OAK — OnChain Attack Knowledge

Worked example · 2019-03

DragonEx exchange compromise — multi-asset cross-chain — 2019-03-24

Loss
approximately $7M USD at-the-time across multiple chains and assets — per DragonEx's contemporaneous public statements and subsequent industry-forensic analysis (Chainalysis, Recorded Future, Group-IB), the principal stolen assets spanned BTC (~135 BTC), ETH (~3,150 ETH), USDT (~205,000 USDT, on Omni-layer at-the-time), EOS (~115,000 EOS), and LTC (~444 LTC), with smaller balances across XRP, BCH, ETC, and adjacent supported assets. The cross-chain distribution of the loss is the case's structurally distinctive feature and is the load-bearing fact on which the subsequent attribution analysis rests.
Recovery
none directly attributable. DragonEx engaged Singapore Police Force, Hong Kong cyber-crime authorities, Thai law enforcement, and other jurisdictional law-enforcement contacts on incident response; subsequent industry-forensic tracing (Chainalysis, Recorded Future) reached the canonical 2018–2019 Lazarus-cluster laundering rails. No on-chain recovery of the stolen assets is publicly documented at the OAK v0.1 cutoff. Operational disposition: DragonEx subsequently shut down exchange operations; the operating entity exited the exchange business across 2019–2020 with limited public disclosure on customer-asset disposition. OAK Techniques observed: OAK-T11 broadly construed (custody-side compromise — operator-side hot-wallet key compromise) producing authorised cross-chain withdrawals across BTC, ETH, USDT, EOS, LTC, and adjacent inventories. OAK-T15.001 (Social Engineering of Operator Personnel) — the pre-LinkedIn-canonical-pattern WFC Proof "fake-trading-bot" pretext is the canonical pre-2020 anchor for the TraderTraitor social-engineering vector. OAK-T15.003 (Operator-Endpoint Compromise) — DragonEx employee endpoints compromised by the WFC Proof installer payload, then leveraged for hot-wallet key extraction. The proximate entry vector per industry-forensic analysis (notably the Chainalysis and Recorded Future post-event reporting and the broader 2019-era TraderTraitor-cluster pattern) was a spear-phishing-led social-engineering compromise of DragonEx employees using a fake cryptocurrency-trading-bot service ("WFC Proof") that DragonEx employees were socially-engineered to install — the canonical TraderTraitor entry-vector pattern that subsequently became widely-documented across 2020–2025 Lazarus-cluster operations. Attribution: inferred-strong — Chainalysis, Recorded Future, and Group-IB industry-forensic analysis attributed the case to the OAK-G01 / Lazarus / TraderTraitor cluster on the basis of (1) the spear-phishing entry-vector pattern matching the TraderTraitor playbook, (2) the cross-chain laundering rail matching the canonical 2018–2019 Lazarus-cluster laundering surface, and (3) on-chain wallet-cluster overlap with adjacent G01-attributed events. The CISA AA22-108A joint advisory on the TraderTraitor cluster (2022-04) cross-references the broader 2018–2019 Lazarus cryptocurrency-targeting wave that includes DragonEx 2019. No DOJ indictment names the DragonEx 2019 case specifically at the OAK v0.1 cutoff; the attribution rests on the industry-forensic record plus the cohort-level CISA / FBI / Treasury advisories on the TraderTraitor cluster.
Attribution
pseudonymous — no public actor attribution at OAK v0.1 cutoff.
OAK-Gnn
OAK-G01 Lazarus Group / DPRK-attributed.
Key teaching point
DragonEx 2019 is the canonical OAK-record illustration of the spear-phishing-via-fake-trading-bot TraderTraitor entry-vector pattern at the 2019-era loss magnitude, and is the cleanest available 2019-era reference for the cross-chain-extraction-shape variation within the broader T11 family. The case is structurally significant because it bridges the 2017–2018 OAK-G01 cohort (NiceHash, Coincheck, Coinrail, Bithumb 2018-06) — characterised by spear-phishing-led malware delivery against operator endpoints and concentrated single-asset or East-Asian-exchange extractions — to the 2020–2025 OAK-G01 / TraderTraitor cohort (Atomic Wallet 2023, Bitcoin.DMM.com 2024, WazirX 2024, Bybit 2025) — characterised by social-engineering-via-fake-recruiter-or-trading-tool entry vectors and multi-chain extractions against globally-distributed targets. DragonEx is the 2019-era anchor for that bridge.

