Hackers stole $41m from Stake in movie-worthy heist, CasinoWow investigates the case

In a heist reminiscent of Hollywood thrillers, North Korea’s infamous Lazarus Group is believed to have executed a daring cyberattack on Stake.com, an online casino and sports betting platform, siphoning off $41m in cryptocurrency.

This attack is just another proof of the evolving nature of crime – thieves are now hackers who use sophisticated techniques to exploit digital vulnerabilities. CasinoWow did thorough research on the Stake hack and prepared a full article with all the details that we found astonishing! They also followed the recent global IT outage with predictions of whether this can impact more casinos online. We invited them to share some key details about this heist, learn more about CasinoWow’s research on the Stake attack and get valuable insights into much-needed cybersecurity protection measures.

A movie-like heist in real life

September 4, 2023, was just an ordinary Monday for Stake and its players… or so they thought. The company was unaware that it was the target of a planned cyberattack by hackers. Later, it was believed that behind the hack was the Lazarus Group, an organisation known for its ties to the North Korean government. Within three hours, hackers accessed multiple hot wallets, draining millions of digital assets. It took over four hours for Stake to act on the robbery.

It all began by stealing approximately $16m from Stake’s Ethereum’s hot wallet in different digital assets. The hackers then moved on to Stake’s Binance Smart Chain accounts, seizing an additional $26m in various tokens and stablecoins. The final stage of the heist involved the theft of another $7.8m in tokens, bringing the total to $41m.

So, how did they do it?

Despite the blockchain’s reputation for security, it obviously comes with its own set of vulnerabilities. So, how did the hackers breach Stake’s defences? Though it’s not confirmed, the hackers most likely bypassed technological safeguards by obtaining user accounts and passwords through phishing scams and malware. This speaks volumes about the practice of attacking the weakest link in any technology-based system – the human factor – and the need for more complex security protocols because of it. More about the actual act you can read in CasinoWow’s article.

Finally, laundering the loot

Converting stolen cryptocurrency into usable assets is one of the greatest challenges for cybercriminals. However, the hackers’ group was prepared using a multi-step process to launder the funds. They first converted stablecoins into decentralised cryptocurrencies to avoid asset freezes, then further converted these into other tokens, and finally into Bitcoin. These steps were carried out using the Russian exchange Kucoin, known for its lax regulations regarding illicit funds.

A cybercrime pattern as a way to make money

This heist is just one part of a broader pattern of cyberattacks linked to the Lazarus Group. Recently, it has been connected to a number of other significant heists, including the $54m theft from CoinEx and a $36m attack on Atomic Wallet.

These heists raise critical questions about the security of online casinos and cryptocurrency platforms. CasinoWow thoroughly researched how something like this could happen to Stake and what more is on the cards for online crypto casinos and fiat casinos, preparing a full article with all the details needed!

They also followed the recent global IT outage with predictions of whether this can impact more casinos online. Is it safe to gamble in online casinos? How do you protect your digital assets? Read the full story on CasinoWow’s website.