OAK — OnChain Attack Knowledge

Worked example · 2023-09

Stake.com hot-wallet theft — multi-chain — 2023-09-04

Loss
approximately $41M across Ethereum, BNB Chain (BSC), and Polygon hot wallets — including ~9,620 ETH on Ethereum mainnet, ~14.24M MATIC on Polygon, ~82,650 BNB on BNB Chain, plus stablecoin balances (Tether USDT).
Recovery
approximately $970K (~15.5 BTC.b) recovered through a U.S. DOJ civil forfeiture action filed in 2024 against laundered proceeds traced through Avalanche's Bitcoin bridge and the Sinbad / Yonmix mixers — ~2.4% recovery rate, three orders of magnitude below the KuCoin (2020) coordinated-recovery benchmark.
Attribution
confirmed — see OAK-Gnn line below for attribution detail.
OAK Techniques observed
no exact OAK v0.1 entry-vector match — the entry vector was operator-internal hot-wallet private-key compromise, not a third-party signing vendor (T11.001), not wallet-software distribution (T11.002), and not in-use multisig manipulation (T11.003). Closest sibling Technique class is the broader T11 custody-and-signing family; the Stake.com case is the second canonical worked example (after KuCoin 2020) of the operator-side internal hot-wallet key compromise gap in the OAK v0.1 taxonomy. Public reporting (TRM Labs) attributes the access vector to social-engineering of Stake employees with access to the platform's internal withdrawal mechanism — which puts the case in the same off-chain-entry-vector class OAK already documents under the worked-example surface, not under an on-chain Technique. Downstream Techniques observed on-chain: OAK-T7.001 (Mixer-Routed Hop — Sinbad and Yonmix on the Bitcoin side), OAK-T7.003 (Cross-Chain Bridge Laundering — Avalanche Bitcoin bridge BTC.b conversion), and OAK-T8.001 (Common-Funder Cluster Reuse) for OAK-G01 attribution.
Actor
OAK-G01 Lazarus Group / DPRK-attributed.
Attribution status
confirmed — the FBI published a public press release on 2023-09-07 explicitly identifying Lazarus Group / APT38 / DPRK cyber actors as responsible for the Stake.com theft and listing 40 attacker-controlled wallet addresses. By OAK convention this is confirmed-grade attribution: it sits at FBI-press-release evidentiary strength, the same tier as the Harmony Horizon (2022) FBI attribution. The FBI release also explicitly grouped Stake.com with the Atomic Wallet (June 2023, ~$100M) and Alphapo / CoinsPaid (July 2023, ~$60M) thefts, framing the four cases as a single OAK-G01 campaign cluster.
Key teaching point
Stake.com is the canonical OAK example of an operator-internal hot-wallet key compromise that was successfully laundered — the structural counterpart to KuCoin (2020). The two cases share the same entry-vector class (operator-side key compromise, no exact OAK v0.1 Technique match) and the same OAK-G01 attribution; they diverge sharply on the laundering rail and recovery outcome. KuCoin's stolen value sat predominantly in ERC-20s with freeze-capable issuers, and the laundering chain ran through DEXes and mixers that the industry was able to block fast enough to recover ~84% of value. Stake.com's stolen value moved out of ERC-20 / exchange-blocking choke-points within hours via the Avalanche BTC.b bridge, then through Bitcoin-native mixers (Sinbad, Yonmix) that sit outside the issuer-freeze surface entirely. The ~2.4% recovery rate is the structural ceiling for cases with that laundering profile, not an operational failure.

Summary

On September 4, 2023, Stake.com — a crypto-native online gambling platform — saw unauthorised outbound transactions from its hot wallets on Ethereum, BNB Chain, and Polygon beginning shortly after 00:00 UTC. The first observable on-chain event was a transfer of approximately $3.9M USDT on Ethereum, followed by a 6,001 ETH (~$9.8M) extraction; sequential transfers on Polygon (~14.24M MATIC) and BNB Chain (~82,650 BNB) brought the cumulative loss to approximately $41M within hours. Stake.com's operations team paused withdrawals and deposits within ~20 minutes of the first malicious transaction and disabled the malicious-transaction surface within ~4 hours.

The proximate cause was compromise of the platform's hot-wallet private keys. Stake co-founder Edward Craven publicly stated that the platform's private keys were "not compromised"; this is at odds with on-chain forensic analysis (Hacken, Halborn, Merkle Science, Olympix, QuillAudits, TRM Labs) which uniformly concluded that the attacker held key material with transfer() authority over the affected hot-wallet contracts. TRM Labs's reporting, drawing on the FBI's investigation, attributes the access vector to social engineering of Stake.com employees with access to internal withdrawal mechanisms — which lands the case in the same off-chain-entry-vector class as the KuCoin (2020) operator-internal-IT compromise pattern, not in a third-party-vendor supply-chain class.

The FBI's 2023-09-07 press release confirmed Lazarus Group / DPRK attribution and published 40 attacker-controlled wallet addresses across Ethereum, BNB Chain, Polygon, and Bitcoin. The attribution was made within 72 hours of the incident — a notably faster public-attribution timeline than the OAK-G01 cases of the prior decade — and explicitly grouped Stake.com with Atomic Wallet (2023-06) and Alphapo / CoinsPaid (2023-07) as a single OAK-G01 campaign wave.