Summary

DragonEx was a Singapore-headquartered cryptocurrency exchange operating since approximately 2017–2018, with exchange operations distributed across Singapore, Hong Kong, and adjacent regional jurisdictions. The exchange was operationally distinctive within the 2018–2019 surface for its multi-chain support — at peak, DragonEx supported trading and custody across BTC, ETH, USDT (Omni-layer at-the-time), EOS, LTC, XRP, BCH, ETC, and a long-tail of adjacent assets — and for an operator-side employee surface that included engineering and operations staff who were targets of social-engineering activity by external actors in the run-up to the March 2019 compromise.

On 2019-03-24 (UTC; the proximate-extraction event timing is consistent with end-of-business-day operational windows in the Singapore / Hong Kong jurisdictional surface), DragonEx's hot-wallet infrastructure suffered a multi-chain unauthorised drain across BTC, ETH, USDT, EOS, LTC, and adjacent inventories. DragonEx detected the activity rapidly (the public-disclosure timeline indicates same-day-or-next-day detection) and announced the breach publicly on 2019-03-26 / 2019-03-27, suspending all deposit-and-withdrawal operations and engaging Singapore Police Force and adjacent regional law-enforcement contacts on incident response.

The proximate entry vector per industry-forensic analysis was a spear-phishing-led social-engineering compromise of DragonEx employees using a fake cryptocurrency-trading-bot service. Per the Recorded Future and adjacent industry-forensic reporting in the months and years following the event, the actor cluster (subsequently identified by CISA / FBI as the TraderTraitor sub-cluster of the broader OAK-G01 / Lazarus tradecraft surface) created a fake trading-bot brand, "WFC Proof," with corresponding website, social-media presence, and a Telegram outreach campaign targeting DragonEx employees. DragonEx employees were socially-engineered to install the malicious trading-bot software on their workstations; once installed, the malicious payload reached operational credentials and lateral-movement capability into DragonEx's wallet-management infrastructure, producing the multi-chain authorised-from-the-signing-host extraction that drained the cross-chain hot-wallet inventories.

For OAK's purposes the DragonEx 2019 case is the canonical reference for two structurally distinctive features. First, it is the 2019-era anchor for the spear-phishing-via-fake-trading-bot TraderTraitor entry-vector pattern that subsequently became the load-bearing entry vector across the 2020–2025 OAK-G01 / TraderTraitor cohort (Axie Infinity / Ronin 2022 used a fake-recruiter-LinkedIn-PDF variant; Atomic Wallet 2023 and adjacent operations used variants; Bybit 2025 used a fake-cloud-developer-tool variant against Safe{Wallet} engineers). Second, it is the cleanest available 2019-era reference for the cross-chain extraction-shape variation within the broader T11 family — an exchange compromise where the load-bearing loss is distributed across multiple chains rather than concentrated in a single chain or in a single chain's ERC-20 token portfolio.

Timeline (UTC unless noted)

