Atomic Wallet said on June 4, 2023 that it was investigating possible attack vectors with outside security specialists after users reported unauthorized transactions. The company said it was collecting affected addresses and had contacted major exchanges and blockchain-analysis companies in an effort to trace and block stolen assets. It had not identified or confirmed the cause.

The update followed Atomic Wallet’s initial acknowledgment on June 3 that it had received reports of compromised wallets. By June 4, pseudonymous on-chain investigator ZachXBT reported that a cross-chain graph of suspected thefts had surpassed $35 million. That was an investigator’s evolving estimate—not a figure independently verified by Atomic Wallet or an audit—and its rapid growth showed that the incident could not yet be measured conclusively.

What the June 4 estimate covered

ZachXBT’s June 4 update placed the largest identified individual loss at 7.95 million USDT on the Tron network. The investigator said the five largest losses totaled $17 million, or about 49% of the reported $35 million aggregate. That percentage is a Coinburn calculation using the two rounded figures and should not be read as a precise distribution of all losses.

Contemporaneous reporting described the tracing work as covering assets on Bitcoin, Ethereum, Tron, BNB Smart Chain, Cardano, XRP Ledger, Polkadot, Cosmos, Algorand, Avalanche, Stellar, Litecoin and Dogecoin. BleepingComputer reported that a separate security researcher identified the earliest suspected theft transaction at 21:45 UTC on June 2.

The $35 million figure represented the estimated dollar value of multiple crypto assets linked through an investigator’s address graph through June 4. The surviving event-day record does not provide a complete address ledger, valuation timestamp for every asset or uniform exchange-price source. It therefore cannot be treated as a final forensic accounting.

A security failure without a confirmed mechanism

Atomic Wallet marketed software for users to control private keys locally rather than depositing assets with a custodial exchange. The compromise mattered because reports spanned multiple blockchains and users, suggesting a common point of exposure associated with wallet use rather than a demonstrated failure of one blockchain’s consensus rules.

That distinction did not identify the mechanism. Possible explanations circulating on June 4 included a compromised software build, malicious dependencies, local-device malware and exposure of recovery phrases. Atomic Wallet’s official update said nothing had been confirmed. Reports that some affected users had not recently updated the application also complicated the software-update theory.

BleepingComputer observed that Atomic Wallet’s download server was unavailable during the investigation. That observation established an operational precaution, not proof that distributed software was infected. Likewise, the movement of assets from user addresses demonstrated unauthorized transfers where owners reported them, but public blockchains could not reveal how signing credentials had been obtained.

Why the response mattered

A multi-chain theft required coordination outside any single ledger. Exchanges could potentially identify deposits and restrict accounts under their control, while analytics companies could follow public transactions across supported networks. Neither measure guaranteed recovery: assets could be divided, swapped, bridged or sent through services intended to obscure their origin.

The episode also exposed a structural limit of noncustodial-wallet branding. Users may retain legal and technical control of their keys, but they still depend on wallet software, distribution infrastructure, device security and recovery-phrase handling. “Noncustodial” did not mean that the software presented no common security risk.

Later context

In a statement updated in September 2023, Atomic Wallet claimed that fewer than 0.1% of its application users were affected and that no new cases had been confirmed after June 3. The company still did not confirm a root cause, listing several possibilities instead. Those later claims were not available as established facts on June 4 and do not revise the event-day uncertainty or the narrower $35 million tracing snapshot.

Primary sourceAtomic Wallet June 4 investigation update

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.