T
iTokenly

Rain hack — April 2024

Verified — 5 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMay 13, 2024
Target typeCentralised exchange
Loss$14,800,000Published estimates range $14,800,000 to $16,000,000Price at time of incident
Recovered$760,000
MethodSocial engineeringAccording to a U.S. Justice Department seizure warrant drawing on an investigation by Google's Mandiant, attackers approached a Rain employee on LinkedIn with a fake job offer and sent a coding-challenge file carrying TraderTraitor malware. The malware harvested the credentials and private keys needed to reach Rain's wallets. Outflows then hit Rain's BTC, ETH, SOL and XRP wallets, and the proceeds were pushed through instant exchangers and converted into BTC and ETH.
ChainsBitcoin, Ethereum, Solana, Other
Attributed toLazarus Group (North Korea), operating the TraderTraitor campaignAlleged
OutcomePartially recovered

What happened

Rain, a Bahrain-based exchange licensed in the UAE as a virtual asset broker and custodian, lost about $14.8 million on 29 April 2024. The exchange said nothing publicly for two weeks. The incident only became known on 13 May, when the investigator ZachXBT flagged suspicious outflows from Rain's BTC, ETH, SOL and XRP wallets and traced the proceeds through instant exchangers into BTC and ETH, where they were consolidated into 137.9 BTC and 1,881 ETH and left untouched.

Hours after that post Rain published a statement saying the situation had been resolved, that customer funds remained in custody, fully accounted for and held on a one-to-one basis, and that it had covered any losses arising from the incident. On Rain's account the money taken was operational rather than customer balances.

In December 2024 a U.S. Justice Department seizure warrant, relying on an investigation by Google's Mandiant, set out how the breach happened: North Korea's Lazarus Group contacted a Rain employee on LinkedIn with a fake job offer and sent a coding-challenge file containing TraderTraitor malware, which harvested the credentials and private keys used to access Rain's wallets. That warrant is a prosecutorial filing rather than a proven case, and no defendant has been tried for this theft.

The published totals differ. ZachXBT's on-chain estimate was $14.8 million; reporting on the seizure warrant put the loss at about $16 million. Working with the FBI, Rain traced part of the proceeds to the exchange WhiteBIT, which froze roughly $760,000 in SOL and returned it.

Law enforcement

U.S. Department of Justice seizure warrant filed in 2024 attributing the intrusion to Lazarus Group based on a Mandiant investigation; FBI worked with Rain to trace proceeds, and WhiteBIT froze and returned roughly $760,000 in SOL. No charges specific to this theft have been tried.

Sources

  1. RainPrimary · retrieved 2026-08-01
  2. The BlockSecondary · retrieved 2026-08-01
  3. CoinDeskSecondary · retrieved 2026-08-01
  4. ForbesSecondary · retrieved 2026-08-01
  5. CryptopolitanSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Rain hack — April 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/rain
https://itokenly.com/hacks/rain

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.