HostDeFi › Is Atomic Wallet safe
Is Atomic Wallet safe? The self-custody wallet that lost the argument it was making
Atomic Wallet is the family's hardest case because the marketing and the incident are the same claim: 'your keys, your coins.' In June 2023, roughly $100 million left thousands of users' wallets in a drain attributed to North Korea's Lazarus Group — users who had never typed their seed anywhere, whose keys existed only inside Atomic's app. Three years of incident records in this corpus, and this is the only major one where the vendor never published what actually broke.
What Atomic Wallet is
Atomic Wallet launched around 2017–2018 — associated with Konstantin Gladych, formerly CEO of Changelly — and describes itself as a Tallinn, Estonia-based non-custodial wallet for desktop and mobile, claiming roughly five million users and its own AWC token. The custody shape is the standard hot-wallet one: a 12-word seed generated on your device, keys encrypted locally under your password, nothing held by the company.
That shape is exactly why June 2023 matters beyond one vendor. 'Non-custodial' is the entire sales pitch — the company holds nothing, so there is nothing to steal from the company. The incident then demonstrated the uncomfortable refinement: non-custodial means the company holds nothing; it does not prove the software cannot expose what you hold.
June 3, 2023: the drain
On June 3, 2023, users began reporting emptied wallets — including users who had never typed their seed phrase into anything after setup. On-chain sleuth ZachXBT put early losses around $35 million. The company's initial framing was 'less than 1%' of users affected, later revised to 'less than 0.1%' of five million users.
By June 13–14 Elliptic's tracing told the larger story: more than $100 million out of more than 5,500 wallets, attributed to the Lazarus Group — North Korea's state hacking operation — with stolen tokens swapped to Bitcoin and pushed through Sinbad.io (the mixer Elliptic had already tied to Lazarus's laundering of the Axie and Horizon Bridge proceeds), then Garantex. Roughly $1 million was frozen through exchange partners. Estonia's National Criminal Police opened an investigation.
The company named four candidate causes — a virus on user devices, an infrastructure breach, malicious code injection, or a man-in-the-middle attack — a list broad enough to cover essentially every layer of the product — and then, in the fact that defines this page, never publicly identified which one it was. No root-cause disclosure, no published audit of the affected component, no patch a user could verify against. Affected users filed suit in the US; there was no insurance fund and no blanket reimbursement, because a non-custodial company has no balance sheet of yours to draw on.
What the silence costs
Every other incident in this corpus has a named mechanism: Bybit's was a poisoned Safe{Wallet} signing UI, Trezor's a voltage glitch, Trust Wallet's a leaked Chrome Web Store key, Crypto.com's a bypassed 2FA control. Named mechanisms let users do the arithmetic — was I exposed, is it patched, does the fix close my variant.
Atomic's incident has a named attacker and no named mechanism. That is not a technicality — it means a current user cannot determine whether the flaw that drained 5,500 wallets was ever closed, because it was never identified. 'Less than 0.1% affected' is simultaneously true and useless: it describes who got hit, not what got broken. The non-custodial disclaimer that is the product's entire safety claim is also the reason the company owes you no answer it hasn't given.
The risk list, repriced after the incident
For most wallets in this family the honest risk list ranks phishing first and vendor software last. Atomic inverts it: the unexplained mass drain is a documented failure of either the software or its distribution, undiagnosed in public, so the vendor layer itself stays on the list — near the top — until a root cause is published. Below it sit the standard hot-wallet vectors: seed phishing via fake 'Atomic support' and clone apps, host-OS malware and clipboard hijackers (the same 2023 npm campaign that patched Exodus installs also patched Atomic's), and the swap window — in-app exchanges hand assets to third-party providers for settlement.
The structural lesson the page exists to carry: self-custody wallets are only as trustworthy as their build pipeline, because the keys you 'hold' are held inside code someone else wrote. 'Your keys' is a claim about the architecture. June 2023 showed it is also a claim about the binary.
Where Atomic Wallet stands
On documented record this is the weakest page in the wallet tier: the only mainstream self-custody wallet with a nine-figure unexplained mass drain, attribution to a state actor, no published root cause, and no make-whole — partial freezes around $1M against $100M+ out. Users who held through it unharmed held through an unmeasured exposure — the wallet equivalent of surviving turbulence whose cause the airline never announced. The corpus's calibration applies cleanly: unbreached is not the same as safe — but unexplained is the one thing worse than breached. For a product whose entire pitch was removing counterparty trust, that unanswered question is now the product's defining feature — and a reasonable user's due-diligence item number one before any deposit, on any platform, in any category of this entire family.
Frequently asked questions
Was Atomic Wallet actually hacked?
Yes — June 3, 2023, thousands of user wallets were drained on-chain. ZachXBT's early tally was ~$35M; Elliptic's tracing pushed it past $100M across 5,500+ wallets. The company acknowledged compromised wallets while disputing the share of users hit ('less than 0.1%' of a claimed 5M). The drain is settled fact; what was never settled is the mechanism.
Who stole the funds?
Elliptic attributed the theft to North Korea's Lazarus Group — the same operation behind the Axie/Ronin and Horizon Bridge thefts — and traced the stolen tokens being swapped to Bitcoin and laundered through Sinbad.io and Garantex. Atomic Wallet itself pointed only to unnamed 'investigation agencies' claiming 'sorta Lazarus group.'
What was the actual vulnerability?
Never disclosed. The company publicly listed four candidates — malware on user devices, an infrastructure breach, malicious code injection, or a man-in-the-middle attack — and has not published which applied, nor a root-cause report or an independent audit of the affected component. That absence is the central fact of this page: the exposure that emptied wallets may or may not still exist in current builds.
Did affected users get reimbursed?
No blanket reimbursement. Roughly $1M of stolen funds was frozen through cooperating exchanges per Elliptic; beyond that, affected users' recourse ran through reports and a US lawsuit filed against the company — not a compensation fund. A non-custodial wallet holds no user balance sheet, so there is no SAFU-style pool to draw from.
Is it safe to keep using Atomic Wallet?
The honest read from this family: an unexplained nine-figure incident is the one record worse than an explained one. With no published root cause, 'is it fixed' is unanswerable from the outside. Users who stay should treat it as a hot wallet with a documented vendor-layer failure — small balances, seed stored only offline, zero tolerance for any 'support' contact asking for the phrase. Users who leave can import the same 12 words into another BIP39 wallet in minutes.
How is this different from the Bybit hack?
Mechanism disclosure. Bybit's $1.5B loss was bigger but diagnosed in public within days — a compromised Safe{Wallet} developer machine poisoning the signing UI — so every user could see the boundary that failed (an integration, not the custody core). Atomic's was a hundredth the size and has no diagnosed boundary at all. Size measures the event; disclosure measures whether it can happen again.