On July 23, 2023, on-chain investigator ZachXBT publicly reported that hot wallets attributed to cryptocurrency payments processor Alphapo had been drained for more than $23 million across Ethereum, Tron and Bitcoin. The disclosure turned a series of blockchain transfers and customer withdrawal problems into a named infrastructure incident, while leaving the total loss and cause unresolved.

That distinction matters for chronology. The visible Ethereum transfers began on July 22, not July 23. July 23 was when the incident was publicly identified and quantified by outside researchers. Alphapo had not issued a reviewed public confirmation by the end of July 23.

What the chain showed

Etherscan records a transfer of 2,464.3 ETH at 02:32:47 UTC on July 22 from an address it now labels “AlphaPo 1” to 0x040a…0d17, an address it now labels “Alphapo Drainer.” The receiving address also collected tokens in additional transactions. Those records verify that assets moved and when they moved; Etherscan’s entity and exploit labels are off-chain annotations, not facts established by Ethereum consensus, and may have been applied after the incident.

At 02:30:46 UTC on July 23, ZachXBT posted the initial public alert. The investigator said Ethereum-side assets had been exchanged for ether and then bridged toward Avalanche and Bitcoin. A follow-up post stated that the amount of native bitcoin stolen remained undetermined.

The “more than $23 million” figure was therefore an investigator’s event-day lower-bound estimate, not an audited loss statement. The public alert did not provide a single valuation timestamp, exchange, price index or complete asset schedule. Token prices and liquidity also differed, so the estimate cannot be independently reproduced as a consolidated market valuation from the preserved alert alone.

The operational impact

HypeDrop, an Alphapo customer, told users that its provider was having problems with BTC, ETH and TRX withdrawals and with ETH and TRX deposits. It said affected user funds were secure. The statement corroborated a payment-processing disruption, but it did not name Alphapo in the preserved post, provide a reserve reconciliation or independently prove that every customer balance was available.

This made the development consequential as an industry and custody event rather than a demonstrated protocol failure. Ethereum and the other networks processed signed transactions as designed. The unanswered question was how control over service-operated hot wallets was obtained. Public ledgers made the outflows visible, but they could not identify the controller, establish the internal compromise path or reverse settlement.

The incident also showed the concentration risk behind hosted crypto payments. Multiple consumer-facing businesses could depend on one processor’s wallet operations, turning a compromise at the infrastructure layer into deposit and withdrawal interruptions elsewhere. No defensible evidence reviewed for this reconstruction links the disclosure to a measurable move in bitcoin, ether or the broader market, so no price-reaction claim is made.

What remained unknown on July 23

By the end of July 23, the full bitcoin amount, final loss, entry vector and attacker identity were not established publicly. Private-key leakage was suggested by security researchers, but it remained a hypothesis rather than a disclosed forensic conclusion. Claims attributing the operation to North Korea’s Lazarus Group also arrived later and should not be imported into the event-day account.

Later context

On September 6, 2023, the FBI attributed approximately $60 million stolen from Alphapo and CoinsPaid on or about July 22 to DPRK cyber actors. That later government statement strengthens the threat-actor attribution and incident-date record, but its combined figure does not validate the Alphapo-specific estimate reported on July 23.

Primary sourceZachXBT — July 23 initial Alphapo alert

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.