📈 Get daily crypto insights that make you smarter about your money

LockBit Ransomware Cartel Gets Hacked: 60,000 Bitcoin Wallets and 4,400 Negotiation Logs Exposed

The world’s most notorious ransomware-as-a-service operation has suffered a humiliating blow. On May 20, 2025, cybersecurity analysts confirmed that LockBit’s entire dark web infrastructure — including administrative and affiliate control panels — was breached by an unknown party. The defaced panels now display a taunting message: “Don’t do crime, CRIME IS BAD xoxo from Prague,” along with a downloadable MySQL database dump named “paneldb_dump.zip.” The breach exposes the inner workings of a criminal enterprise that has extorted hundreds of millions from victims worldwide.

The Exploit Mechanics

The leaked database was created on April 29, 2025, and extracted from a local development environment running MySQL Server 8.0.41 on Ubuntu 22.04.1. The SQL dump contains 20 database tables that provide an unprecedented look into LockBit’s operations. The breach appears to have exploited weaknesses in LockBit’s own server infrastructure — an ironic twist for a group that built its reputation on exploiting others’ vulnerabilities. Preliminary analysis suggests the attackers gained access to a working backend server, likely through misconfigured access controls or unpatched software.

Affected Systems

The scope of the leaked data is staggering. The “btc_addresses” table lists nearly 60,000 Bitcoin wallet addresses believed to be tied to ransom payments, revealing the massive financial infrastructure behind LockBit’s operation. The “builds” and “builds_configurations” tables detail how LockBit affiliates generated custom ransomware payloads for specific targets, with some entries listing intended victim companies by name. These tables also reveal technical options used during attacks, such as which ESXi servers to avoid and which file types to encrypt. The “chats” table contains 4,442 negotiation messages between LockBit operators and victims, spanning from December 19, 2024, to April 29, 2025. Perhaps most embarrassingly, the “users” table lists 75 individuals with access to the affiliate panel, with passwords stored in plaintext — including credentials as weak as “Lockbitproud231.”

The Mitigation Strategy

While LockBit’s leader, known as “LockBitSupp,” has downplayed the breach by claiming no private keys or critical data were lost, the exposure is significant. Cybersecurity firm Arete, which analyzed the leak, noted that the breach provides actionable intelligence for defenders. Organizations can now cross-reference the 60,000 Bitcoin addresses against their own transaction records to identify potential ransom payments. Law enforcement agencies gain access to affiliate identities and communication patterns. The plaintext passwords can be used to track affiliate activity across other platforms. For the broader ransomware ecosystem, this breach serves as a cautionary tale: even criminal enterprises cannot afford to neglect their own security posture.

Lessons Learned

The LockBit breach reinforces several critical security principles. First, no organization — legitimate or criminal — is immune to supply chain and infrastructure attacks. Second, storing credentials in plaintext is a catastrophic failure at any scale. Third, the breach demonstrates the value of proactive threat intelligence; organizations that monitor dark web leaks can gain early warning of threats targeting their industry. For the cryptocurrency community specifically, the leaked Bitcoin addresses provide a treasure trove of data for blockchain analytics firms tracing illicit fund flows.

User Action Required

Organizations that have previously been targeted by LockBit should review the leaked database to determine if their data appears in negotiation logs or build configurations. Cryptocurrency exchanges and compliance teams should integrate the 60,000 Bitcoin addresses into their screening systems. Security researchers are encouraged to analyze the leaked ransomware build configurations to develop more targeted detection signatures. With Bitcoin trading at approximately $106,791 and the total value of tracked ransom payments potentially reaching hundreds of millions, the financial stakes of this leak cannot be overstated.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always consult with qualified cybersecurity professionals for threat mitigation strategies.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

25 thoughts on “LockBit Ransomware Cartel Gets Hacked: 60,000 Bitcoin Wallets and 4,400 Negotiation Logs Exposed”

  1. breach_autopsy_

    4400 negotiation logs exposed. imagine being a LockBit affiliate and your entire extortion playbook is now public. career over

    1. prague_taunt_fan

      breach_autopsy_ the prague taunt is elite hacker humor. broke in, dumped the db, left a sarcastic note. lockBit got outclassed at their own game

    2. breach_autopsy_ 4400 negotiation logs exposed means every victim can now see what LockBit actually said behind closed doors. the lawsuits from this will be endless

    1. Piotr Zielinski formal verification is great for new contracts but LockBit ran on off the shelf infrastructure. the breach was opssec failure not code vulnerability

  2. 60000 btc wallets from one mysql dump on ubuntu 22.04. ransomware kings running the same stack as a high school vps project

    1. Soren D. mysql 8.0.41 on ubuntu 22.04 for a ransomware cartel. literally the same digitalocean droplet config as every indie dev in berlin

      1. Ranel K. running a ransomware empire on the same digitalocean droplet config as a react tutorial blog. these guys extorted hundreds of millions and skipped a 5 dollar security audit on their own infra

        1. mysql_foreteller_

          Kaspian V. a dev environment exposed to the internet with root mysql credentials is not misconfiguration. its gross negligence. ransomware groups opsec is consistently worse than their victims

          1. mysql_foreteller_ dev environment with root credentials exposed to internet. ransomware kings had worse opsec than a startup intern

  3. MySQL 8.0.41 on Ubuntu 22.04 for a ransomware cartel is hilarious. same stack as every startup in Berlin. criminals cutting corners on infra just like everyone else

  4. 60k bitcoin wallets exposed from one breach. and these are the wallets ransomware operators themselves used. the irony of criminals getting robbed is chef kiss

  5. crypto_forensics

    The irony of ransomware operators getting hacked is delicious. Criminals using poor opsec is poetic justice.

    1. security_architect

      This breach shows that even sophisticated criminal enterprises overlook basic security hygiene. The MySQL dump exposure was preventable.

  6. 60k Bitcoin wallets exposed proves no system is truly secure. It’s a constant cat-and-mouse game between attackers and defenders.

    1. breach_autopsy_ the Prague taunt is what kills me. someone broke in, dumped the db, and left a sarcastic note. LockBit literally got out-trolled

      1. Klaudia W. the prague taunt is peak hacker energy. broke their entire operation and left a love note

  7. 60000 bitcoin wallets exposed and nobody has traced whether any of them have moved since the dump. thats the real story. watch the chain not the leak

    1. chain_trace_kep

      Leona S. 60000 btc wallets and nobody tracking movements. chain analysis firms should be all over this dump

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,175.00+0.1%ETH$2,511.82+2.2%SOL$101.59+1.9%BNB$733.24+2.4%XRP$1.36+1.1%ADA$0.2075-1.2%DOGE$0.0843+0.4%DOT$1.05-7.9%AVAX$7.45-0.8%LINK$11.51-0.1%UNI$6.17-0.2%ATOM$1.64-7.2%LTC$53.79+1.8%ARB$0.1409-4.4%NEAR$2.35-4.5%FIL$0.7996+0.7%SUI$0.7227-2.2%BTC$77,175.00+0.1%ETH$2,511.82+2.2%SOL$101.59+1.9%BNB$733.24+2.4%XRP$1.36+1.1%ADA$0.2075-1.2%DOGE$0.0843+0.4%DOT$1.05-7.9%AVAX$7.45-0.8%LINK$11.51-0.1%UNI$6.17-0.2%ATOM$1.64-7.2%LTC$53.79+1.8%ARB$0.1409-4.4%NEAR$2.35-4.5%FIL$0.7996+0.7%SUI$0.7227-2.2%
Scroll to Top