📈 Get daily crypto insights that make you smarter about your money

3CX Supply Chain Attack Exposes Millions to Crypto Wallet Theft

The cybersecurity landscape shifted dramatically on March 29, 2023, when multiple vendors disclosed a massive supply chain attack targeting the 3CX DesktopApp, a widely-used voice and video conferencing platform serving approximately 12 million users worldwide. The campaign, dubbed “Smooth Operator” by researchers, represents one of the most significant supply chain compromises in recent memory and carries direct implications for cryptocurrency holders and financial institutions.

The Exploit Mechanics

Attributed to North Korea’s Lazarus Group—the same state-sponsored collective responsible for stealing an estimated $1.7 billion in cryptocurrency from major financial institutions—the attack began with the infiltration of a 3CX developer’s workstation. The threat actors replaced two dynamic link libraries (DLLs) in the daily software build, including one masquerading as Microsoft’s legitimate d3dcompiler.exe. The trojanized updates were then distributed to users at an alarming rate of roughly 2,000 installations per minute.

The compromised software functioned normally on the surface, but behind the scenes, a sophisticated backdoor opened pathways for data exfiltration. The malware specifically targeted usernames, passwords, and critically, cryptocurrency wallet credentials stored on infected machines. Security researchers later identified the Gopuram backdoor as a key component, a modular tool capable of stealing data, installing additional malware, and maintaining persistent access to compromised systems.

Affected Systems

The scale of the breach was staggering. The 3CX DesktopApp is used by over 350,000 organizations globally, including financial institutions, cryptocurrency exchanges, and enterprises handling sensitive digital asset operations. With Bitcoin trading at approximately $28,348 and Ethereum at $1,793 at the time of the attack, the potential for cryptocurrency theft from exposed wallets was immense.

Crypto-related companies were specifically targeted. The Lazarus Group, which has a well-documented history of targeting cryptocurrency exchanges and DeFi protocols, appeared to be using the 3CX compromise as a means to gain access to cryptocurrency wallets and exchange credentials across a broad swath of the financial technology sector.

The Mitigation Strategy

CrowdStrike first flagged suspicious activity through a Reddit channel before publishing a formal advisory. SentinelOne and Sophos quickly followed with their own analyses. By March 30, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a formal alert recommending that all organizations immediately uninstall the 3CX DesktopApp and switch to the Progressive Web Application (PWA) client.

Notably, Palo Alto Networks’ Cortex XDR platform had autonomously blocked the malicious software days before the public disclosure, thanks to its AI-based shellcode detection module. The platform’s behavioral analysis recognized that code was loading into memory through unconventional means—a pattern that thousands of legitimate applications use, but one that the AI correctly identified as anomalous in this context based on training across billions of samples.

MITRE assigned CVE-2023-29059 to the vulnerability, categorizing it under CWE-506 for Embedded Malicious Code, providing organizations with a standardized reference for tracking and managing their exposure to this threat.

Lessons Learned

The 3CX incident underscores several critical realities for the cryptocurrency sector. First, supply chain attacks represent an escalating threat vector that bypasses traditional perimeter defenses. When trusted, legitimately signed software becomes a delivery mechanism for malware, conventional security measures prove inadequate. Second, the involvement of a nation-state actor specifically targeting crypto wallets demonstrates that digital assets remain a primary objective for sophisticated threat groups.

Organizations that had implemented behavioral threat detection and zero-trust principles fared significantly better than those relying solely on signature-based antivirus solutions. The speed at which the malicious update propagated—thousands of endpoints per minute—highlights the importance of automated, AI-driven response capabilities.

User Action Required

If you or your organization used the 3CX DesktopApp between March 16 and March 29, 2023, take immediate action. Uninstall the application and switch to the PWA client. Rotate all passwords and API keys that may have been exposed on machines running the compromised software. For cryptocurrency holders specifically: move funds from any wallet whose private keys or seed phrases were stored on or accessible from an affected machine. Enable hardware wallet authentication for significant holdings, and review transaction histories for any unauthorized activity. The Lazarus Group’s operational tempo suggests they move quickly once they obtain credentials, making rapid response essential.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making financial decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

25 thoughts on “3CX Supply Chain Attack Exposes Millions to Crypto Wallet Theft”

  1. 2000 installs per minute of trojanized software. let that sink in. lazarus really out here weaponizing the update pipeline itself

