DEFCON 3 · ELEVATED OBSERVATORY STATUS
04:24:00 UTC
EXPLORE DIRECTORY
LAST SYNCHRONIZED: 2026-08-29 18:30 UTC
incidentcriticalresolved

Singapore Multi-Chain Institutional Bridge $280M Extraction

EXECUTIVE INTELLIGENCE SUMMARY

Social engineering compromise of developer cryptographic signing keys by Lazarus Group leading to massive smart contract treasury liquidation.

Lazarus Group actors established contact with senior protocol engineers via fraudulent recruiter profiles on professional networking networks, transmitting trojanized npm packages that bypassed local static analysis. Upon execution, the payload extracted threshold signature (TSS) shard keys stored in developer environment variables, allowing the attacker to forge withdrawal attestations.

PHASED INCIDENT CHRONOLOGY
PHASE: Discovery2026-08-19 11:20 UTC
Multi-Sig Shard Unauthorized Authorization Transaction

Automated treasury monitor flags $40M batch transfer to unverified tornado mixer address.

PHASE: Legal Action2026-08-21 16:00 UTC
OFAC Sanction Filing & Asset Freezing Orders

US Treasury and Singapore MAS blacklist 14 recipient blockchain addresses.

VERIFIED PROVENANCE TRAIL1 INDEPENDENT ATTESTATIONS
Attribution to DPRK Reconnaissance General Bureau Lazarus sub-group BlueNoroff.
security_lab2026-08-2099% CONFIDENCE
Chainalysis & Mandiant Joint Forensics

On-chain fund clustering matches known Lazarus laundering peel chains.

SOURCE CITATIONS & ATTESTATIONS (1)
OFAC & FBI Cyber AdvisoryUS Treasury OFAC

Identification of Malicious Cyber Addresses Associated with Lazarus

TELEMETRY CARDID: inc-2026-0782
ENTITY TYPE
incident
COORDINATES
1.3521, 103.8198 (Singapore)
INDEXED TAGS
#fintech#cryptocurrency#lazarus#social_engineering#tss_key_theft#smart_contract