When Event OAK ref
Pre-event (2018-Q4 to 2019-Q1) Actor cluster (subsequently identified by CISA / FBI as the TraderTraitor sub-cluster of OAK-G01 / Lazarus) creates the "WFC Proof" fake trading-bot brand: corresponding website, social-media presence, Telegram outreach campaign. Targets DragonEx employees with social-engineering outreach pitching the trading-bot service. TraderTraitor entry-vector setup — fake trading-bot social-engineering
2019-Q1 (estimated) DragonEx employees socially-engineered to install the malicious "WFC Proof" trading-bot software on their workstations. Malicious payload reaches operational credentials and lateral-movement capability into DragonEx's wallet-management infrastructure. T11 entry — endpoint compromise via fake trading-bot
2019-03-24 (UTC) Attacker reaches DragonEx wallet-management infrastructure; issues authorised cross-chain withdrawals across BTC (~135 BTC), ETH (~3,150 ETH), USDT (~205,000 USDT on Omni-layer), EOS (~115,000 EOS), LTC (~444 LTC), and adjacent inventories. Aggregate at-time loss ~$7M USD. T11 extraction — multi-chain cross-asset drain
2019-03-25 (UTC) DragonEx detects the activity; suspends deposit-and-withdrawal operations. (operator detection — same-day-or-next-day)
2019-03-26 / 2019-03-27 (UTC) DragonEx publicly discloses the breach. Engages Singapore Police Force, Hong Kong cyber-crime authorities, Thai law enforcement, and other regional law-enforcement contacts on incident response. Operator disclosure
2019-Q2 onward Stolen BTC, ETH, USDT, EOS, LTC laundered through chain-hopping, cross-chain bridges, and the canonical 2018–2019 Lazarus-cluster laundering rails. Industry-forensic tracing (Chainalysis, Recorded Future, Group-IB) reaches the actor-cluster wallets. T7-class long-tail laundering across multiple chains
2019-Q3 to 2019-Q4 DragonEx operational scale-down begins; the operating entity exits the exchange business across 2019–2020 with limited public disclosure on customer-asset disposition. Operational shutdown
2020 onward DragonEx exchange operations effectively cease. Industry-forensic and intelligence-community attribution analysis continues to develop the TraderTraitor-cluster surface across 2020–2022. (post-shutdown attribution development)
2022-04 CISA / FBI / Treasury joint advisory AA22-108A introduces the TraderTraitor cluster as a confirmed-attribution OAK-G01 sub-cluster; the advisory cross-references the broader 2018–2019 Lazarus cryptocurrency-targeting wave that includes DragonEx 2019 as a cohort member. CISA / FBI / Treasury cohort attribution — TraderTraitor cluster confirmed
2022 onward Industry-forensic analysis (Chainalysis, Recorded Future, Group-IB) continues to develop the TraderTraitor entry-vector documentation; the DragonEx 2019 spear-phishing-via-fake-trading-bot pattern is referenced as a 2019-era anchor for the cluster's entry-vector tradecraft. Cohort attribution — inferred-strong with TraderTraitor cluster cross-reference

What defenders observed and learned

  • Pre-event: the load-bearing failure was that DragonEx employees' workstations held credentials and operational reach into the wallet-management infrastructure, and that the social-engineering-via-fake-trading-bot vector was sufficient to compromise those endpoints at scale. The defender lesson is that operator-and-engineer endpoint hardening against social-engineering-installed malicious payloads is a primary control surface; the post-2020 industry baseline of (1) endpoint detection-and-response (EDR) tooling on every operator workstation, (2) signed-and-vetted-software-only allowlisting on operator endpoints, (3) hardware-token-mediated signing access rather than software-credential-based signing access, and (4) just-in-time / break-glass elevation rather than persistent operator access to wallet-management infrastructure is retro-engineered against precisely this entry-vector class.
  • Pre-event (TraderTraitor pattern): the spear-phishing-via-fake-trading-bot variant the DragonEx attackers used in 2019 is the canonical 2019-era reference for the TraderTraitor entry-vector pattern that subsequently became the load-bearing entry vector across the 2020–2025 OAK-G01 / TraderTraitor cohort. The defender lesson is that the TraderTraitor cluster's entry-vector tradecraft is generalist social-engineering-via-fake-tool-or-fake-recruiter applied to the cryptocurrency-engineering target surface, and that defenders should treat the entire surface of (1) cryptocurrency-trading-bot software, (2) cryptocurrency-engineering recruiting outreach, (3) cryptocurrency-developer-tool software, and (4) cryptocurrency-trading-API integration software as elevated-trust-attack-surface targets that warrant explicit hardening against social-engineering-installed malicious payloads.
  • At-event (cross-chain extraction): the multi-chain cross-asset shape of the extraction is the case's structurally distinctive feature on the T11-axis surface. Most exchange-hack worked examples in the OAK corpus document compromises concentrated in a single asset (Mt. Gox: BTC; Bitfinex: BTC; NiceHash: BTC; Coincheck: NEM / XEM) or in a single-chain ERC-20 token portfolio (Coinrail 2018). DragonEx 2019 documents an exchange compromise where the load-bearing loss is distributed across multiple chains. The defender-side implication is that signing-authority segregation across chains is itself a control surface; an exchange holding multi-chain hot-wallet inventory under a single signing-authority surface produces a multi-chain drain when that authority is compromised, with the additional operational complications of multi-chain laundering rails being available to the attacker downstream.
  • Post-event (recovery — none directly attributable): no on-chain recovery of the stolen assets is publicly documented at the OAK v0.1 cutoff. The case is one of the cleaner illustrations available on the OAK record of the zero-recovery shape — an exchange compromise where the stolen assets are laundered to ground via the canonical 2018–2019 Lazarus-cluster laundering rails and where the operational shutdown of the compromised exchange across 2019–2020 produced no continuing-operator capacity to fund customer restitution.
  • Post-event (attribution): the attribution surface is inferred-strong on the basis of (1) the spear-phishing-via-fake-trading-bot entry-vector pattern matching the TraderTraitor playbook, (2) the cross-chain laundering rail matching the canonical 2018–2019 Lazarus-cluster laundering surface, and (3) on-chain wallet-cluster overlap with adjacent G01-attributed events. The CISA AA22-108A joint advisory on the TraderTraitor cluster (2022-04) cross-references the broader 2018–2019 Lazarus cryptocurrency-targeting wave that includes DragonEx 2019 as a cohort member. No DOJ indictment names the DragonEx 2019 case specifically at the OAK v0.1 cutoff; contributors writing operator-accountability or attribution-axis material should preserve the inferred-strong notation rather than over-claiming a confirmed attribution that the public record does not support.