    1. $1.7 billion stolen by Lazarus and they just keep finding new attack vectors. supply chain is the hardest to defend against because you trust the software

      1. Lazarus has stolen an estimated $1.7B in crypto and they keep finding new supply chain vectors. the next 3CX is already in some build pipeline

        1. lazarus has been the most consistent threat to crypto since 2017. 1.7B stolen and their playbook keeps expanding

    2. weaponizing the update pipeline is the ultimate supply chain attack. you literally cannot defend against it unless you hash verify every binary

      1. hash verify every binary is the only defense but nobody does it. IT departments auto-approve vendor updates because there are too many to check manually

    3. patch_paranoia

      blue_team_lee_ 2000 per minute and most of those installs were enterprise IT departments who auto-approve vendor updates. the blast radius was insane

  2. 2000 installs per minute of trojanized software. Lazarus turned the update channel into the largest malware distribution network for a full day

    1. 12 million users on 3CX and Lazarus compromised the build pipeline. two thousand installs per minute of malware disguised as a compiler update

  3. My company uses 3CX for internal comms. IT sent out an emergency patch notice at 2AM. This was the real deal, not a drill.

  4. Anders H. and the worst part is 3CX did nothing wrong initially. they got compromised first. supply chain attacks cascade through no fault of the end user

  5. dll_inspector

    masquerading as d3dcompiler.exe is a classic move. sad thing is the DLL was legitimately signed so endpoint protection had no reason to flag it

    1. supply_chain_nightmare_

      dll_inspector the DLL was legitimately signed which means every endpoint tool waved it through. the entire signature based trust model is broken

    2. signed DLLs passing endpoint checks is nightmare fuel. this is why zero trust has to extend to your own software supply chain

    3. signed DLL passing endpoint protection is the real nightmare. the entire trust model assumes signatures mean safe and lazarus exploited that perfectly

      1. dll_paranoid_

        the trojanized DLL was legitimately signed so every endpoint tool waved it through. the entire signature based trust model collapsed in one attack

        1. dll_paranoid_ the signed DLL bypassing every EDR is the scariest part. vendor signatures are trusted by default and lazarus knew it

  6. switched our entire org to Element + self-hosted Jitsi after this. took 2 weeks of migration pain but never trusting a vendor build pipeline again

  7. 2,000 installs per minute of trojanized 3CX updates. the speed of that distribution is what made it devastating. nobody checks hashes on auto-updates

    1. 2000 installs per minute of a trojanized update. our SOC team was working around the clock for a week straight after this

  8. build_signed_

    2,000 installs per minute of a trojanized DLL and 3CX didnt notice until researchers flagged it. supply chain security is fundamentally broken

    1. build_signed_ the scariest part is the DLL was legitimately signed. every endpoint tool trusted it because the signature was valid

      1. incident_resp_

        build_signed_ the DLL being legitimately signed is the detail that keeps me up at night. every security model that trusts vendor signatures broke that day

  9. Lazarus going from crypto exchange hacks to compromising software build pipelines is a serious escalation. the $1.7B figure is probably low

    1. nom___hash 1.7B is the tracked number. unlabeled lazus wallets probably hold double that. they fund the next attack with the last heist

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,707.00-0.3%ETH$1,911.45-0.1%SOL$75.75+2.4%BNB$600.50+1.5%XRP$1.03+0.2%ADA$0.1981-1.4%DOGE$0.0698-0.2%DOT$0.8121-0.9%AVAX$6.44-1.2%LINK$8.26+0.8%UNI$3.95-1.3%ATOM$1.38+0.9%LTC$45.86+0.7%ARB$0.0780-0.3%NEAR$1.61+0.9%FIL$0.7086+2.5%SUI$0.6882+1.6%BTC$64,707.00-0.3%ETH$1,911.45-0.1%SOL$75.75+2.4%BNB$600.50+1.5%XRP$1.03+0.2%ADA$0.1981-1.4%DOGE$0.0698-0.2%DOT$0.8121-0.9%AVAX$6.44-1.2%LINK$8.26+0.8%UNI$3.95-1.3%ATOM$1.38+0.9%LTC$45.86+0.7%ARB$0.0780-0.3%NEAR$1.61+0.9%FIL$0.7086+2.5%SUI$0.6882+1.6%
Scroll to Top