OAK — OnChain Attack Knowledge

Worked example · 2025-09

SBI Crypto mining-pool drain — Bitcoin / multi-chain — 2025-09-24

Loss
approximately $21M extracted from addresses linked to SBI Crypto on 2025-09-24, distributed across BTC, ETH, LTC, DOGE, and BCH per ZachXBT's on-chain investigation. SBI Crypto is the cryptocurrency-mining subsidiary of Japanese financial conglomerate SBI Group; the affected addresses corresponded to the operational mining-pool wallets rather than to user-deposit custody.
Recovery
none of material consequence on the on-chain layer at v0.1 cutoff. SBI Group did not publicly confirm the incident in the days following the on-chain detection. The stolen funds were funnelled through five instant exchanges before being deposited into Tornado Cash per ZachXBT's tracking.
OAK Techniques observed
OAK-T11.001 (Third-Party Signing / Custody Vendor Compromise) broadly construed — the entry vector pattern matches the canonical OAK-G01 / TraderTraitor playbook of operator-side / vendor-side key-handling-environment compromise; the precise mechanism (whether via SBI internal personnel, vendor-side compromise, or signing-infrastructure-supply-chain compromise) has not been publicly disclosed at v0.1 cutoff. OAK-T7.001 (Mixer-Routed Hop) — the post-extraction laundering pipeline routed through five instant-exchange hops then into Tornado Cash. Note that Tornado Cash was de-listed from OFAC SDN on 2025-03-21 per the court ruling that autonomous smart contracts are not property subject to sanctions; the de-listing did not retire the Tornado Cash protocol, and post-de-listing usage by DPRK-cohort operators is on the public record.
Attribution
inferred-strong OAK-G01 / TraderTraitor cluster per ZachXBT on-chain investigation and matching of laundering-pattern fingerprints against the established 2024–2025 G01 cohort. No FBI IC3 PSA had been issued for this specific incident at v0.1 cutoff; no OFAC SDN designation tied to this incident; no DOJ named-actor designation. The attribution rests primarily on the laundering-rail-pattern match (instant-exchange hops + Tornado Cash) and on wallet-cluster overlap with addresses previously linked to G01 activity.
OAK-Gnn
OAK-G01 Lazarus Group / DPRK-attributed.
Key teaching point
the SBI Crypto case is the strongest H2 2025 worked example of the OAK-G01 cohort continuing to extract from second-tier crypto-firm targets at the ~$10–50M scale, distinct from the headline 2024–2025 cases (DMM Bitcoin $308M, WazirX $235M, Bybit $1.46B) by an order of magnitude in dollar loss but operationally identical in entry-vector pattern, target profile (regulated-jurisdiction Japanese / Korean / Indian crypto-firm), and laundering-rail substrate. The H2 2025 cohort — SBI Crypto (September), Upbit secondary breach (November per industry reporting), and adjacent smaller cases — collectively reinforce the structural OAK observation that the OAK-G01 operator pattern by 2025 is industrialised and continues to produce ~$10–50M extractions from second-tier targets at a steady cadence even in the headline shadow of the Bybit predicate.

Summary

SBI Crypto is the cryptocurrency-mining subsidiary of SBI Group, a major Japanese financial conglomerate. The subsidiary operates Bitcoin (and adjacent PoW asset) mining infrastructure with associated operational wallets used to receive mining rewards, settle pool payouts, and manage operational expenses. The structural target surface — operational wallets at a regulated-jurisdiction crypto-firm subsidiary — places SBI Crypto in the same target profile as DMM Bitcoin (May 2024), WazirX (July 2024), Indodax (September 2024), Phemex (January 2025), and Infini (February 2025): regulated-jurisdiction crypto-firm with material operational holdings and a key-handling environment that — per the recurring 2024–2025 G01 cohort fingerprint — is the load-bearing failure surface.