What this example tells contributors writing future Technique pages

  • DragonEx 2019 is the 2019-era anchor for the TraderTraitor entry-vector pattern. The spear-phishing-via-fake-trading-bot variant ("WFC Proof") subsequently became the load-bearing entry vector across the 2020–2025 OAK-G01 / TraderTraitor cohort — Ronin Bridge 2022 (fake-recruiter LinkedIn PDF variant), Atomic Wallet 2023, Bitcoin.DMM.com 2024, WazirX 2024, Bybit 2025 (fake-cloud-developer-tool variant against Safe{Wallet} engineers). Contributors writing T11-class Technique pages, the OAK-G01 / TraderTraitor sub-cluster page, or future TraderTraitor-attributed worked examples should treat DragonEx 2019 as the 2019-era anchor for the entry-vector pattern's lineage, with the 2020–2025 cohort cases as the iterative descendants.
  • Cross-chain extraction-shape variation deserves explicit M-axis treatment. The case demonstrates that hot-wallet inventory composition matters for the operational shape of an extraction event: an exchange holding multi-chain hot-wallet inventory under a single signing-authority surface produces a multi-chain drain when that authority is compromised. Contributors writing M-axis pages should treat signing-authority segregation across chains as a distinct mitigation class, with DragonEx 2019 as one of the canonical cross-chain references alongside the post-2020 cross-chain compromises (Stake.com 2023, CoinEx 2023, DMM Bitcoin 2024).
  • The exchange-shutdown-without-customer-restitution shape deserves explicit recovery-mechanism treatment. The case is one of the cleaner illustrations available on the OAK record of the zero-recovery + operational-shutdown shape — an exchange compromise where the stolen assets are laundered to ground and where the operational shutdown of the compromised exchange produces no continuing-operator capacity to fund customer restitution. Contributors writing future exchange-hack worked examples in which the recovery shape is degenerate (zero on-chain recovery + operational shutdown of the compromised entity + no external-investor absorption) should reference DragonEx 2019 as the canonical 2019-era illustration, alongside Cryptopia 2019 (insolvency proceeding) on adjacent recovery-mechanism axes.
  • inferred-strong is the right attribution-strength marker for DragonEx 2019. The attribution rests on industry-forensic analysis (Chainalysis, Recorded Future, Group-IB) plus cohort-level CISA / FBI / Treasury advisories on the TraderTraitor cluster. Contributors writing the OAK-G01 / TraderTraitor sub-cluster page should preserve this notation rather than over-claiming a confirmed attribution that the public record does not support.

