📈 Get daily crypto insights that make you smarter about your money

CoinStats Security Breach: How Lazarus Group Exploited Infrastructure Vulnerabilities to Steal $2.2 Million

The cryptocurrency portfolio tracking platform CoinStats disclosed a devastating security breach on July 12, 2024, revealing that a sophisticated attacker—attributed to the North Korean-linked Lazarus Group—stole approximately $2.2 million from 1,590 non-custodial CoinStats Wallets. The incident, initially detected on June 22, 2024, exposes critical weaknesses in how third-party infrastructure components can be weaponized against crypto users, even when private keys are supposedly isolated from platform control.

With Bitcoin trading at $59,231 and Ethereum at $3,177 at the time of disclosure, the attack highlights that as the crypto market grows in value, so does the sophistication and ambition of state-sponsored threat actors targeting the ecosystem.

The Exploit Mechanics

The attack vector was multifaceted, exploiting a chain of vulnerabilities across CoinStats’ infrastructure and its third-party service providers. The attackers first gained unauthorized access to parts of CoinStats’ infrastructure, specifically targeting HashiCorp Vault, the secrets management tool that stored CoinStats Wallet 2FA keys (PINs).

With the 2FA keys compromised, the attackers then exploited APIs connected to a third-party wallet-as-a-service provider. This combination allowed them to access the private keys of exactly 1,590 CoinStats Wallets—despite CoinStats maintaining security protocols designed to keep private keys outside the platform’s direct control.

The sophistication of the attack was remarkable. The Lazarus Group used a combination of unauthorized intrusions across multiple services, including systems outside CoinStats’ direct purview. This cross-service exploitation technique represents an evolution in how nation-state actors approach crypto theft, moving beyond simple phishing or single-point vulnerabilities.

Affected Systems

The breach affected only the non-custodial CoinStats Wallet feature—wallets created directly within the CoinStats platform. Importantly, the following remained unaffected:

– Connected external wallets (MetaMask, Phantom, etc.) used for portfolio tracking
– Exchange accounts linked to CoinStats (Binance, Coinbase, etc.)
– Read-only API connections

This segmentation proved crucial in limiting the blast radius. CoinStats only requests read-only access for portfolio tracking of external wallets, meaning the attacker could not leverage the platform to drain funds from connected accounts. However, for the 1,590 users who utilized the built-in CoinStats Wallet feature, the losses were total and immediate.

The Mitigation Strategy

CoinStats’ response was comprehensive and swift. Upon detecting the abnormal activity at approximately 18:00 UTC on June 22, the team immediately took down the entire platform to prevent further exploitation. By 23:00 UTC, they had identified and published the list of affected wallets.

The remediation involved a complete infrastructure rebuild from scratch. No parts of the old production environment were reused. The team migrated to entirely new AWS accounts, severing all connections to compromised third parties. External security experts, including ZachXBT and Tay (Head of Security at MetaMask), were engaged through Security Alliance (SEAL Org) to trace the stolen funds.

Law enforcement and the FBI were also brought in, providing additional forensic capabilities. The platform was fully restored by July 3, 2024, following comprehensive infrastructure audits by top-tier security firms.

Lessons Learned

Several critical lessons emerge from this incident. First, secrets management systems like HashiCorp Vault are only as secure as the infrastructure surrounding them. If an attacker can reach the Vault through lateral movement, the encrypted secrets within become accessible.

Second, third-party dependencies create invisible attack surfaces. Even when a platform maintains proper key isolation, the chain of trust extending to wallet-as-a-service providers introduces risks that may not be fully understood or monitored.

Third, the attribution to Lazarus Group confirms that nation-state actors continue to view cryptocurrency platforms as high-value targets. Their willingness to invest significant resources in multi-stage, cross-platform attacks means that crypto companies must adopt security postures comparable to traditional financial institutions.

