger's widely used 'Connect Kit' library, injecting the Angel Drainer into many dApps. About $500K–$600K was drained in a few hours before a fix shipped.
- Platypus FinanceProjectsAn Avalanche stablecoin protocol exploited for about $8.5M in February 2023 via a flash loan that abused a flawed solvency check. Two brothers were arrested in France (aided by ZachXBT) but were later acquitted of criminal charges by a French court.
- Angel DrainerWallet drainers
This page was last updated on Jun 15, 2026. View revision history.
