Crypto betting platform Stake disclosed on September 4, 2023 that unauthorized transactions had been made from its hot wallets, while blockchain-security researchers estimated approximately $41.35 million in assets had moved across Ethereum, BNB Smart Chain and Polygon.
The incident mattered beyond one operator’s balance sheet. It exposed the operational risk created when a centralized service holds assets in internet-connected wallets while serving customers across several public networks. It also demonstrated how quickly investigators could observe transfers on-chain even though the cause, ownership of destination addresses and recoverability of the assets remained uncertain.
What Stake acknowledged
Stake said unauthorized transactions had occurred from its Ethereum and BNB Smart Chain hot wallets. The company said it was investigating and would restore the affected wallets after re-securing them. It characterized customer funds as safe and said wallets for bitcoin, litecoin, XRP, EOS, TRX and other assets remained operational.
Those assurances were company claims, not an independently audited reserve statement. Stake did not disclose the incident’s cause, a final loss calculation or technical details establishing how its wallet controls had been defeated on September 4.
Later that day, Stake announced that all services had resumed and that deposits and withdrawals were processing. Contemporaneous reporting placed that announcement at approximately 21:28 UTC, about five hours after the first public reports of suspicious outflows. Resuming service showed that the operator believed it had contained the immediate disruption; it did not establish that the transferred assets had been recovered or that every underlying vulnerability had been identified.
How researchers reached the estimate
Beosin Alert reported approximately $15.7 million in suspicious Ethereum outflows, $7.8 million on Polygon and $17.8 million on BNB Smart Chain, producing its approximately $41.35 million headline estimate. The three rounded network figures add to $41.3 million, so the extra precision came from Beosin’s underlying calculation rather than the rounded figures reproduced publicly.
The estimate valued multiple tokens in dollars around the time of the September 4 transfers. It was therefore a contemporaneous mark, not a fixed cash loss or a consolidated market price. Token prices could change while assets were exchanged or redistributed, and public-chain records alone could not prove the identity or intent of whoever controlled the receiving addresses.
Earlier reports focused on roughly $15.7 million moved on Ethereum. The larger estimate emerged after analysts included activity on Polygon and BNB Smart Chain. That progression is important: the September 4 record developed from an initial single-network alert into a cross-chain incident, rather than beginning with one complete and audited total.
Why the breach mattered
Hot wallets allow platforms to process deposits and withdrawals without the delay of retrieving assets from offline storage. The same connectivity creates a concentrated operational risk: compromised signing authority or internal wallet controls can permit rapid transfers that a blockchain will execute without regard to whether the platform authorized them.
Stake co-founder Ed Craven said the company kept only a small portion of its crypto reserves in hot wallets for this reason. That statement explained the intended risk boundary, but Stake supplied no reserve denominator on September 4 from which outsiders could calculate the loss as a share of its holdings.
The incident also showed the distinction between transparent settlement and secure custody. Ethereum, Polygon and BNB Smart Chain made the transfers publicly traceable, but visibility did not prevent them, reverse them or establish that funds would be recoverable.
Later confirmation
On September 6, 2023, the FBI described the event as an approximately $41 million virtual-currency theft occurring on or about September 4 and attributed it to North Korea’s Lazarus Group, also known as APT38. That attribution was not available when the transfers first unfolded and should not be projected into the September 4 contemporaneous account. It is included here only as later confirmation of the event’s scale and date.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

