@tanuki42_

Independent on-chain analyst | founder @ pangolin intelligence & contributor @SEAL_911

Somewhere
Joined June 2022
1/ Thought it might be helpful to translate this for crypto folks so you know who is hacking you. tl;dr the word "Lazarus" doesn't mean anything anymore, it's just a collective name used to describe various North Korean cyber operations. The (relevant) clusters are as follows:
14
54
7
275
25,489
PSA: On the eve of @token2049 week, please be CAREFUL when talking to people you don't know. 🇰🇵 North Korea has used proxies to socially engineer people in real life at conferences (see $285M Drift hack in April). Others do the same. Be extremely careful what you disclose.
17
34
11
298
52,283
North Korea got Bitget. They are already working on whoever is next. If you work in the crypto industry, that includes you, and you need to be ready. You can't defend against an adversary you don't understand. If your team would like to receive a personalised briefing on threat actors like North Korea, The Com and the rest of the dark forest, please reach out. pangolinintelligence.com/bri…
1/ Thought it might be helpful to translate this for crypto folks so you know who is hacking you. tl;dr the word "Lazarus" doesn't mean anything anymore, it's just a collective name used to describe various North Korean cyber operations. The (relevant) clusters are as follows:
3
8
1
55
7,694
Managed to work with @circle (🤯) to help coordinate another $201k of @bitget proceeds being frozen. The launderers were trying to shift funds between EVM and Noble, but CCTP has limits on the amount which can be bridged out of Noble. One of their transfers hit the cap and sat pending in the bridge. That gave a window to get Circle to blacklist the destination address before the limit reset. The transfers can't settle, so $201k is now stuck between Noble and Ethereum, which could provide a path to recovery through legal process.
2
4
1
59
3,699
My timeline after every big DPRK hack: 1) Big exchange gets hacked for XXX,XXX,XXX 2) "ITS LAZARUS" 3) They immediately launder it all through @THORChain into @Kruwed CoinJoins. Been the exact same story since ~2023?
5
9
97
8,008
A break from the DPRK doom for once: just picked up these custom AF1s from @KicksByAchiles. Awesome work sir, thanks so much! 🔥
4
17
1,500
Inb4 @Kruwed launders another $350M of stolen funds for DPRK with not a single care in the world
🤖 Made with AI
4
1
15
1,492
Lets have a race: @circle vs @tether There is 100k USDC and 218k USDT on this address: 0xe07bd590e1198666230932bad5db3dbbe21e7d57 It's three hops from the @bitget initial theft address and has sat for >2.5 hours now. Who's going to stop 🇰🇵 first?
10
10
5
174
75,028
tanuki42 retweeted
Circle and Tether should have a CT autist on the payroll, just spotting hacks at all times and blacklisting any legs with their stablecoins. One single guy who nolifes CT for hacks is all they need they would recover so many millions not even joking
Lets have a race: @circle vs @tether There is 100k USDC and 218k USDT on this address: 0xe07bd590e1198666230932bad5db3dbbe21e7d57 It's three hops from the @bitget initial theft address and has sat for >2.5 hours now. Who's going to stop 🇰🇵 first?
15
2
105
11,217
Displaying transaction flows related to the Bitget incident on Ethereum and Arbitrum, based on available data. Credit to @dcfgod, @Dogetoshi, @SpecterAnalyst and @tanuki42_ for references. Please let us know of important info we should add 🙏 etherscan.io/flow?s=54fa8072…
At 18:31 UTC on September 24, 2026, Bitget’s security systems identified unauthorized transfers involving a limited number of hot wallets. Our security team immediately activated emergency response procedures and began a full investigation. Based on our current assessment, approximately $351.6 million in assets were affected. Bitget’s cold wallets and the overwhelming majority of platform assets remain secure and unaffected. Most importantly, user funds remain protected. The incident falls within the coverage of Bitget’s User Protection Fund, which currently holds more than $464 million. Customer account balances remain accurate, and deposits and trading continue to operate normally. As a precaution, withdrawals have been temporarily suspended while our teams complete a comprehensive security review. We have identified and flagged the relevant transfer addresses and have formally engaged law enforcement agencies and leading on-chain security partners. We are working around the clock to restore withdrawal services as soon as it is safe to do so. Bitget will provide further updates through our official channels. We will not speculate on the attack vector while the investigation remains ongoing. Our focus is on protecting users, securing all systems, and delivering complete transparency throughout this process.
