Rumors suggest DWF Labs was attacked by the North Korean hacker organization AppleJeus, exposing a theft of $44 million.

MarketWhisper
BTC0,47%
USDC0,03%
YGG-1,64%

On-chain analysts disclosed that the crypto market maker DWF Labs is suspected to have suffered a major cyberattack in September 2022, resulting in losses of up to $44 million. The attack is linked to the North Korean hacker organization AppleJeus, which has previously carried out multiple nation-state cyberattacks targeting the crypto industry. The stolen stablecoins were subsequently converted into Bitcoin (BTC) and transferred via the Mixero mixing service. As of November 2025, DWF Labs has not issued any public statement regarding the incident, raising questions about its transparency and security.

DWF Labs Suspected of Attack by AppleJeus, Losses Exceed $44 Million

On-chain security researchers revealed on X (formerly Twitter) that DWF Labs was targeted by the North Korean hacker organization AppleJeus in September 2022. The attacker compromised address 0x3d67fdE4B4F5077f79D3bb8Aaa903BF5e7642751, stealing a large amount of USDC and USDT stablecoins.

The researcher noted: “This victim address can be directly linked to DWF Labs through transaction history prior to the attack.” According to on-chain data, DWF Labs used this wallet to transfer funds to the vault wallet of Yield Guild Games (YGG) for OTC token purchases. Subsequently, these YGG tokens were sent to a publicly associated address controlled by DWF Labs.

Additionally, on September 15, 2022, DWF Labs announced a strategic partnership with MagnifyCash (formerly NFTY Finance), and the same attack address conducted transactions with that project on the same day, further strengthening the connection.

Attack Details: Private Key Leakage and Multiple Fund Transfers

On-chain data shows that the attacker began transferring assets on September 22, 2022, employing methods such as private key leakage and compromised exchange login credentials.

Funds were stolen continuously over several hours (from 12:04 AM to 5:59 AM), with no successful intervention. Early the next morning (September 23, 2022, at 12:59 AM), an additional transfer occurred.

The stolen assets were then bridged via Ren Protocol to the Bitcoin network, a common “money laundering route” used by AppleJeus hackers. These BTC remained dormant for an extended period until recently being detected as transferred again through the Mixero platform.

Researchers also pointed out that these funds were later mixed with assets stolen from other incidents involving Deribit and Tower Capital to further obscure traces. Currently, over $30 million worth of Bitcoin remains unused.

Despite clear on-chain evidence, DWF Labs has yet to respond publicly, prompting widespread skepticism within the industry. Noted crypto investigator ZachXBT commented, “DWF hiding $44 million being hacked? I’m not surprised at all.”

North Korean Hacker Organization Continues Threats to Global Crypto Industry

This incident highlights the ongoing vulnerabilities in the crypto industry’s cybersecurity. According to a BeInCrypto report, from 2024 to September 2025, North Korean hacker groups have stolen approximately $2.83 billion in digital assets worldwide.

The most notable group is Lazarus, which has orchestrated several major attacks, including breaches of centralized exchanges. These hackers target not only crypto infrastructure but also disguise infiltration of Web3 companies through fake job applications, phishing emails, and malware, expanding their attack scope.

In recent years, North Korean hackers have employed increasingly sophisticated techniques, from social engineering to on-chain mixing and money laundering, demonstrating high technical capabilities. This poses unprecedented challenges to the risk management systems and regulatory transparency of the entire crypto sector.

Industry Impact and Security Lessons

The alleged hacking of DWF Labs serves as a reminder for crypto institutions:

  1. Multi-signature and cold wallet separation remain the primary measures to prevent fund theft;
  2. Timely monitoring of on-chain abnormal transactions is crucial for detecting potential threats;
  3. Transparent and open information disclosure mechanisms can effectively maintain investor trust;
  4. Reviewing transaction histories of partners and project wallets can reduce supply chain attack risks.

Additionally, this incident has prompted regulators to re-examine Market Maker security management systems. As institutional funds continue to flow into crypto, transparency and compliance are becoming essential thresholds for industry survival.

Conclusion

The rumors of DWF Labs suffering a $44 million hack reveal underlying security vulnerabilities and opacity issues within the crypto industry. As nation-state cyberattacks become more frequent, companies that continue to neglect security and compliance will face even greater trust crises. To counteract evolving tactics by North Korean and other hacker groups, strengthening on-chain tracking, enhancing internal risk controls, and increasing security transparency will be key to the sustainable development of the crypto ecosystem.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Scammers Impersonating Iranian Authorities Demand Bitcoin and USDT as Strait Passage Fees; At Least One Vessel Attacked After Payment

Gate News message, April 22 — Scammers posing as Iranian authorities are demanding cryptocurrency payments in Bitcoin or USDT from shipping companies in exchange for safe passage through the Strait of Hormuz, according to CoinDesk. Greek maritime risk firm Marisks has issued a warning that

GateNews11m ago

Michael Saylor's Strategy Realizes 47,079 BTC Gain with 6.2% Return

Gate News message, April 22 — Michael Saylor announced on X that Strategy has realized a gain of 47,079 BTC, representing a 6.2% return valued at approximately $3.6 billion at current prices. Saylor noted that Bitcoin gain (BTC Gain) is the closest measure to net income within a "Bitcoin

GateNews38m ago

Kelp DAO Hacker Transfers Over 106K ETH in 20 Hours, Converts 34.5K ETH to BTC via THORChain

Gate News message, April 22 — The suspected Kelp DAO hacker transferred 106,466 ETH to external wallets over the past 20 hours, according to on-chain data from Arkham. The attacker dispersed the funds across multiple addresses, a common money-laundering technique used to obscure transaction trails.

GateNews1h ago

Polymarket launches sustainable contracts: 10x leverage trading for BTC, NVDA, and gold

Polymarket announced on April 21 that it will launch sustainable contracts. The first batch of underlying assets will be Bitcoin, NVDA, and gold, with up to 10x leverage and 24/7 trading. It is now open to an early-user whitelist. After completing the CFTC DCM registration, it is able to offer long-position futures and perpetual contracts in the United States, with no expiration date. Around the same time, Kalshi announced a competing product, and market rumors suggest that the new round’s financing valuation is too high. Details such as fees, margin, and liquidation are pending publication ahead of the official launch.

ChainNewsAbmedia1h ago

Bitcoin at $79,959 Would Trigger $1.573B in Short Liquidations Across Major CEX

Gate News message, April 22 — According to Coinglass data, if Bitcoin breaks above $79,959, cumulative short liquidations across major centralized exchanges would reach $1.573 billion. Conversely, if BTC falls below $72,483, cumulative long liquidations across major CEX would reach $1.248 billion.

GateNews1h ago

Polymarket Launches Perpetual Contracts Trading for BTC, Gold, NVIDIA, AAPL and More

Polymarket launched perpetual contracts for leveraged long and short trades on assets like gold, BTC, NVIDIA, and AAPL, with early access for registered users.

GateNews1h ago
Comment
0/400
No comments