LockBit hack: 60 000 ransomware bitcoin addresses and negotiation data revealed
A notorious cybercriminal group lost control of its infrastructure to other hackers

08.05.2025 - 10:45
83
3 min
0
What’s new? Nearly 60 000 BTC addresses associated with LockBit’s ransomware infrastructure have been exposed after hackers breached the group’s dark web affiliate panel. Information about the incident spread in the public space after administrative sections on darknet sites associated with LockBit were replaced with a message warning against illegal activities: “Don’t do crime CRIME IS BAD xoxo from Prague.” Along with this, a reference to an archive called “paneldb_dump.zip” was published, which contained a SQL file with data from the MySQL database of the group’s partner network.

The Security Alliance uncovers a scheme to hack crypto wallets via Zoom calls
One of the victims was the head of the NFT platform Emblem Vault
What has been discovered? According to a hacker hiding under the nickname Rey, the leak provides a unique opportunity to study the inner workings of LockBit. Experts from the publication BleepingComputer, having reviewed the contents of the database, reported the discovery of twenty tables. Particular attention was drawn to the table “btc_addresses”, where about 60 000 unique bitcoin addresses were found, which may indicate a significant scope of the group’s activities. In addition, the stolen database also included a “chats” table. This table contained more than 4400 messages of conversations between victims and the ransomware organization.

Guide for crypto companies: how to prevent infiltration through employment
Employees of the Kraken crypto exchange managed to identify a Lazarus Group hacker who claimed to be in a technical position at the company
What else is known? It’s unclear who was behind the hack and how they gained access to LockBit’s operations, but analysts at Bleeping Computer said that the message used in the Everest ransomware website hack matched the message used by LockBit. The analysts suggested there may be a connection between the two incidents.
Address disclosure allows law enforcement and blockchain investigators to track patterns and potentially link past ransom payments to known wallets.
Earlier, the US Department of Justice identified the creator, developer, and administrator of the LockBit group responsible for launching the ransomware.
Useful material?
Crypto regulations
GENIUS aims to regulate dollar-pegged payment stablecoins
Jun 18, 2025
Crypto regulations
Under the new law, no cryptocurrency reserve can be created at the state level
Jun 11, 2025
Mining
This is the 300th block mined within this pool
Jun 5, 2025
Incidents
The marketplace started operating in 2022 and allowed trading in stolen personal data
Jun 5, 2025
Incidents
Hackers laundered assets using Tornado Cash, Thorchain, and Wasabi mixers
Jun 2, 2025
Market
After June 30, fines and prison sentences will be imposed for violating the rules
Jun 2, 2025