On September 24, 2025, over $21 million in digital assets were withdrawn from addresses associated with the SBI Crypto mining pool, a subsidiary of Japan's SBI Group. The stolen funds included Bitcoin, Ethereum, Litecoin, Dogecoin, and Bitcoin Cash, according to crypto researcher ZachXBT.
The stolen assets were first transferred to five ”instant exchangers” and subsequently sent to the cryptocurrency mixer Tornado Cash.
ZachXBT noted that the patterns observed in this incident resemble previous attacks attributed to hacker groups linked to North Korea. However, there is no official confirmation of this yet.
SBI Crypto has been a leading cryptocurrency mining pool since 2017, offering a platform for miners of all levels. In August 2025, SBI Holdings submitted applications to launch two cryptocurrency ETFs, one of which will invest in Bitcoin and XRP.
This breach underscores the increasing sophistication of cyberattacks targeting cryptocurrency infrastructure. North Korean hacker groups, such as the Lazarus Group, have been linked to several high-profile crypto heists in recent years.
For instance, in 2024, they were responsible for the $1.3 billion theft from various crypto exchanges, marking one of the largest crypto heists to date.
The use of Tornado Cash, a privacy-focused mixer, highlights ongoing challenges in tracking illicit crypto transactions. Despite regulatory efforts, such mixers continue to be utilized for laundering stolen funds, complicating enforcement actions.
![[OPINION] US National Security Strategy 2025: An iconoclastic document](https://www.rappler.com/tachyon/2025/12/AMERICANS-ARE-BACK-DEC-12-2025.jpg?resize=75%2C75&crop_strategy=attention)