User Action Required

If you used a CoinStats Wallet (not a connected external wallet), you should:

1. Verify whether your wallet was among the 1,590 affected addresses published by CoinStats
2. Report losses to local law enforcement and the FBI’s Internet Crime Complaint Center
3. Monitor blockchain explorers for movement of your stolen funds
4. Consider migrating to self-custody solutions where you control the private keys entirely
5. Enable hardware wallet authentication for any remaining crypto holdings

For users of any portfolio tracking platform, this incident serves as a stark reminder: whenever possible, use read-only connections rather than importing wallets via private keys. The convenience of integrated wallets comes with risks that may not be immediately apparent.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research and consult with security professionals regarding cryptocurrency protection.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

23 thoughts on “CoinStats Security Breach: How Lazarus Group Exploited Infrastructure Vulnerabilities to Steal $2.2 Million”

  1. northkorea_aint_playin

    lazarus targeting hashicorp vault is next level. they went after the secrets management layer not individual wallets

    1. hashicorp vault is supposed to be the gold standard for secrets management. if lazarus can crack that, what hope do smaller defi teams have

    2. lazarus going after hashicorp vault instead of individual wallets shows their opsec level. they attacked the trust infrastructure itself

      1. vault_seep_ and nobody talks about how many other apps use hashicorp vault the same way. coinstats was the first to get caught, not the only one exposed

  2. 1590 wallets drained and the attack started june 22 but disclosure was july 12. three weeks of silence is rough

    1. non custodial is supposed to mean they dont have your keys. clearly the 2fa pin storage in vault broke that promise

      1. non custodial means you hold the keys. coinstats holding 2fa pins in a third party vault defeats the entire purpose. buzzword compliance at its finest

        1. incognito_key_

          keyslayer_ storing 2FA pins in hashicorp vault on the server side is the design flaw. non custodial should mean NOTHING leaves the device, including 2FA

        2. keyslayer_ storing 2FA pins outside the user device is basically custodial with extra steps. the branding was the problem

    2. Tomasz Kowal three weeks of silence while wallets drained. at some point transparency has to matter more than investigation time

    3. 3 weeks between detection and disclosure is standard for incident response but brutal for users whose wallets were being drained the whole time

  3. 1387 dollars average per victim across 1590 wallets. for Lazarus thats pocket change. they were testing infrastructure attacks not chasing big scores

  4. Mira Johansson

    lazarus stole 2.2m here. now imagine what they pull from actual exchanges. the numbers must be staggering

  5. 20 days between detection and disclosure is rough. how many wallets got drained in that gap while they investigated

  6. 20 days between detection and disclosure. CoinStats knew wallets were getting drained for three weeks before telling users. thats not investigation thats liability management

  7. storing 2FA pins in hashicorp vault on the server side is the dumbest design choice. non-custodial is a lie when you hold the second auth factor

  8. 20 days between detection and public disclosure. CoinStats knew wallets were getting drained for almost 3 weeks and said nothing. thats not investigation thats cover your ass

  9. Lazarus getting into HashiCorp Vault means every crypto app using shared secrets infrastructure is exposed. this wasnt a coinstats problem it was an industry problem

    1. fjord_rat_ agree. the attack on Vault was the real story. if Lazarus can compromise HashiCorp configs they can hit every DeFi app that uses it

  10. 1590 wallets drained and only 2.2M stolen. averages about 1387 dollars per victim. life-changing money for some, a rounding error for Lazarus

  11. vault_break_analyst

    Lazarus targeting HashiCorp Vault instead of individual wallets is the real story. they attacked trust infrastructure not private keys

  12. disclosure_lag_

    20 days between detection and disclosure is criminal. CoinStats knew wallets were being drained and said nothing for almost 3 weeks while users kept getting phished

  13. Lazarus going after HashiCorp Vault specifically shows they understand infrastructure layers. most crypto teams dont even audit their secrets management setup

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$65,152.00+0.5%ETH$1,923.55+0.5%SOL$76.84+1.3%BNB$604.64+0.4%XRP$1.04+0.1%ADA$0.1976-0.7%DOGE$0.06990.0%DOT$0.8011-1.7%AVAX$6.52+0.7%LINK$8.23-0.8%UNI$4.07+2.3%ATOM$1.38-0.3%LTC$45.61-1.0%ARB$0.0786+0.6%NEAR$1.62+0.1%FIL$0.7063-0.9%SUI$0.6939+0.7%BTC$65,152.00+0.5%ETH$1,923.55+0.5%SOL$76.84+1.3%BNB$604.64+0.4%XRP$1.04+0.1%ADA$0.1976-0.7%DOGE$0.06990.0%DOT$0.8011-1.7%AVAX$6.52+0.7%LINK$8.23-0.8%UNI$4.07+2.3%ATOM$1.38-0.3%LTC$45.61-1.0%ARB$0.0786+0.6%NEAR$1.62+0.1%FIL$0.7063-0.9%SUI$0.6939+0.7%
Scroll to Top