BNB Whale Drained of $27M in DPRK-Linked Phishing Attack

In brief

  • A Binance Smart Chain user fell victim to a phishing scam and lost $27 million worth of tokens on Tuesday.
  • Early reports suggested that BNB lending platform Venus Protocol had been hacked, but blockchain security firms subsequently confirmed that this was not the case.
  • Venus Protocol and security firm PeckShield are in contact with the victim and are attempting to recover the funds that still sit in the attacker’s wallet.

A user on the Binance Smart Chain has lost $27 million to a phishing scam, according to security experts and those who have spoken with the victim. Several groups are now working with the victim and are attempting to recover the funds.

Early reports indicated that BNB lending protocol Venus Protocol had been hacked, due to the funds being held in Venus wrapper tokens for USDT and USDC. However, blockchain security firm Cyvers and Venus Protocol confirmed to Decrypt that the lending platform is not compromised—meaning the assets of other Venus users are safe.

PeckShield, another security company, also confirmed to Decrypt that it was a phishing scam, that the firm is in contact with the victim, and is working to recover the funds.

Venus Protocol community delegate Danny Cooper dismissed reports that the lending protocol had been hacked as “fake news,” telling Decrypt that, “A user falling victim to a phishing attack does not mean the protocol was drained. It was the user’s wallet that got compromised, not Venus.”

Cooper added that initial analysis from security firm ZeroShadow suggests that the “attack fingerprint” strongly points to the attackers being from the Democratic People’s Republic of Korea.

North Korean scammers are rife in crypto, with centralized exchange Binance claiming it fends off phishing attempts from the region every single day. Lazarus Group, one of the most notorious hacker outfits in the world, is located in North Korea. According to the FBI, the group was responsible for the infamous $1.4 billion Bybit hack in March—the largest hack in crypto history.

How phishing scams work

Phishing scams involve tricking users into approving malicious transactions by imitating trusted platforms. “They succeed because they exploit human trust and urgency,” Hakan Unal, Senior Security Operations Center Lead at Cyvers, told Decrypt, adding that they usually take place during airdrops and token launches.

According to Cyvers, the attack likely came at the hands of a website that looked like a trusted site, with minor changes in the domain. The victim then approved a malicious transaction, which resulted in their funds being drained from their wallet.

Following the suspicious transfer, Cooper said, Venus Protocol’s security mechanism was triggered, and the protocol was paused. He said this appears to have prevented the attacker from moving the Venus wrapped tokens from their wallet.

Venus Protocol is also in contact with the victim and is working with several security partners, including Binance Security, HexaGate, ChaosLabs, and ZeroShadow, to help recover the funds. However, Cooper explained, the team isn’t 100% certain that recovery will be possible at this moment.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



Source link

Ryan Gladwin

https://decrypt.co/337685/bnb-whale-drained-of-27m-in-dprk-linked-phishing-attack

2025-09-02 13:16:00

bitcoin
Bitcoin (BTC) $ 84,674.00 7.30%
ethereum
Ethereum (ETH) $ 2,733.92 9.82%
tether
Tether (USDT) $ 1.00 0.00%
xrp
XRP (XRP) $ 1.99 9.42%
bnb
BNB (BNB) $ 812.20 9.20%
usd-coin
USDC (USDC) $ 0.999801 0.00%
tron
TRON (TRX) $ 0.275939 2.32%
staked-ether
Lido Staked Ether (STETH) $ 2,734.57 9.75%
dogecoin
Dogecoin (DOGE) $ 0.132764 11.33%
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03 1.15%
cardano
Cardano (ADA) $ 0.375178 11.56%
whitebit
WhiteBIT Coin (WBT) $ 57.20 2.80%
wrapped-steth
Wrapped stETH (WSTETH) $ 3,338.86 9.70%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 84,491.00 7.14%
bitcoin-cash
Bitcoin Cash (BCH) $ 510.14 8.10%
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 2,962.38 9.81%
usds
USDS (USDS) $ 0.999812 0.00%
leo-token
LEO Token (LEO) $ 9.81 0.09%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999733 0.02%
chainlink
Chainlink (LINK) $ 11.81 11.17%
hyperliquid
Hyperliquid (HYPE) $ 29.51 12.52%
weth
WETH (WETH) $ 2,735.80 9.72%
stellar
Stellar (XLM) $ 0.227988 9.30%
monero
Monero (XMR) $ 393.72 5.03%
ethena-usde
Ethena USDe (USDE) $ 0.998598 0.06%
wrapped-eeth
Wrapped eETH (WEETH) $ 2,959.54 9.74%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 84,765.00 7.20%
litecoin
Litecoin (LTC) $ 75.73 9.76%
hedera-hashgraph
Hedera (HBAR) $ 0.130798 9.29%
avalanche-2
Avalanche (AVAX) $ 12.64 9.63%
zcash
Zcash (ZEC) $ 326.83 25.12%
sui
Sui (SUI) $ 1.32 14.61%
shiba-inu
Shiba Inu (SHIB) $ 0.000008 7.18%
dai
Dai (DAI) $ 0.999391 0.02%
world-liberty-financial
World Liberty Financial (WLFI) $ 0.151951 4.59%
susds
sUSDS (SUSDS) $ 1.08 0.56%
paypal-usd
PayPal USD (PYUSD) $ 0.999635 0.03%
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.21 0.02%
usdt0
USDT0 (USDT0) $ 0.99984 0.01%
crypto-com-chain
Cronos (CRO) $ 0.099642 7.91%
the-open-network
Toncoin (TON) $ 1.48 7.88%
uniswap
Uniswap (UNI) $ 5.47 10.98%
polkadot
Polkadot (DOT) $ 1.99 12.22%
mantle
Mantle (MNT) $ 0.96597 11.47%
canton-network
Canton (CC) $ 0.078183 12.26%
usd1-wlfi
USD1 (USD1) $ 0.999574 0.03%
aave
Aave (AAVE) $ 163.32 9.32%
bittensor
Bittensor (TAO) $ 256.71 12.76%
bitget-token
Bitget Token (BGB) $ 3.43 5.15%
memecore
MemeCore (M) $ 1.39 0.73%