CoinStats began bringing its portfolio-tracking platform back online on June 23, 2024 after a security breach affected wallets created through the service and prompted the company to shut down its application.

The partial restoration did not resolve the incident. CoinStats said it was activating functions gradually, while its chief executive, Narek Gevorgyan, said the production environment was being recovered with additional security measures intended to isolate the attackers. The company was still investigating how funds had been taken and had not released a technical post-mortem.

A limited restoration after a broad shutdown

CoinStats had disclosed the breach on June 22. It said the attack affected 1,590 CoinStats Wallets, representing 1.3% of wallets created through that product, and published a list of addresses it considered affected. The company asserted that wallets and centralized-exchange accounts connected to CoinStats for portfolio tracking were not compromised.

Those were contemporaneous company statements, not independently audited findings. CryptoSlate reported on June 23 that its editor had funds removed from a CoinStats-generated wallet before users received a malicious notification. The notification advertised a fictitious 14.2 ETH reward and directed recipients toward a wallet-draining website.

CoinStats initially took the entire application offline while attempting to contain the breach. Its official announcement channel subsequently said on June 23 that the service was back online, although not every function was active. Later updates listed transaction entry, portfolio charts and portfolio synchronization among the restored features, while Binance synchronization remained unavailable.

The distinction between tracking connections and CoinStats-created wallets was central to the incident. Read-only portfolio connections ordinarily allow software to display balances without possessing the private keys required to move assets. CoinStats Wallet was a separate feature that generated wallets for users. The company’s early record indicated that this second category—not every wallet merely displayed inside the application—was the affected population.

Attribution remained a company hypothesis

Gevorgyan said on June 23 that CoinStats had significant evidence suggesting the attack belonged to a group of operations associated with North Korea. He referenced a 2022 U.S. government advisory describing “TraderTraitor” campaigns in which North Korean state-sponsored actors targeted blockchain companies through social engineering and malicious cryptocurrency applications.

That advisory established a known threat pattern, but it did not investigate the CoinStats incident and could not independently validate the June 23 attribution. On the event date, CoinStats had not published the evidence connecting its breach to a particular state, hacking group or intrusion method. The North Korea connection therefore remained an attributable company assessment rather than a confirmed government finding.

Gevorgyan also estimated on June 23 that approximately $2 million had been drained, including roughly $800,000 from two wallets whose owners had imported seed phrases into CoinStats Wallet. These figures were preliminary company estimates. No preserved event-day record supplied a reproducible asset-by-asset valuation method, pricing timestamp or independent reconciliation.

What the June 23 record established

The verified development was operational: CoinStats was rebuilding its environment and cautiously restoring service after identifying 1,590 affected wallet addresses. The surviving evidence also showed that the incident combined two security problems—a malicious notification distributed through trusted application channels and unauthorized transfers from company-generated wallets.

It did not establish the final loss, the complete path into CoinStats’ systems or the identity of the attacker. Users and observers consequently had to distinguish the company’s verified actions from its still-developing forensic conclusions.

Later context

In a report dated July 12, CoinStats said an attacker had obtained unauthorized access across parts of its infrastructure and third-party services, accessed private keys for exactly 1,590 wallets and stolen approximately $2.2 million. It attributed the operation to the Lazarus Group or a related organization and said full functionality had been restored by July 3. Those later findings clarify the investigation but were not available on June 23.

Primary sourceCoinStats official announcement channel — incident recovery and service-restoration updates

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.