Worked example · 2023-09
Stake.com hot-wallet theft — multi-chain — 2023-09-04
Summary
On September 4, 2023, Stake.com — a crypto-native online gambling platform — saw unauthorised outbound transactions from its hot wallets on Ethereum, BNB Chain, and Polygon beginning shortly after 00:00 UTC. The first observable on-chain event was a transfer of approximately $3.9M USDT on Ethereum, followed by a 6,001 ETH (~$9.8M) extraction; sequential transfers on Polygon (~14.24M MATIC) and BNB Chain (~82,650 BNB) brought the cumulative loss to approximately $41M within hours. Stake.com's operations team paused withdrawals and deposits within ~20 minutes of the first malicious transaction and disabled the malicious-transaction surface within ~4 hours.
The proximate cause was compromise of the platform's hot-wallet private keys. Stake co-founder Edward Craven publicly stated that the platform's private keys were "not compromised"; this is at odds with on-chain forensic analysis (Hacken, Halborn, Merkle Science, Olympix, QuillAudits, TRM Labs) which uniformly concluded that the attacker held key material with transfer() authority over the affected hot-wallet contracts. TRM Labs's reporting, drawing on the FBI's investigation, attributes the access vector to social engineering of Stake.com employees with access to internal withdrawal mechanisms — which lands the case in the same off-chain-entry-vector class as the KuCoin (2020) operator-internal-IT compromise pattern, not in a third-party-vendor supply-chain class.
The FBI's 2023-09-07 press release confirmed Lazarus Group / DPRK attribution and published 40 attacker-controlled wallet addresses across Ethereum, BNB Chain, Polygon, and Bitcoin. The attribution was made within 72 hours of the incident — a notably faster public-attribution timeline than the OAK-G01 cases of the prior decade — and explicitly grouped Stake.com with Atomic Wallet (2023-06) and Alphapo / CoinsPaid (2023-07) as a single OAK-G01 campaign wave.
For OAK's purposes, the Stake.com case is the second canonical worked example of operator-internal hot-wallet key compromise, after KuCoin 2020. Where KuCoin produced the high-water-mark coordinated-recovery outcome (~84%), Stake.com produced the opposite outcome: ~2.4% recovery, with the bulk of stolen value successfully laundered through cross-chain bridges and mixers. The contrast between the two cases is one of the most directly actionable defender-side lessons in the OAK corpus.
Timeline (UTC unless noted)
| When | Event | OAK ref |
|---|---|---|
| Pre-event | Social-engineering compromise of Stake.com employee(s) with access to internal withdrawal mechanisms / hot-wallet key material (per TRM Labs / FBI investigation) | (off-chain entry vector — no exact OAK v0.1 match) |
| 2023-09-04 ~00:00 | First anomalous outbound from Stake.com Ethereum hot wallet (~$3.9M USDT, then 6,001 ETH ~$9.8M) | T5-equivalent (extraction event) |
| 2023-09-04 ~00:20 | Stake.com pauses withdrawals and deposits | (operator response) |
| 2023-09-04 hours 0–4 | Sequential extractions on Polygon (~14.24M MATIC) and BNB Chain (~82,650 BNB); cumulative loss reaches ~$41M | (extraction continued) |
| 2023-09-04 ~04:00 | Stake.com disables malicious-transaction surface; containment complete | (operator response) |
| 2023-09-04 onward | Attacker begins consolidating proceeds across Ethereum, Polygon, and BSC into a 40-address attacker cluster | T8.001-equivalent signal |
| 2023-09-07 | Stake.com discloses cross-chain movements to Bitcoin via Polygon and Avalanche bridges | (disclosure) |
| 2023-09-07 | FBI press release publicly identifies Lazarus Group / APT38 / DPRK cyber actors as responsible; publishes 40 attacker-controlled wallet addresses; explicitly groups Stake.com with Atomic Wallet and Alphapo / CoinsPaid as a single campaign wave | G01 attribution (confirmed) |