For OAK's purposes, the Stake.com case is the second canonical worked example of operator-internal hot-wallet key compromise, after KuCoin 2020. Where KuCoin produced the high-water-mark coordinated-recovery outcome (~84%), Stake.com produced the opposite outcome: ~2.4% recovery, with the bulk of stolen value successfully laundered through cross-chain bridges and mixers. The contrast between the two cases is one of the most directly actionable defender-side lessons in the OAK corpus.

Timeline (UTC unless noted)

When Event OAK ref
Pre-event Social-engineering compromise of Stake.com employee(s) with access to internal withdrawal mechanisms / hot-wallet key material (per TRM Labs / FBI investigation) (off-chain entry vector — no exact OAK v0.1 match)
2023-09-04 ~00:00 First anomalous outbound from Stake.com Ethereum hot wallet (~$3.9M USDT, then 6,001 ETH ~$9.8M) T5-equivalent (extraction event)
2023-09-04 ~00:20 Stake.com pauses withdrawals and deposits (operator response)
2023-09-04 hours 0–4 Sequential extractions on Polygon (~14.24M MATIC) and BNB Chain (~82,650 BNB); cumulative loss reaches ~$41M (extraction continued)
2023-09-04 ~04:00 Stake.com disables malicious-transaction surface; containment complete (operator response)
2023-09-04 onward Attacker begins consolidating proceeds across Ethereum, Polygon, and BSC into a 40-address attacker cluster T8.001-equivalent signal
2023-09-07 Stake.com discloses cross-chain movements to Bitcoin via Polygon and Avalanche bridges (disclosure)
2023-09-07 FBI press release publicly identifies Lazarus Group / APT38 / DPRK cyber actors as responsible; publishes 40 attacker-controlled wallet addresses; explicitly groups Stake.com with Atomic Wallet and Alphapo / CoinsPaid as a single campaign wave G01 attribution (confirmed)
2023-09 onward Stage-1 laundering: conversion of stolen assets into native tokens and bridging to Bitcoin via Avalanche's BTC.b bridge T7.003 (Cross-Chain Bridge Laundering)
2023-09 onward Stage-2 laundering: stolen BTC routed through Sinbad and Yonmix mixers T7.001 (Mixer-Routed Hop)
2023-09 onward Stage-3 laundering: BTC converted back into stablecoins (USDT) for off-ramp T7.x
2023-09 onward Law enforcement freezes assets from seven Avalanche-bridge transactions during stages 1 and 3 (freeze action)
2024-10 U.S. DOJ files civil forfeiture complaint targeting 15.5 BTC.b ($970K) traced from the Stake.com hack laundering chain (recovery outcome — ~2.4%)

What defenders observed and learned

  • Operator-internal hot-wallet key compromise via social engineering is now the modal OAK-G01 entry vector against custody operators. TRM Labs's public framing of the Stake.com vector as employee social engineering matches the documented patterns in Atomic Wallet (June 2023), Alphapo / CoinsPaid (July 2023), and the broader 2023–2024 wave of OAK-G01 custody compromises. Stake.com is not a smart-contract exploit, not a bridge exploit, and not a third-party-vendor supply-chain compromise; it is operator-internal-key compromise driven by employee-targeted social engineering. Defender runbooks for crypto-custody operators should treat this vector as a primary threat model.
  • Sub-three-day public FBI attribution is now operationally achievable for OAK-G01 events. The Stake.com timeline (theft 2023-09-04, FBI press release 2023-09-07) is materially faster than the OAK-G01 attribution surface available pre-2022. The FBI's 2023-09-07 release also published the attacker address list, which directly enabled exchange-side and bridge-side address blocking. Defender risk teams should treat FBI public-attribution releases as a real-time blocklist source, not just an after-the-fact attribution record.
  • Cross-chain-bridge laundering plus Bitcoin-side mixer laundering defeated industry recovery in this case. The Avalanche BTC.b bridge plus Sinbad / Yonmix mixer combination moved the bulk of value out of the issuer-freeze and exchange-blocking choke-points that drove the KuCoin (2020) recovery. The ~2.4% recovery figure is roughly the inverse of the KuCoin ~84% benchmark; the gap is structural, not operational. The lesson for defenders is that the recovery model that worked in 2020 (issuer freezes on ERC-20s plus exchange-side deposit-blocking) does not generalise to a laundering chain that exits ERC-20 land within hours and routes through Bitcoin mixers.
  • Operator's own public-statement framing can diverge from forensic consensus. Stake co-founder Craven's "keys not compromised" statement is at odds with the on-chain evidence and with the FBI's attribution. Defender risk teams reading public post-incident statements from operators should weight on-chain forensic analysis (Hacken, Halborn, Merkle Science, TRM Labs, Elliptic) above operator self-statements, particularly when the operator has commercial reasons to minimise the incident.