On 2025-09-24, addresses linked to SBI Crypto saw suspicious outflows worth approximately $21M across BTC, ETH, LTC, DOGE, and BCH per ZachXBT's on-chain investigation published on 2025-10-01 by CoinDesk ([coindesksbicrypto2025]) and Unchained ([unchainedsbicrypto2025]). The stolen funds were routed through five instant-exchange hops then deposited into Tornado Cash. ZachXBT noted that several indicators resembled tactics used in previous North Korean state-backed cyberattacks, raising concerns that this incident was another in the H2 2025 string of DPRK-linked crypto heists.

SBI Group did not publicly confirm the hack and did not respond to CoinDesk's request for comment. The lack of operator-side public statement is structurally different from the 2024–2025 cohort cases where the operator (DMM, WazirX, Bybit, Phemex, Infini) issued public statements within hours-to-days of detection; the SBI silence is itself a v0.1 attribution-and-detection-chain limitation that future contributors should track.

For OAK's purposes the case is the canonical H2 2025 worked example of the OAK-G01 cohort continuing to extract from second-tier crypto-firm targets under the same operational pattern as the headline 2024–2025 cases but at a smaller dollar scale. The novel OAK contribution is the H2 2025 cohort framing — SBI Crypto sits in the cohort with the smaller incidents that fill the gap between the headline 2025 events (Bybit February, Phemex January, Infini February).

Timeline (UTC)

When Event OAK ref
Pre-event SBI Crypto operates Bitcoin mining infrastructure with operational wallets across BTC, ETH, LTC, DOGE, and BCH; key-handling environment for operational wallets is the latent T11.001 surface (T11.001 latent surface)
Pre-event (mechanism not publicly disclosed) Off-chain compromise of operator-side key-handling environment per the inferred-strong G01 cohort fingerprint match; precise mechanism not publicly disclosed at v0.1 T11.001 entry vector (mechanism inferred)
2025-09-24 Anomalous outflows from SBI Crypto-linked addresses; ~$21M extracted across BTC, ETH, LTC, DOGE, BCH T11.001 extraction
2025-09-24 onward Funds funnelled through five instant-exchange hops; deposits into Tornado Cash T7.001 laundering
2025-10-01 ZachXBT publishes on-chain investigation; CoinDesk and Unchained publish coverage with G01-leaning attribution (community / industry forensic surface)
2025-10 onward SBI Group does not publicly confirm the hack; no public operator-side statement at v0.1 cutoff (operator-silence; attribution-chain limitation)
Continuing No FBI IC3 PSA; no OFAC SDN designation; no DOJ named-actor designation specific to this incident at v0.1 cutoff (attribution state)

