@tanuki42_i
iAccount based inEurope
About this account
- Account based in
- Europe
- Connected via
- Southeast Asia Android App
Account-level information from X, not a live location or the device used for a specific post.
Independent on-chain analyst | founder @ pangolin intelligence & contributor @SEAL_911
Somewhere
Joined June 2022
- Tweets494
- Following392
- Followers7.2K
- Likes923
Pinned Tweet
1/ Thought it might be helpful to translate this for crypto folks so you know who is hacking you.
tl;dr the word "Lazarus" doesn't mean anything anymore, it's just a collective name used to describe various North Korean cyber operations. The (relevant) clusters are as follows:
PSA: On the eve of @token2049 week, please be CAREFUL when talking to people you don't know.
🇰🇵 North Korea has used proxies to socially engineer people in real life at conferences (see $285M Drift hack in April). Others do the same.
Be extremely careful what you disclose.
North Korea got Bitget. They are already working on whoever is next. If you work in the crypto industry, that includes you, and you need to be ready.
You can't defend against an adversary you don't understand.
If your team would like to receive a personalised briefing on threat actors like North Korea, The Com and the rest of the dark forest, please reach out.
pangolinintelligence.com/bri…
Managed to work with @circle (🤯) to help coordinate another $201k of @bitget proceeds being frozen.
The launderers were trying to shift funds between EVM and Noble, but CCTP has limits on the amount which can be bridged out of Noble. One of their transfers hit the cap and sat pending in the bridge.
That gave a window to get Circle to blacklist the destination address before the limit reset. The transfers can't settle, so $201k is now stuck between Noble and Ethereum, which could provide a path to recovery through legal process.
My timeline after every big DPRK hack:
1) Big exchange gets hacked for XXX,XXX,XXX
2) "ITS LAZARUS"
3) They immediately launder it all through @THORChain into @Kruwed CoinJoins.
Been the exact same story since ~2023?
A break from the DPRK doom for once: just picked up these custom AF1s from @KicksByAchiles. Awesome work sir, thanks so much! 🔥
Inb4 @Kruwed launders another $350M of stolen funds for DPRK with not a single care in the world
🤖 Made with AI
And Tether finally comes in. Circle beat Tether by 7 hours 18 minutes. 🤯 I'll eat my words, I only pray this continues.
etherscan.io/tx/0xdd30e4831e…
tanuki42 retweeted
Circle and Tether should have a CT autist on the payroll, just spotting hacks at all times and blacklisting any legs with their stablecoins.
One single guy who nolifes CT for hacks is all they need they would recover so many millions not even joking
tanuki42 retweeted
Displaying transaction flows related to the Bitget incident on Ethereum and Arbitrum, based on available data. Credit to @dcfgod, @Dogetoshi, @SpecterAnalyst and @tanuki42_ for references.
Please let us know of important info we should add 🙏
etherscan.io/flow?s=54fa8072…
At 18:31 UTC on September 24, 2026, Bitget’s security systems identified unauthorized transfers involving a limited number of hot wallets.
Our security team immediately activated emergency response procedures and began a full investigation.
Based on our current assessment, approximately $351.6 million in assets were affected. Bitget’s cold wallets and the overwhelming majority of platform assets remain secure and unaffected.
Most importantly, user funds remain protected.
The incident falls within the coverage of Bitget’s User Protection Fund, which currently holds more than $464 million.
Customer account balances remain accurate, and deposits and trading continue to operate normally.
As a precaution, withdrawals have been temporarily suspended while our teams complete a comprehensive security review.
We have identified and flagged the relevant transfer addresses and have formally engaged law enforcement agencies and leading on-chain security partners.
We are working around the clock to restore withdrawal services as soon as it is safe to do so.
Bitget will provide further updates through our official channels.
We will not speculate on the attack vector while the investigation remains ongoing. Our focus is on protecting users, securing all systems, and delivering complete transparency throughout this process.
This overlap is legit, here is the map.
Somewhat ironically it overlaps on accounts being used to launder funds through Bitget's own cross-chain bridge 🫠🫠🫠
Regarding who is behind the hack:
I present to you THE LAZARUS GROUP.
just linked this hack to the AFX hack, which stole $24M in July and was specifically attributed to TraderTraitor.
The stolen XRP from Bitget was bridged and can be directly linked to the funds stolen in the AFX hack.
Stay smart.
If the crypto industry decides that it's too "decentralized" to do anything to stop these funds being laundered, then I promise you that virtually none of this money is going to be seen again.
Well, it will be seen. Briefly. Somewhere off the coast of Japan 🇰🇵.
Compromised by 🇰🇵: December 2024
Telegram taken over: August 2026
Going 20 months undetected is a new record for me. It's crazy how long these guys will wait.
Props to @_clemens__ for spreading the word to protect others 🤝
I have been hacked by the DPRK. Here's how it happened:
In December 2024, a contact that i had met in person several weeks earlier messaged me on telegram asking for a meeting, just like my fake account is now doing. Upon joining the call, the audio wasn't working and then my contact pinged me to update my video call software (Microsoft Teams, which i usually never use), as soon as I clicked that link, my entire device was compromised.
Text book social engineering and urgency in a key moment were all that was needed to get comfy on my device. Although I deleted all files and did several malware sweeps, I did not fully factory reset my device.
21 months later, this piece of malware became active and took over my PC and the result is 8 years of telegram history and contacts now in the hand of a group linked to north korea.
I sincerely hope none of you have tried joining any of the calls with "me" or worse fallen into their trap. A huge thank you to @tanuki42_ who has been tracing this groups activities and has been extremely helpful in getting my compromised accounts deleted after telegram support proved useless.
If you think this couldn't happen to you, here is who you are dealing with: nitter.cf/tanuki42_/status/20975…
securelist.com/bluenoroff-ap…
If you are a person or company who has lost crypto, one of the first things that any reputable incident responder is going to tell you to do is to call the police.
Except it seems like too few people in crypto know who to call. Here is a list: pangolinintelligence.com/rep…
For any law enforcement reading this: if you either don't see your jurisdiction listed or something needs correcting, reach out to me (can email [email protected])
For random people reading this: lmk if you find the easter egg 🥚
7/ Somehow we need to start translating this stuff so that crypto devs sitting on top of X million/billion dollars actually start understanding the threat and put resources/people towards protecting themselves.
I would strongly recommend not getting hacked in the first place rather than trying to salvage your project when Marshall Kim is sipping on the Hennessy he bought with your treasury money.
8/ Once you have hired people who can actually understand this graph, please beg them to read the wider research from @blackorbird and Kudelski Security here:
nitter.cf/blackorbird/status/209…
Beyond Lazarus: Organization of DPRK Cyber Capabilities
The old #Lazarus umbrella has been decomposed into six distinct clusters (TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, Famous Chollima) that mix espionage with crypto theft, ransomware, and bank heists.
kudelskisecurity.com/researc…