What this example tells contributors writing future Technique pages

  • The operator-internal hot-wallet key compromise gap (flagged in the KuCoin 2020 worked example) is now a recurring pattern, not a one-off. With Stake.com (2023-09), Atomic Wallet (2023-06), Alphapo / CoinsPaid (2023-07), CoinEx (2023-09), and the broader 2023–2024 OAK-G01 custody wave, the operator-side internal-key-compromise entry vector now has multiple confirmed worked examples. A future v0.x update should add a T11.x sub-Technique covering operator-internal key compromise — likely with sub-sub-Techniques for (a) social-engineered employee access (Stake.com, Atomic Wallet), (b) internal-IT compromise via malware (KuCoin candidate vector), and (c) insider misuse. The OAK convention from KuCoin still applies until that update lands: document the off-chain entry vector in the worked example, do not stretch existing T11 sub-Techniques.
  • confirmed attribution is the right marker for Stake.com, in contrast to KuCoin's inferred-strong. The FBI press release dated 2023-09-07 names Lazarus Group / APT38 / DPRK explicitly and lists wallet addresses; this clears the OAK confirmed-grade bar set by the Harmony Horizon (2022-06) FBI attribution. Contributors writing post-2022 OAK-G01 custody-compromise cases should expect confirmed to be the typical attribution grade — the FBI / Treasury attribution surface for crypto-specific OAK-G01 events accelerated materially after the Harmony Horizon precedent.
  • Recovery-rate documentation matters precisely because the Stake.com outcome is not the KuCoin outcome. The KuCoin worked example sets the upper bound (~84%); the Stake.com worked example sets a realistic lower bound (~2.4%) for cases where laundering exits the ERC-20 / exchange-blocking choke-point fast. Contributors writing future custody-hack examples should document both the recovery rate and the laundering-chain structure that produced it — the recovery rate is downstream of the laundering Technique mix (T7.001 / T7.003 / DEX-routing), and the OAK corpus should make that relationship legible.

Public references

  • [fbistake2023] — FBI press release (2023-09-07) confirming Lazarus Group attribution and publishing 40 attacker-controlled wallet addresses.
  • [chainalysisstake2023] — Chainalysis on the Stake.com cluster and OAK-G01 2023 campaign-wave context.
  • [ellipticstake2023] — Elliptic on Stake.com tactics and the broader OAK-G01 2023 custody-compromise wave.
  • [stakepostmortem2023] — Stake.com / TRM Labs incident-analysis and laundering-chain reconstruction (Avalanche BTC.b → Sinbad / Yonmix → USDT).
  • [chainalysis2024dprk] for cumulative OAK-G01 / DPRK-attributed totals context.
  • [ofac2022tornado] for the Tornado Cash sanctions context shaping OAK-G01's post-2022 mixer-rail shift to Sinbad / Yonmix.

Discussion

Stake.com is the canonical OAK example of an operator-internal hot-wallet key compromise that was successfully laundered — the structural counterpart to KuCoin (2020). The two cases share the same entry-vector class (operator-side key compromise, no exact OAK v0.1 Technique match) and the same OAK-G01 attribution; they diverge sharply on the laundering rail and recovery outcome. KuCoin's stolen value sat predominantly in ERC-20s with freeze-capable issuers, and the laundering chain ran through DEXes and mixers that the industry was able to block fast enough to recover ~84% of value. Stake.com's stolen value moved out of ERC-20 / exchange-blocking choke-points within hours via the Avalanche BTC.b bridge, then through Bitcoin-native mixers (Sinbad, Yonmix) that sit outside the issuer-freeze surface entirely. The ~2.4% recovery rate is the structural ceiling for cases with that laundering profile, not an operational failure.

The case is also part of the 2023–2024 OAK-G01 custody-compromise wave that the FBI's 2023-09-07 press release explicitly grouped: Atomic Wallet (June 2023, ~$100M), Alphapo and CoinsPaid (July 2023, ~$60M), Stake.com (September 2023, ~$41M), CoinEx (September 2023, ~$54M). The wave shares (a) operator-internal-key entry vectors in the same OAK v0.1 taxonomy gap, (b) post-Tornado-Cash-sanctions laundering rails (Sinbad, Yonmix, cross-chain bridges replacing the pre-2022 Tornado Cash–dominated pattern documented in [ofac2022tornado]), and (c) confirmed-grade FBI attribution. Contributors writing the other cases in the wave should mirror the Stake.com worked-example structure; the four cases together are the strongest evidence in the OAK corpus that operator-internal hot-wallet key compromise via employee social engineering is the modal OAK-G01 custody-side entry vector for the post-2022 era.

The contrast with the smart-contract-exploit OAK-G01 cases (Ronin Bridge 2022, Harmony Horizon 2022) is also instructive. The 2022 wave compromised on-chain control surfaces (validator keys, multisig signers); the 2023 wave compromised off-chain operator surfaces (employee endpoints, internal withdrawal mechanisms). The shift suggests that on-chain hardening (multisig threshold increases, validator-key segregation) post-2022 pushed OAK-G01 toward the operator's off-chain surface — which OAK v0.1 does not cover at the Technique level and should add coverage for in a future v0.x update.

Techniques demonstrated (3)