CoinsPaid Hacker
“CoinsPaid Hacker” (CoinsPaid hack of July 22, 2023)
In most reporting, “CoinsPaid hacker” does not refer to a publicly identified individual. Rather, it is a shorthand for the threat actor(s) believed to be responsible for the July 22, 2023 theft of roughly USD $37.3 million from CoinsPaid, a cryptocurrency payment processor. (cointelegraph.com)
Alleged attribution: Lazarus Group (North Korea–linked)
CoinsPaid has publicly stated that it suspects the Lazarus Group—a well-known, highly capable hacking group widely described as state-backed and linked to North Korea—based on the observed tactics and laundering patterns. (coinspaid.com)
Important limitation: this attribution is a company assessment / investigative suspicion, and the attackers’ real-world identities (names) are not publicly confirmed in mainstream sources. (csidb.net)
How the attacker(s) reportedly gained access
CoinsPaid and related coverage describe a campaign that relied heavily on social engineering, including:
- fake recruiter/job-offer approaches (e.g., high-salary offers) targeting employees, and
- getting at least one employee to download/install malicious software during a purported “technical test,” enabling access to internal systems. (coinspaid.com)
What happened (high-level)
- Date of theft: July 22, 2023. (csidb.net)
- Amount reported stolen: about $37.3 million. (csidb.net)
- CoinsPaid stated it reimbursed clients and that client funds were not ultimately lost, framing the loss as borne by the company. (theblock.co)
Summary
So, the “CoinsPaid hacker” is best understood as the (still unnamed) attacker(s) behind the CoinsPaid breach, which CoinsPaid and some coverage associate with the Lazarus Group, rather than a single known person. (csidb.net)
Related Bitcoin addresses:
Total 1 addresses.
| Address | Bitcoins | USD |
|---|---|---|
| 38YN2d12PoSZHULQgY4kQtrFMZyba3Uzc3 | $ |