Stake.com hack — September 2023
Incident facts
| Date of incident | |
|---|---|
| Target type | Gaming or metaverse |
| Loss | $41,300,000Published estimates range $41,000,000 to $41,300,000Price at time of incident |
| Method | Private key compromisehot wallet compromise, described in reporting as a leaked or stolen private key; never confirmed by Stake or the FBI |
| Chains | Ethereum, BNB Chain, Polygon |
| Attributed to | Lazarus Group (APT38), DPRK state cyber actorsConfirmed |
| Outcome | Unresolved |
What happened
Stake.com, an online casino and sports betting platform, lost roughly $41 million from hot wallets on or about 4 September 2023. The FBI published that figure and date in a press release two days later and attributed the theft to the Lazarus Group, also tracked as APT38, which it describes as comprised of DPRK cyber actors. The release listed 33 addresses the stolen funds moved through: four on Ethereum, five on BNB Smart Chain, two on Polygon and 22 Bitcoin addresses.
On-chain investigators including PeckShield and ZachXBT tracked the outflows as they happened and put the total at $41.3 million, split as about $15.7 million on Ethereum and about $25.6 million across BNB Smart Chain and Polygon. Stake said its Bitcoin, Litecoin, XRP, EOS and TRX wallets were untouched, told users their funds were safe, and restored deposits and withdrawals. Co-founder Ed Craven said only a small portion of reserves is held in hot wallets because of the risk.
Neither Stake nor the FBI has stated how the wallets were compromised. Contemporary reporting and later analyses describe a leaked or stolen private key rather than a smart contract flaw, which remains the working assumption rather than an established finding.
TRM Labs traced the laundering: Ethereum and BNB Chain proceeds were swapped into native assets and parked, while the Polygon funds were converted to stablecoins through Squid Router, moved to Avalanche, turned into wrapped Bitcoin and bridged to Bitcoin.
The funds were not recovered and no one has been charged over this theft. OFAC had already sanctioned the Lazarus Group in 2019.
Law enforcement
FBI press release of 6 September 2023 formally attributed the theft to the Lazarus Group / APT38 (DPRK) and published 33 associated wallet addresses. The FBI links the same actors to roughly $200m of 2023 thefts including Alphapo/CoinsPaid and Atomic Wallet. OFAC sanctioned the Lazarus Group in 2019. No arrests or charges specific to this incident.
Sources
- Federal Bureau of InvestigationPrimary · retrieved 2026-08-01
- BleepingComputerSecondary · retrieved 2026-08-01
- TRM LabsSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Stake.com hack — September 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/stake-comhttps://itokenly.com/hacks/stake-comPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.