T
iTokenly

Stake.com hack — September 2023

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Target typeGaming or metaverse
Loss$41,300,000Published estimates range $41,000,000 to $41,300,000Price at time of incident
MethodPrivate key compromisehot wallet compromise, described in reporting as a leaked or stolen private key; never confirmed by Stake or the FBI
ChainsEthereum, BNB Chain, Polygon
Attributed toLazarus Group (APT38), DPRK state cyber actorsConfirmed
OutcomeUnresolved

What happened

Stake.com, an online casino and sports betting platform, lost roughly $41 million from hot wallets on or about 4 September 2023. The FBI published that figure and date in a press release two days later and attributed the theft to the Lazarus Group, also tracked as APT38, which it describes as comprised of DPRK cyber actors. The release listed 33 addresses the stolen funds moved through: four on Ethereum, five on BNB Smart Chain, two on Polygon and 22 Bitcoin addresses.

On-chain investigators including PeckShield and ZachXBT tracked the outflows as they happened and put the total at $41.3 million, split as about $15.7 million on Ethereum and about $25.6 million across BNB Smart Chain and Polygon. Stake said its Bitcoin, Litecoin, XRP, EOS and TRX wallets were untouched, told users their funds were safe, and restored deposits and withdrawals. Co-founder Ed Craven said only a small portion of reserves is held in hot wallets because of the risk.

Neither Stake nor the FBI has stated how the wallets were compromised. Contemporary reporting and later analyses describe a leaked or stolen private key rather than a smart contract flaw, which remains the working assumption rather than an established finding.

TRM Labs traced the laundering: Ethereum and BNB Chain proceeds were swapped into native assets and parked, while the Polygon funds were converted to stablecoins through Squid Router, moved to Avalanche, turned into wrapped Bitcoin and bridged to Bitcoin.

The funds were not recovered and no one has been charged over this theft. OFAC had already sanctioned the Lazarus Group in 2019.

Law enforcement

FBI press release of 6 September 2023 formally attributed the theft to the Lazarus Group / APT38 (DPRK) and published 33 associated wallet addresses. The FBI links the same actors to roughly $200m of 2023 thefts including Alphapo/CoinsPaid and Atomic Wallet. OFAC sanctioned the Lazarus Group in 2019. No arrests or charges specific to this incident.

Sources

  1. Federal Bureau of InvestigationPrimary · retrieved 2026-08-01
  2. BleepingComputerSecondary · retrieved 2026-08-01
  3. TRM LabsSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Stake.com hack — September 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/stake-com
https://itokenly.com/hacks/stake-com

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.