8
20
1
113
15,715
This overlap is legit, here is the map. Somewhat ironically it overlaps on accounts being used to launder funds through Bitget's own cross-chain bridge 🫠🫠🫠
Regarding who is behind the hack: I present to you THE LAZARUS GROUP. just linked this hack to the AFX hack, which stole $24M in July and was specifically attributed to TraderTraitor. The stolen XRP from Bitget was bridged and can be directly linked to the funds stolen in the AFX hack. Stay smart.
3
5
41
5,303
To be specific though - this does not mean that it's overlapping because DPRK control the intermediary accounts. All this tells us is that the same party is laundering the proceeds from both hacks. Subtle. But different.
5
429
If the crypto industry decides that it's too "decentralized" to do anything to stop these funds being laundered, then I promise you that virtually none of this money is going to be seen again. Well, it will be seen. Briefly. Somewhere off the coast of Japan 🇰🇵.
确认 1.初步评估涉及金额约3.516亿美金 2.平台有三层钱包体系,确认当前全部冷钱包未受影响 3.用户资金安全。本次损失金额完全在Bitget用户保护基金覆盖范围之内,保护基金当前规模逾4.64亿美元 已采取的措施: 1.事件发生后数分钟内启动应急响应小组 2.异常转账地址已标记并上报 3.出于资金安全考虑,提币功能暂时关闭,待安全核查完成后有序恢复 4.已通知执法机构及链上安全机构介入调查 我将以小时级别持续同步事件最新进展,请关注本渠道及官方各平台。正在准备会开启一个直播,直面大家有的任何问题。
1
2
16
2,370
Compromised by 🇰🇵: December 2024 Telegram taken over: August 2026 Going 20 months undetected is a new record for me. It's crazy how long these guys will wait. Props to @_clemens__ for spreading the word to protect others 🤝
I have been hacked by the DPRK. Here's how it happened: In December 2024, a contact that i had met in person several weeks earlier messaged me on telegram asking for a meeting, just like my fake account is now doing. Upon joining the call, the audio wasn't working and then my contact pinged me to update my video call software (Microsoft Teams, which i usually never use), as soon as I clicked that link, my entire device was compromised. Text book social engineering and urgency in a key moment were all that was needed to get comfy on my device. Although I deleted all files and did several malware sweeps, I did not fully factory reset my device. 21 months later, this piece of malware became active and took over my PC and the result is 8 years of telegram history and contacts now in the hand of a group linked to north korea. I sincerely hope none of you have tried joining any of the calls with "me" or worse fallen into their trap. A huge thank you to @tanuki42_ who has been tracing this groups activities and has been extremely helpful in getting my compromised accounts deleted after telegram support proved useless. If you think this couldn't happen to you, here is who you are dealing with: nitter.cf/tanuki42_/status/20975… securelist.com/bluenoroff-ap…
16
72
16,387
If you are a person or company who has lost crypto, one of the first things that any reputable incident responder is going to tell you to do is to call the police. Except it seems like too few people in crypto know who to call. Here is a list: pangolinintelligence.com/rep…
4
14
2
93
19,618
For any law enforcement reading this: if you either don't see your jurisdiction listed or something needs correcting, reach out to me (can email [email protected]) For random people reading this: lmk if you find the easter egg 🥚
1
4
1,199
7/ Somehow we need to start translating this stuff so that crypto devs sitting on top of X million/billion dollars actually start understanding the threat and put resources/people towards protecting themselves. I would strongly recommend not getting hacked in the first place rather than trying to salvage your project when Marshall Kim is sipping on the Hennessy he bought with your treasury money.
1
1
13
819
8/ Once you have hired people who can actually understand this graph, please beg them to read the wider research from @blackorbird and Kudelski Security here: nitter.cf/blackorbird/status/209…
Beyond Lazarus: Organization of DPRK Cyber Capabilities The old #Lazarus umbrella has been decomposed into six distinct clusters (TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, Famous Chollima) that mix espionage with crypto theft, ransomware, and bank heists. kudelskisecurity.com/researc…
1
1
8
1,097