EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/kucoin-hack-2020
192/430

File EL-0239CriticalResolvedData Breach / Financial Theft

KuCoin Hack

Also filed as KuCoin Exchange Breach · KuCoin Theft

The KuCoin hack was a major cryptocurrency theft event that occurred in September 2020, resulting in the unauthorized draining of significant funds from the exchange. The attack was attributed to the Lazarus Group, a sophisticated, state-sponsored hacking collective. The incident highlighted the vulnerability of major crypto exchanges to nation-state level financial crime.

  • #kucoin
  • #lazarus-group
  • #cryptocurrency
  • #hacking
  • #exchange-breach
  • #theft
Notoriety8/10
Event
26 Sept 2020
Disclosed
26 Sept 2020
Target
KuCoin Exchange
Actor
Lazarus Group
Scale
Multiple large transactions (Specific amount varies by report)
Status
Resolved

01Summary

The breach occurred when the Lazarus Group successfully compromised the internal systems of the KuCoin exchange. The attackers utilized sophisticated methods to bypass security controls, allowing them to access and transfer vast amounts of cryptocurrency. The theft was characterized by its scale and the apparent coordination required to move funds across multiple wallets and exchanges. While the exact initial vector remains debated, the successful exfiltration of funds demonstrated a high level of operational security and technical capability, marking it as a significant financial blow to the exchange. The incident prompted immediate industry-wide scrutiny regarding the security protocols and custodial practices of major cryptocurrency platforms.

02Background

The cryptocurrency exchange market has become a primary target for state-sponsored actors due to the pseudonymous and borderless nature of digital assets. Historically, exchanges have been vulnerable to internal fraud or external hacking, but the scale of the KuCoin theft suggested a highly resourced, nation-state level operation. This incident contributed to the growing regulatory push for stricter security standards within the crypto industry.

03Key revelations

  1. 01The successful theft demonstrated the vulnerability of centralized crypto exchanges to nation-state actors.
  2. 02The attackers utilized sophisticated techniques to obfuscate the trail of the stolen funds across multiple blockchains.
  3. 03The incident prompted calls for greater regulatory oversight and enhanced security standards across the entire crypto industry.

04Technical analysis

The attack likely involved compromising private keys or internal API credentials. The methodology suggests a multi-stage operation: initial access, lateral movement to the core treasury management system, and finally, the execution of multiple withdrawal transactions. The use of multiple intermediary wallets suggests an attempt to obfuscate the trail of the stolen funds, a common tactic used by advanced persistent threat groups.

Attack vector
Compromise of internal systems/API keys (Likely)
Attack method
Financial Theft / Exfiltration
Initial access
Credential Theft / System Compromise
Lateral movement
Internal Network Access
Persistence
Backdoors / API Key Manipulation
Exfiltration
Blockchain Transactions
Malware type
Stealer / Exfiltration

MITRE ATT&CK techniques

  • T1566.001

05Threat actor

The Lazarus Group is widely believed to be a unit operating under the direction of North Korea's state intelligence apparatus. They are known for their highly professional, multi-faceted attacks, targeting financial institutions, intellectual property, and critical infrastructure for state revenue generation.

Aliases

  • APT31
  • Hidden Cobra

APT designations

  • Lazarus Group

MITRE groups

  • T1566.001

Attribution sources

  • Chainalysis
  • CoinMetrics
  • Security Researchers

06Victims and impact

Countries affected

  • Global

07Data exposed

Data types

  • Cryptocurrency Assets
  • Private Keys

08Financial damage

The total loss was measured in tens of millions of USD, representing a significant portion of the exchange's liquid assets.

09Timeline

  1. 2020-09-26The breach is detected, and the theft of funds begins.
  2. 2020-09-26KuCoin publicly acknowledges the hack and the scale of the loss.

10Reaction and fallout

Public reaction

The public reaction was one of alarm and increased skepticism regarding the security of centralized crypto exchanges. Many investors were advised to increase their personal security measures, such as using hardware wallets and diversifying custody.

Political impact

The hack intensified global regulatory discussions, particularly in jurisdictions like the EU and US, pushing for clearer legal frameworks and mandatory security audits for crypto platforms.

Geopolitical consequences

It reinforced the narrative that cryptocurrency markets are a primary vector for state-sponsored financial warfare, increasing geopolitical tension between nations and private financial entities.

11Legal

No specific criminal charges were filed against the Lazarus Group, as they are a state-sponsored entity. However, the incident contributed to increased international cooperation among law enforcement agencies targeting crypto crime.

12Aftermath

Policy changes

  • Increased calls for mandatory cold storage and multi-signature requirements for exchange treasuries.

Regulatory changes

  • Increased scrutiny from financial regulators (e.g., SEC, FCA) regarding custody and operational risk.

Security improvements

  • Adoption of advanced multi-signature wallet schemes.
  • Implementation of real-time, AI-driven anomaly detection for large withdrawals.

13Significance and legacy

Significance

The KuCoin hack is a landmark case demonstrating the operational reach and financial capability of modern nation-state cybercrime groups. It shifted the focus of crypto security from simple perimeter defense to complex internal systemic risk management, forcing the industry to acknowledge state-level threats.

Legacy

The incident accelerated the development of decentralized finance (DeFi) concepts as a perceived hedge against the systemic risk posed by centralized exchanges. It also spurred significant investment in blockchain forensics and threat intelligence services.

14Disclosure and media

Authentication
Blockchain Transaction Analysis

Media partners

  • CoinDesk
  • The Block
  • Reuters

Publishing organisations

  • Security Research Firms

15Related files

Related events

  • Ronin Bridge Hack (2022)
  • Bangladesh Bank Heist (2016)

16Field notes

  1. 01The Lazarus Group is known for targeting financial institutions globally, not just crypto exchanges.
  2. 02The complexity of the fund movement required multiple specialized blockchain analysis firms to trace the assets.

17Resolution

KuCoin eventually recovered and stabilized, but the incident served as a permanent warning regarding the risks associated with centralized custody of digital assets.

18Sources

References

  1. [1]Chainalysis Reports
  2. [2]CoinMetrics Analysis
Fact sheetEL-0239

Dates

Event
26 Sept 2020
Started
26 Sept 2020
Ended
26 Sept 2020
Duration
1 days
Discovered
26 Sept 2020
Disclosed
26 Sept 2020
Ongoing
No

Target

Organisation
KuCoin
Type
Financial Institution
Sector
Cryptocurrency Exchange
Country
Global

Actor

Name
Lazarus Group
Type
Nation-State Actor
Nationality
North Korea
Nation-state
Democratic People's Republic of Korea (DPRK)
Motivation
Financial gain and state-sponsored theft of cryptocurrency assets.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
Multiple large transactions (Specific amount varies by report)
Sensitivity
Top Secret
Published
No
Sold (dark web)
No

Money

Crypto
Bitcoin, Ethereum, etc.

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.