What defenders observed

  • The H2 2025 cohort sits in the headline shadow of Bybit but is operationally identical in pattern. The Bybit February 2025 predicate produced a $1.46B headline that absorbed industry-reporting attention through Q1–Q2 2025; the H2 2025 cohort (SBI Crypto September, Upbit secondary breach November per industry reporting, adjacent smaller cases) sits at a structurally different scale ($10–50M) but shares the operational-pattern fingerprints with the headline cases. Contributors writing future H2 2025 examples should preserve the cohort-shadow framing — the operator pattern is industrialised, the target profile is recurring, and the smaller cases are not "background noise" but the ongoing expression of the same operator pattern at smaller target scales.
  • Operator-silence is itself a structural attribution-and-detection-chain limitation. SBI Group did not publicly confirm the hack and did not respond to CoinDesk's request for comment. This is structurally different from the 2024–2025 cohort cases where the operator issued public statements within hours-to-days of detection. The structural reasons for operator-silence vary: regulatory-disclosure-bound silence (Japanese FSA / FSC reporting requirements may impose timing constraints), insurance-coverage-bound silence (operator may be in active insurance-claim negotiation), legal-process-bound silence (active law-enforcement engagement may impose disclosure restrictions), or reputational silence (operator weighing reputational cost of disclosure against probability of successful private remediation). Contributors writing future cases involving operator-silence should be explicit about the silence as a first-class observation; the silence does not invalidate the on-chain attribution evidence but it materially constrains the public-record detection-chain.
  • The instant-exchange-then-Tornado-Cash laundering pattern survived the March 2025 Tornado Cash de-listing. OFAC formally de-listed Tornado Cash from the SDN list on 2025-03-21 following a court ruling that autonomous smart contracts are not property subject to sanctions. The de-listing did not retire the Tornado Cash protocol; the SBI Crypto laundering chain (instant-exchange hops then Tornado Cash deposits) is canonical evidence that the OAK-G01 cohort continued to use Tornado Cash post-de-listing. Contributors writing future T7.001 examples should not treat the March 2025 de-listing as having retired the Tornado Cash laundering surface; the de-listing changed the legal posture for U.S.-jurisdiction users but did not change the operational availability of the protocol.
  • The five-instant-exchange-hop pattern is the post-Bybit 2025 G01 laundering signature. The SBI Crypto laundering chain routed through five instant exchanges before depositing into Tornado Cash. The instant-exchange-as-mixer-equivalent pattern is the canonical 2025 G01 laundering signature, observable across SBI Crypto, the Bybit-eXch routing (examples/2025-04-exch-shutdown.md), and adjacent 2025 incidents. Contributors writing future T7.001 examples should preserve the per-hop instant-exchange enumeration when the data is on the public record; the per-hop accounting is the structural evidence that distinguishes the 2025 G01 laundering signature from the 2022–2023 Tornado-Cash-direct pattern.
  • The smaller-target H2 2025 cohort is structurally informative for defender-practice generalisation. The DMM Bitcoin / WazirX / Bybit headline cases anchored the 2024–2025 G01 cohort framing at the $200M-and-up scale. The SBI Crypto case extends the cohort framing to the ~$20M scale; combined with the broader H2 2025 smaller-target cohort, the structural observation is that defender practice (OAK-M15 Threshold Signing with Operator Separation, OAK-M18 Out-of-Band Destination Verification, OAK-M21 Anti-Phishing Training, OAK-M22 Rotate-on-Disclosure Discipline) applies uniformly across the cohort regardless of dollar-loss scale. The headline-case framing systematically under-represents the cohort breadth.

What this example tells contributors writing future Technique pages

  • The cohort-shadow framing is a first-class OAK contribution for H2 2025 and forward. Future OAK-G01 worked examples should preserve the cohort-shadow framing explicitly — the headline predicate event (Bybit February 2025) absorbed the industry-reporting attention, but the cohort continued to produce ~$10–50M extractions at a steady cadence through H2 2025. Contributors writing future OAK-G01 cases at the smaller-target scale should resist treating these as "background noise" and should anchor the worked example in the cohort-pattern framing.
  • Operator-silence is a first-class attribution-chain observation. Contributors writing future cases involving operator-silence should make the silence explicit in the timeline and the discussion sections. The silence is a structural attribution-chain limitation — it does not invalidate on-chain evidence but it materially constrains the public-record forensic surface. The structural reasons for silence (regulatory-disclosure-bound, insurance-coverage-bound, legal-process-bound, reputational) are themselves diagnostic and contributors should record the most likely framing where the public record permits.
  • Post-Tornado-Cash-de-listing usage is on the public record and contributors should not treat the de-listing as having retired the laundering surface. The March 2025 Tornado Cash de-listing changed the U.S.-jurisdiction legal posture but did not retire the protocol. The SBI Crypto case is the canonical H2 2025 evidence that the OAK-G01 cohort continued to use Tornado Cash post-de-listing. Contributors writing future T7.001 examples should preserve this distinction explicitly.
  • The instant-exchange-then-mixer pattern is the post-Bybit 2025 G01 laundering signature and should be enumerated per-hop where data permits. The five-instant-exchange-hop pattern observed in the SBI Crypto laundering chain is structurally analogous to the eXch-then-THORChain pattern observed in the Bybit laundering chain. Contributors writing future T7.001 examples should preserve per-hop instant-exchange enumeration when the data is on the public record; the per-hop accounting is the structural evidence that grounds the laundering-rail-substrate attribution.

