The company explained that the attack occurred when a routine ethereum transfer, from a cold wallet to an online wallet, was manipulated. Manuel Villegas, an analyst at Julius Baer, described the attack as highly sophisticated, highlighting that the manipulation of the cold wallet involved a "blind signature exploit," a method of deception through a fake interface that presented itself as legitimate.

Analysts from Certik, a blockchain analysis firm, described this theft as the largest breach in the history of cryptocurrency transactions. Additionally, the FBI warned that the investigation into the attack continues, and that the stolen funds could be used to finance more malicious activities by North Korea.
The North Korean regime has resorted to cybercrime as one of its main sources of foreign currency, due to the country's economic isolation and the severe international sanctions it has faced.
Despite economic difficulties, Kim Jong-un's regime has managed to make significant advances in its missile and nuclear weapons program. In addition to cyberattacks, North Korea has supplied weapons and troops to Russia, in exchange for money and technology, in the context of Russia's war with Ukraine.
A report from the blockchain analysis firm Chainalysis indicated that hackers linked to North Korea stole more than 1.3 billion dollars in cryptocurrencies in 2024, a significant increase from the 660 million dollars stolen in 2023.












