DWF Labs, a market-making firm active in crypto markets, has been linked to an alleged loss of $44 million in a hack that took place in September 2022. Related Reading: Trump Warns Of China’s Crypto Surge, Calls For US To Take Lead According to on-chain investigators, the incident was not publicly disclosed by the firm […]DWF Labs, a market-making firm active in crypto markets, has been linked to an alleged loss of $44 million in a hack that took place in September 2022. Related Reading: Trump Warns Of China’s Crypto Surge, Calls For US To Take Lead According to on-chain investigators, the incident was not publicly disclosed by the firm […]

Crypto Firm DWF Labs Lose $44M To North Korean-Linked Hackers – Report

2025/11/06 11:00

DWF Labs, a market-making firm active in crypto markets, has been linked to an alleged loss of $44 million in a hack that took place in September 2022.

According to on-chain investigators, the incident was not publicly disclosed by the firm at the time and only came to light after a detailed blockchain review.

DWF Labs: Alleged Attack And Method

Reports have disclosed that the attacker drained a wallet tied to DWF Labs and moved the funds through several on-chain steps.

The stolen holdings were mostly stablecoins — USDC and USDT — and were then converted into Bitcoin through the Ren bridge before being routed into a mixer called Mixero.

The pattern of transfers and the tools used are what led some analysts to suggest a link to the DPRK-associated AppleJeus group.

On-Chain Evidence And Reactions

Based on reports, the investigation was driven by an analyst known as tanuki42 who flagged the wallet address and traced payments made to and from it before and after the alleged breach.

Other sleuths on X, including well-known chain trackers, began to comment and share findings. Some posts pointed to roughly $30 million in Bitcoin-valued pots that have not been touched since the transfers, raising questions about what the attacker intends to do next.

DWF Labs has not posted a public incident report or a formal acknowledgement of the claims.

What The Movement Looks Like

Money moved into centralized exchanges at certain points, which suggests private keys or exchange accounts may have been compromised during the event.

After conversion, the flow into a mixer makes it harder to follow the exact trail, but on-chain records show the sequence and timestamps that tie these steps to the September dates.

The way funds were handled is similar to other cases tied to state-linked threat actors, according to the analysts studying the chain.

Potential Impact And Next Steps

If the allegation is confirmed by an independent audit or by the firm itself, the fallout could affect counterparties and projects that relied on DWF Labs for liquidity.

Some forensic firms and trackers are poring over the dormant pots of Bitcoin that amount to about $30 million in current value, while exchanges and law-enforcement partners may be asked to help trace or freeze moves if they occur.

Investor confidence is part of the discussion now, because public trust depends on clear disclosure and rapid response once a breach is found.

Featured image from Unsplash, chart from TradingView

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Let insiders trade – Blockworks

Let insiders trade – Blockworks

The post Let insiders trade – Blockworks appeared on BitcoinEthereumNews.com. This is a segment from The Breakdown newsletter. To read more editions, subscribe ​​“The most valuable commodity I know of is information.” — Gordon Gekko, Wall Street Ten months ago, FBI agents raided Shayne Coplan’s Manhattan apartment, ostensibly in search of evidence that the prediction market he founded, Polymarket, had illegally allowed US residents to place bets on the US election. Two weeks ago, the CFTC gave Polymarket the green light to allow those very same US residents to place bets on whatever they like. This is quite the turn of events — and it’s not just about elections or politics. With its US government seal of approval in hand, Polymarket is reportedly raising capital at a valuation of $9 billion — a reflection of the growing belief that prediction markets will be used for much more than betting on elections once every four years. Instead, proponents say prediction markets can provide a real service to the world by providing it with better information about nearly everything. I think they might, too — but only if insiders are free to participate. Yesterday, for example, Polymarket announced new betting markets on company earnings reports, with a promise that it would improve the information that investors have to work with.  Instead of waiting three months to find out how a company is faring, investors could simply watch the odds on Polymarket.  If the probability of an earnings beat is rising, for example, investors would know at a glance that things are going well. But that will only happen if enough of the people betting actually know how things are going. Relying on the wisdom of crowds to magically discern how a business is doing won’t add much incremental knowledge to the world; everyone’s guesses are unlikely to average out to the truth. If…
Share
BitcoinEthereumNews2025/09/18 05:16