| 2023-09 onward | Stage-1 laundering: conversion of stolen assets into native tokens and bridging to Bitcoin via Avalanche's BTC.b bridge | T7.003 (Cross-Chain Bridge Laundering) |
| 2023-09 onward | Stage-2 laundering: stolen BTC routed through Sinbad and Yonmix mixers | T7.001 (Mixer-Routed Hop) |
| 2023-09 onward | Stage-3 laundering: BTC converted back into stablecoins (USDT) for off-ramp | T7.x |
| 2023-09 onward | Law enforcement freezes assets from seven Avalanche-bridge transactions during stages 1 and 3 | (freeze action) |
| 2024-10 | U.S. DOJ files civil forfeiture complaint targeting |
(recovery outcome — ~2.4%) |
What defenders observed and learned
- Operator-internal hot-wallet key compromise via social engineering is now the modal OAK-G01 entry vector against custody operators. TRM Labs's public framing of the Stake.com vector as employee social engineering matches the documented patterns in Atomic Wallet (June 2023), Alphapo / CoinsPaid (July 2023), and the broader 2023–2024 wave of OAK-G01 custody compromises. Stake.com is not a smart-contract exploit, not a bridge exploit, and not a third-party-vendor supply-chain compromise; it is operator-internal-key compromise driven by employee-targeted social engineering. Defender runbooks for crypto-custody operators should treat this vector as a primary threat model.
- Sub-three-day public FBI attribution is now operationally achievable for OAK-G01 events. The Stake.com timeline (theft 2023-09-04, FBI press release 2023-09-07) is materially faster than the OAK-G01 attribution surface available pre-2022. The FBI's 2023-09-07 release also published the attacker address list, which directly enabled exchange-side and bridge-side address blocking. Defender risk teams should treat FBI public-attribution releases as a real-time blocklist source, not just an after-the-fact attribution record.
- Cross-chain-bridge laundering plus Bitcoin-side mixer laundering defeated industry recovery in this case. The Avalanche BTC.b bridge plus Sinbad / Yonmix mixer combination moved the bulk of value out of the issuer-freeze and exchange-blocking choke-points that drove the KuCoin (2020) recovery. The ~2.4% recovery figure is roughly the inverse of the KuCoin ~84% benchmark; the gap is structural, not operational. The lesson for defenders is that the recovery model that worked in 2020 (issuer freezes on ERC-20s plus exchange-side deposit-blocking) does not generalise to a laundering chain that exits ERC-20 land within hours and routes through Bitcoin mixers.
- Operator's own public-statement framing can diverge from forensic consensus. Stake co-founder Craven's "keys not compromised" statement is at odds with the on-chain evidence and with the FBI's attribution. Defender risk teams reading public post-incident statements from operators should weight on-chain forensic analysis (Hacken, Halborn, Merkle Science, TRM Labs, Elliptic) above operator self-statements, particularly when the operator has commercial reasons to minimise the incident.
What this example tells contributors writing future Technique pages
- The operator-internal hot-wallet key compromise gap (flagged in the KuCoin 2020 worked example) is now a recurring pattern, not a one-off. With Stake.com (2023-09), Atomic Wallet (2023-06), Alphapo / CoinsPaid (2023-07), CoinEx (2023-09), and the broader 2023–2024 OAK-G01 custody wave, the operator-side internal-key-compromise entry vector now has multiple confirmed worked examples. A future v0.x update should add a T11.x sub-Technique covering operator-internal key compromise — likely with sub-sub-Techniques for (a) social-engineered employee access (Stake.com, Atomic Wallet), (b) internal-IT compromise via malware (KuCoin candidate vector), and (c) insider misuse. The OAK convention from KuCoin still applies until that update lands: document the off-chain entry vector in the worked example, do not stretch existing T11 sub-Techniques.
