The incident occurred back in 2022, but the market maker has yet to publicly confirm or deny the hack

Market maker DWF Labs concealed a $44 million hack. How it happened

05.11.2025

338

6 min

Presumably, in September 2022, market maker DWF Labs fell victim to a hacker attack linked to the North Korean group AppleJeus. As a result of the incident, the attackers stole at least $44 million, mainly in the form of USDC and USDT stablecoins. GetBlock AML Research publishes details of the hack, which went unnoticed.

At the time of publication, DWF Labs has not officially confirmed the hack.

How the theft occurred

On September 22, 2022, one of DWF’s crypto wallets (address: 0x3d67fdE4B4F5077f79D3bb8Aaa903BF5e7642751) began to lose funds. Almost simultaneously, hackers withdrew assets from various exchanges to the same address, which suggests that they managed to gain access to both private keys and exchange account credentials.

Withdrawal of funds from the DWF Labs wallet.

The withdrawal of funds lasted almost 6 hours — from 00:04 to 05:59. During this time, no one was able to stop the transactions or block the wallet. Moreover, the next day, September 23, another transfer was made from the same wallet.

The stolen money was quickly transferred through the Ren Protocol service to convert it from the Ethereum network to bitcoins. After that, the assets remained “motionless” for a long time. Recently, some of these funds began to be transferred to the Mixero bitcoin mixer, where they become even more difficult to track.

Who are AppleJeus?

The AppleJeus group is a hacking unit linked to the North Korean government. It specializes in stealing cryptocurrencies using malware and complex money laundering schemes. They have previously used Ren Protocol and Garden Finance to quickly move stolen assets between the Ethereum and bitcoin networks.

According to researchers, these same hackers were previously behind attacks on the Deribit crypto exchange, Tower Capital investment company, and the Radiant project — all cases are linked by common addresses and signatures.

Why the hack is linked to DWF Labs

The wallet involved in the theft (0x3d67f...) is linked to DWF Labs through several transactions made before the incident. This account, for example, sent money to the Yield Guild Games project treasury, presumably as part of a private deal to purchase YGG tokens. After these transfers, the tokens did indeed arrive in a wallet publicly identified as belonging to DWF Labs.

Connection between the DWF Labs wallet and the Yield Guild Games project.

 Mention of the Yield Guild Games project on the DWF Labs website.

Also, on September 15, 2022, the same address transferred funds to the MagnifyCash project wallet (formerly NFTY Finance), and on the same day, DWF Labs announced a “strategic partnership” with NFTY. This is further confirmation that the wallet belonged to DWF.

Announcement of the partnership between DWF Labs and NFTY.

What happened to the stolen money

At this point, some of the stolen bitcoins have not yet been spent — several large addresses hold assets worth more than $30 million. Some of these bitcoins may have been mixed with other AppleJeus funds to hide the origin of the money.

Diagram of the movement of stolen funds. Source: ZachXBT & TRM Labs.

List of addresses

Subscribe to Getblock Magazine and stay up to date with the latest news from the world of cryptocurrencies and the digital economy