Public references

  • [coindesksbicrypto2025] (proposed) — CoinDesk reporting on the SBI Crypto hack (2025-10-01); primary source for the $21M figure, the per-asset breakdown, and the DPRK-leaning attribution per ZachXBT.
  • [unchainedsbicrypto2025] (proposed) — Unchained Crypto reporting on the SBI Crypto hack and the ZachXBT attribution; corroborating secondary source for the dollar-loss figure and the laundering-pattern observation.
  • [zachxbtsbicrypto2025] (proposed) — ZachXBT on-chain investigation thread on the SBI Crypto outflows; primary community-record source for the wallet-cluster attribution, the per-hop instant-exchange enumeration, and the Tornado Cash deposit observation.
  • [chainalysis2024dprk] — broader OAK-G01 cohort attribution context.
  • [trilateraldprkstatement2025] — U.S.–Japan–ROK trilateral DPRK statement (2025-01-14); provides the multi-government attribution baseline for the cohort. Does not name SBI Crypto specifically.
  • [fbiic3bybit2025] — FBI IC3 PSA attributing Bybit predicate to TraderTraitor / DPRK; the upstream that the cohort-attribution methodology rests on.

Discussion

The SBI Crypto September 2025 case is OAK's canonical H2 2025 worked example for the OAK-G01 cohort continuing to extract from second-tier crypto-firm targets at the ~$10–50M scale. The case fills a structural gap in the OAK 2025 corpus — the headline 2025 events (Phemex January, Bybit February, Infini February) are concentrated in Q1; the H2 2025 cohort had been under-represented in the OAK examples corpus prior to this entry.

The cohort-shadow framing is the analytically distinctive feature. The Bybit predicate produced a ~$1.46B headline that absorbed industry-reporting attention through Q1–Q2 2025; the H2 2025 cohort sits in that shadow. The structural observation is that the OAK-G01 operator pattern by 2025 is industrialised — the same fabricated-job-offer / fabricated-investor / supply-chain-compromise entry-vector chain that produced the headline 2024 cases (Concentric $1.7M, DMM $308M, WazirX $235M, Radiant $50M) and the headline early-2025 cases (Phemex $30M, Bybit $1.46B, Infini) continues to produce ~$10–50M extractions from second-tier targets at a steady cadence. The cohort breadth is structurally informative for defender-practice generalisation; contributors writing future OAK-G01 cases at the smaller-target scale should anchor the worked example in the cohort-pattern framing rather than treating the smaller cases as background noise.

The operator-silence observation is the second analytically distinctive feature. SBI Group did not publicly confirm the hack and did not respond to CoinDesk's request for comment. This is structurally different from the 2024–2025 cohort cases where the operator issued public statements within hours-to-days of detection. The structural reasons for operator-silence — regulatory-disclosure-bound, insurance-coverage-bound, legal-process-bound, reputational — are themselves diagnostic; contributors writing future cases involving operator-silence should make the silence explicit and should record the most likely framing where the public record permits.

The post-Tornado-Cash-de-listing observation is the third analytically distinctive feature. The March 2025 Tornado Cash de-listing changed the U.S.-jurisdiction legal posture but did not retire the protocol; the SBI Crypto case is the canonical H2 2025 evidence that the OAK-G01 cohort continued to use Tornado Cash post-de-listing. Contributors writing future T7.001 examples should preserve this distinction explicitly — the de-listing did not retire the laundering surface, and the post-de-listing usage by DPRK-cohort operators is on the public record.

For OAK's broader credibility, including SBI Crypto in v0.1 closes a H2 2025 gap in the OAK-G01 cohort coverage. The corpus had headline 2024 cases (Concentric, DMM, WazirX, DeltaPrime, Radiant) and headline early-2025 cases (Phemex, Bybit, Infini) but lacked the H2 2025 anchor that demonstrated the operator pattern continued to fire at the second-tier-target scale through the headline shadow of Bybit. SBI Crypto fills that role and provides the cohort-pattern-continuity utility that the OAK Threat-Actors and Mitigations layers depend on.

Techniques demonstrated (2)