Singapore Multi-Chain Institutional Bridge $280M Extraction
Social engineering compromise of developer cryptographic signing keys by Lazarus Group leading to massive smart contract treasury liquidation.
Lazarus Group actors established contact with senior protocol engineers via fraudulent recruiter profiles on professional networking networks, transmitting trojanized npm packages that bypassed local static analysis. Upon execution, the payload extracted threshold signature (TSS) shard keys stored in developer environment variables, allowing the attacker to forge withdrawal attestations.
Automated treasury monitor flags $40M batch transfer to unverified tornado mixer address.
US Treasury and Singapore MAS blacklist 14 recipient blockchain addresses.
On-chain fund clustering matches known Lazarus laundering peel chains.
Identification of Malicious Cyber Addresses Associated with Lazarus