confirmedattribution is the right marker for Stake.com, in contrast to KuCoin'sinferred-strong. The FBI press release dated 2023-09-07 names Lazarus Group / APT38 / DPRK explicitly and lists wallet addresses; this clears the OAKconfirmed-grade bar set by the Harmony Horizon (2022-06) FBI attribution. Contributors writing post-2022 OAK-G01 custody-compromise cases should expectconfirmedto be the typical attribution grade — the FBI / Treasury attribution surface for crypto-specific OAK-G01 events accelerated materially after the Harmony Horizon precedent.- Recovery-rate documentation matters precisely because the Stake.com outcome is not the KuCoin outcome. The KuCoin worked example sets the upper bound (~84%); the Stake.com worked example sets a realistic lower bound (~2.4%) for cases where laundering exits the ERC-20 / exchange-blocking choke-point fast. Contributors writing future custody-hack examples should document both the recovery rate and the laundering-chain structure that produced it — the recovery rate is downstream of the laundering Technique mix (T7.001 / T7.003 / DEX-routing), and the OAK corpus should make that relationship legible.
Public references
[fbistake2023]— FBI press release (2023-09-07) confirming Lazarus Group attribution and publishing 40 attacker-controlled wallet addresses.[chainalysisstake2023]— Chainalysis on the Stake.com cluster and OAK-G01 2023 campaign-wave context.[ellipticstake2023]— Elliptic on Stake.com tactics and the broader OAK-G01 2023 custody-compromise wave.[stakepostmortem2023]— Stake.com / TRM Labs incident-analysis and laundering-chain reconstruction (Avalanche BTC.b → Sinbad / Yonmix → USDT).[chainalysis2024dprk]for cumulative OAK-G01 / DPRK-attributed totals context.[ofac2022tornado]for the Tornado Cash sanctions context shaping OAK-G01's post-2022 mixer-rail shift to Sinbad / Yonmix.
Discussion
Stake.com is the canonical OAK example of an operator-internal hot-wallet key compromise that was successfully laundered — the structural counterpart to KuCoin (2020). The two cases share the same entry-vector class (operator-side key compromise, no exact OAK v0.1 Technique match) and the same OAK-G01 attribution; they diverge sharply on the laundering rail and recovery outcome. KuCoin's stolen value sat predominantly in ERC-20s with freeze-capable issuers, and the laundering chain ran through DEXes and mixers that the industry was able to block fast enough to recover ~84% of value. Stake.com's stolen value moved out of ERC-20 / exchange-blocking choke-points within hours via the Avalanche BTC.b bridge, then through Bitcoin-native mixers (Sinbad, Yonmix) that sit outside the issuer-freeze surface entirely. The ~2.4% recovery rate is the structural ceiling for cases with that laundering profile, not an operational failure.
The case is also part of the 2023–2024 OAK-G01 custody-compromise wave that the FBI's 2023-09-07 press release explicitly grouped: Atomic Wallet (June 2023, ~$100M), Alphapo and CoinsPaid (July 2023, ~$60M), Stake.com (September 2023, ~$41M), CoinEx (September 2023, ~$54M). The wave shares (a) operator-internal-key entry vectors in the same OAK v0.1 taxonomy gap, (b) post-Tornado-Cash-sanctions laundering rails (Sinbad, Yonmix, cross-chain bridges replacing the pre-2022 Tornado Cash–dominated pattern documented in [ofac2022tornado]), and (c) confirmed-grade FBI attribution. Contributors writing the other cases in the wave should mirror the Stake.com worked-example structure; the four cases together are the strongest evidence in the OAK corpus that operator-internal hot-wallet key compromise via employee social engineering is the modal OAK-G01 custody-side entry vector for the post-2022 era.
The contrast with the smart-contract-exploit OAK-G01 cases (Ronin Bridge 2022, Harmony Horizon 2022) is also instructive. The 2022 wave compromised on-chain control surfaces (validator keys, multisig signers); the 2023 wave compromised off-chain operator surfaces (employee endpoints, internal withdrawal mechanisms). The shift suggests that on-chain hardening (multisig threshold increases, validator-key segregation) post-2022 pushed OAK-G01 toward the operator's off-chain surface — which OAK v0.1 does not cover at the Technique level and should add coverage for in a future v0.x update.