Public references

  • [dragonexpress2019] — DragonEx Pte Ltd. Statement on the March 2019 security incident. 2019-03-26 / 2019-03-27 onward; primary-source operator disclosure across the breach response window.
  • [reutersdragonex2019] — Reuters / regional press. Singapore-based DragonEx exchange hacked, multi-million-dollar cryptocurrency loss. 2019-03; contemporaneous press coverage of the breach disclosure.
  • [chainalysisdragonex2019] — Chainalysis primary forensic walk-through of the DragonEx laundering cluster; cross-references the 2018–2019 Lazarus-cluster laundering surface and the cross-chain laundering pattern observed in the months following the event.
  • [recordedfuturedprkfinancial2019] — Recorded Future. North Korea Targeting of cryptocurrency exchanges and adjacent infrastructure — 2019 update. 2019; industry-forensic attribution covering the cohort that includes DragonEx 2019 and the spear-phishing-via-fake-trading-bot ("WFC Proof") entry-vector pattern.
  • [groupibdragonex2019] — Group-IB. DragonEx incident analysis and Lazarus-cluster attribution. 2019; industry-forensic analysis of the entry-vector pattern and the on-chain laundering rails.
  • [cisatradertraitor2022] — CISA / FBI / Treasury. TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies (Joint Cybersecurity Advisory AA22-108A). 2022-04; primary-source US-government cohort attribution introducing the TraderTraitor cluster as a confirmed-attribution OAK-G01 sub-cluster, with cross-reference to the broader 2018–2019 Lazarus cryptocurrency-targeting wave.
  • [chainalysisdprktradertraitor] — Chainalysis. TraderTraitor and DPRK Cryptocurrency-Theft Operations: Forensic Tracing. Industry-forensic walkthrough of the TraderTraitor cluster's entry-vector tradecraft and on-chain laundering patterns; complements CISA AA22-108A as industry-side anchor.

Discussion

DragonEx 2019 is the OAK record's 2019-era anchor for the TraderTraitor entry-vector pattern and a canonical illustration of the cross-chain extraction-shape variation within the broader T11 family. The case bridges the 2017–2018 OAK-G01 cohort (NiceHash, Coincheck, Coinrail, Bithumb 2018-06) — characterised by spear-phishing-led malware delivery against operator endpoints and concentrated single-asset or East-Asian-exchange extractions — to the 2020–2025 OAK-G01 / TraderTraitor cohort (Atomic Wallet 2023, Bitcoin.DMM.com 2024, WazirX 2024, Bybit 2025) — characterised by social-engineering-via-fake-recruiter-or-trading-tool entry vectors and multi-chain extractions against globally-distributed targets. Contributors writing the OAK-G01 actor page or the TraderTraitor sub-cluster page should treat DragonEx 2019 as the 2019-era anchor for that bridge.

The TraderTraitor entry-vector lineage matters most for OAK's mitigation-axis documentation. The spear-phishing-via-fake-trading-bot variant the DragonEx attackers used in 2019 is generalist social-engineering-via-fake-tool-or-fake-recruiter applied to the cryptocurrency-engineering target surface, and the same generalist pattern recurs across the 2020–2025 cohort with iteratively-refined fake-tool-or-fake-recruiter pretexts. The defender lesson is that the entire surface of (1) cryptocurrency-trading-bot software, (2) cryptocurrency-engineering recruiting outreach, (3) cryptocurrency-developer-tool software, and (4) cryptocurrency-trading-API integration software is elevated-trust-attack-surface that warrants explicit hardening against social-engineering-installed malicious payloads. Contributors writing M-axis pages on operator-and-engineer endpoint hardening should treat the TraderTraitor lineage from DragonEx 2019 through Bybit 2025 as the load-bearing historical-record evidence for why that hardening surface is the load-bearing control class for OAK-G01-attributed entry-vector compromises.

The cross-chain extraction-shape distinction is the case's structurally distinctive feature on the T11-axis surface and is worth preserving as an explicit Technique-page cross-reference. Contributors writing T11 sub-technique pages or the broader T11 family page should treat DragonEx 2019 as one of the canonical references for the cross-chain-extraction-shape variation within the family, alongside the post-2020 cross-chain compromises (Stake.com 2023, CoinEx 2023, DMM Bitcoin 2024) that demonstrate the same shape at later loss magnitudes.

Finally, the zero-recovery + operational-shutdown shape is the case's distinctive feature on the recovery-mechanism axis. DragonEx is one of the cleaner illustrations available on the OAK record of an exchange compromise where the stolen assets are laundered to ground via the canonical 2018–2019 Lazarus-cluster laundering rails and where the operational shutdown of the compromised exchange across 2019–2020 produced no continuing-operator capacity to fund customer restitution. Contributors writing future exchange-hack worked examples in which the recovery shape is degenerate should reference DragonEx 2019 as the canonical 2019-era illustration; the OAK record's value depends on accurate recovery-mechanism notation, and DragonEx 2019 is one of the cleanest available cases for the zero-recovery + operational-shutdown end of the recovery-mechanism spectrum within the broader 2018–2019 East-Asian and South-East-Asian exchange-compromise surface.

Techniques demonstrated (3)