T
iTokenly

Solareum hack — March 2024

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident(approximate)
Publicly disclosedMarch 29, 2024
Target typeWallet software or provider
Loss$1,400,000Published estimates range $523,000 to $1,400,000Price at time of incident
MethodInsider actionUS prosecutors allege a developer hired onto the Solareum team in December 2023, working covertly for North Korea, used their access to drain the private keys Solareum custodied for users of its Solana Telegram trading bot. At the time the team gave no technical account of the breach, attributing the drains instead to a broader exploit said to be affecting various bot projects and dApps; the insider account emerged later.
ChainsSolana
Attributed toNorth Korean IT worker hired by Solareum, per US prosecutorsAlleged
OutcomeProject shut down

What happened

On or about 29 March 2024 the wallets of users of Solareum, a Telegram trading bot for Solana, were emptied. Solareum custodied trading keys, and many victims had imported private keys previously exported from other bots. BONKbot, which ran its own analysis of the drained accounts, said 113 of its users were affected and that the exploit came from those victims importing private keys into a specific application, while stating it could not tell whether the cause was an external breach or an internal drain; it later told Decrypt the analysis pointed to Solareum. Decrypt reported about $523,000 taken from more than 300 users at the time, and The Crypto Times put it at over 2,800 SOL, roughly $520,000. Solareum acknowledged a security breach but gave no technical explanation, instead attributing the drains to a broader exploit said to be affecting various bot projects and dApps. On 30 March it announced it would shut down, citing insufficient funds, evolving market trends and the breach, and offered no compensation. It denied orchestrating an exit scam.

Later accounting is substantially higher. DL News, reviewing a US Department of Justice filing of 21 January 2025 in which Solareum appears as 'US Company 1', reported that prosecutors put the theft at 6,045 SOL, about $1.4 million, and attributed it to a developer the team had onboarded in December 2023 who was in fact working for North Korea. Individual reported losses ranged from $30,000 to more than $200,000. The gap between the two figures appears to reflect an incomplete early count rather than a genuine dispute.

The stolen SOL was converted to USDT and moved through HTX, Binance, MEXC, EasyBit and FixedFloat. MetaMask security lead Taylor Monahan, who suspected DPRK involvement because on-chain flows and indicators overlapped heavily with earlier IT-worker thefts, persuaded Tether to freeze funds on 30 March 2024; the FBI seized roughly $950,000 about two months later. The North Korean attribution is the prosecutors' allegation and remains unproven in court.

Law enforcement

Tether froze the converted USDT on 30 March 2024 after researchers presented on-chain evidence; the FBI seized approximately $950,000 in USDT in May 2024. A US Department of Justice court filing dated 21 January 2025, in which Solareum appears as 'US Company 1', attributes the theft of 6,045 SOL to a DPRK IT worker. No one has been convicted of this theft.

Sources

  1. DL NewsSecondary · retrieved 2026-08-01
  2. DecryptSecondary · retrieved 2026-08-01
  3. The Crypto TimesSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Solareum hack — March 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/solareum
https://itokenly.com/hacks/solareum

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.