North Korean Hackers Drain $1.2M From Seedify Bridge

In brief

  • North Korean hackers compromised Web3 gaming incubator Seedify’s cross-chain bridge, draining $1.2 million across BNB Chain networks.
  • The attack exploited a developer’s private key to mint unauthorized SFUND tokens through an audited bridge contract that should have prevented such minting.
  • Blockchain sleuth ZachXbt linked the theft addresses to past North Korean “Contagious Interview” incidents through on-chain analysis

North Korean state-affiliated hacker groups have claimed another victim in the DeFi sector, exploiting Web3 gaming incubator Seedify Fund’s token bridge infrastructure to steal $1.2 million while devastating the platform’s native token SFUND across multiple exchanges.

The attack on Tuesday targeted Seedify’s cross-chain bridge on BNB Chain, allowing hackers to mint unauthorized tokens and systematically drain liquidity pools across Ethereum, Arbitrum, and Base networks before converting proceeds on BNB Chain, the platform said in its official statement.

“The Seedify theft addresses are tied onchain to past Contagious Interview incidents (DPRK),” blockchain sleuth ZachXBT tweeted following the breach, linking the the attack to an ongoing campaign that has claimed over 230 victims between January and March alone, per a recent SentinelLABS intelligence report.

The SFUND token has plunged nearly 35% in the last 24 hours, now trading at $0.28, according to CoinGecko data. It was trading at $0.42 before the hack was reported.

“DPRK/Lazarus decided to take everything we built over 4.5 years in one hack,” Seedify founder Meta Alchemist tweeted in response to the breach.

“The Seedify hack stemmed from a compromised developer key that let DPRK-linked actors mint unauthorized $SFUND tokens via a bridge contract,” Hakan Unal, Senior Security Operations Center Lead at Cyvers, told Decrypt.

“This contract should not have been able to mint these tokens without any token being bridged,” Seedify explained in its official statement, revealing the fundamental vulnerability that allowed unauthorized token creation.

“The hacker wallets connect on-chain to prior DPRK operations, highlighting how aggressive their ongoing rampage across Web3 has become,” Unal explained, recommending platforms monitor on-chain activity and enforce multi-signature approvals.

The crypto industry mobilized quickly in response, with Binance founder Changpeng Zhao (CZ) saying security experts helped freeze $200,000 at HTX exchange, and “the rest seem to remain on-chain.”

‘Contagious Interview’ campaign threat actors operate in “coordinated teams with real-time collaboration, likely using Slack and multiple intelligence sources such as Validin, VirusTotal, and Maltrail” to monitor their infrastructure exposure, SentinelLABS said.

The report also found that despite DPRK hackers “thoroughly examining threat intelligence and identifying artifacts that can be used to discover their infrastructure,” they “did not implement systematic, large-scale changes to make it harder to detect,” instead quickly deploying new infrastructure when disrupted.

“The competitive pressures stemming from North Korea’s annual revenue quotas” drive operatives to protect individual assets and ‘outperform colleagues’ rather than coordinate security improvements,” the cybersecurity firm said.

A recent Cisco Talos intelligence report showed that North Korean groups are continuing to refine their attacks with new malware like “PylangGhost,” targeting crypto professionals through fake Coinbase and Uniswap job postings.

With known DPRK-related losses in 2024 totaling $1.3 billion, the ByBit hack’s $1.5 billion alone has already made 2025 “by far their most successful year to date,” according to Chainalysis’ 2025 Crypto Crime Mid-year Update.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



Source link

Vismaya V

https://decrypt.co/341076/north-korean-hackers-drain-1-2m-from-seedify-bridge

2025-09-24 11:59:00

bitcoin
Bitcoin (BTC) $ 85,696.00 6.38%
ethereum
Ethereum (ETH) $ 2,762.65 9.13%
tether
Tether (USDT) $ 1.00 0.00%
xrp
XRP (XRP) $ 2.02 8.46%
bnb
BNB (BNB) $ 819.17 8.66%
usd-coin
USDC (USDC) $ 0.999892 0.02%
solana
Wrapped SOL (SOL) $ 125.00 9.31%
tron
TRON (TRX) $ 0.276862 2.01%
staked-ether
Lido Staked Ether (STETH) $ 2,763.28 9.02%
dogecoin
Dogecoin (DOGE) $ 0.134514 10.51%
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03 1.15%
cardano
Cardano (ADA) $ 0.379263 11.04%
whitebit
WhiteBIT Coin (WBT) $ 57.43 2.59%
wrapped-steth
Wrapped stETH (WSTETH) $ 3,371.30 9.10%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 85,503.00 6.29%
bitcoin-cash
Bitcoin Cash (BCH) $ 513.69 7.46%
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 2,995.88 9.06%
usds
USDS (USDS) $ 0.999882 0.01%
leo-token
LEO Token (LEO) $ 9.84 0.03%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999491 0.05%
chainlink
Chainlink (LINK) $ 11.96 10.43%
hyperliquid
Hyperliquid (HYPE) $ 29.88 11.51%
weth
WETH (WETH) $ 2,764.76 9.06%
stellar
Stellar (XLM) $ 0.231524 8.17%
monero
Monero (XMR) $ 400.60 3.97%
ethena-usde
Ethena USDe (USDE) $ 0.999352 0.06%
wrapped-eeth
Wrapped eETH (WEETH) $ 2,990.93 9.06%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 85,572.00 6.55%
litecoin
Litecoin (LTC) $ 76.65 8.95%
zcash
Zcash (ZEC) $ 342.32 21.84%
hedera-hashgraph
Hedera (HBAR) $ 0.132626 8.27%
avalanche-2
Avalanche (AVAX) $ 12.73 9.16%
sui
Sui (SUI) $ 1.33 13.88%
shiba-inu
Shiba Inu (SHIB) $ 0.000008 6.25%
dai
Dai (DAI) $ 0.999277 0.02%
world-liberty-financial
World Liberty Financial (WLFI) $ 0.152651 4.13%
susds
sUSDS (SUSDS) $ 1.08 0.12%
paypal-usd
PayPal USD (PYUSD) $ 1.00 0.03%
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.21 0.02%
usdt0
USDT0 (USDT0) $ 0.999648 0.01%
crypto-com-chain
Cronos (CRO) $ 0.100864 7.13%
the-open-network
Toncoin (TON) $ 1.50 6.40%
uniswap
Uniswap (UNI) $ 5.55 10.05%
polkadot
Polkadot (DOT) $ 2.02 11.25%
mantle
Mantle (MNT) $ 0.98114 10.06%
canton-network
Canton (CC) $ 0.078647 10.81%
usd1-wlfi
USD1 (USD1) $ 0.999686 0.04%
aave
Aave (AAVE) $ 166.71 7.78%
bittensor
Bittensor (TAO) $ 260.75 12.33%
bitget-token
Bitget Token (BGB) $ 3.43 5.12%