Trump’s WLFI Moves To Contain Wallet Breach While Federal Inquiry Looms
World Liberty Financial (WLFI) said it is reallocating funds and confirming user identities after several wallets were compromised ahead of its platform launch. According to WLFI’s post on X, the company froze the affect...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
World Liberty Financial (WLFI) said it is reallocating funds and confirming user identities after several wallets were compromised ahead of its platform launch.
According to WLFI’s post on X, the company froze the affected addresses in September and has been verifying ownership before moving assets back to users who pass the checks.
Wallet Breaches And ResponseReports have disclosed that the breaches came from either phishing attacks or exposed seed phrases, not from WLFI’s own platform or smart contracts, the company said.
WLFI described the problem as linked to third-party security failures and said only a “small subset” of users were hit — though it did not give exact figures on how many accounts or how much crypto was involved.
1/ Prior to WLFI’s launch, a relatively small subset of user wallets were compromised via phishing attacks or exposed seed phrases.
Since then, we’ve tested new smart contract logic to safely reallocate user funds and verified users’ identity via KYC checks.
Shortly, users who…
— WLFI (@worldlibertyfi) November 19, 2025
On-chain data cited by analyst Emmett Gallic of Arkham shows WLFI executed an emergency action that burned 166.67 million WLFI tokens, a move valued at $22.14 million from a compromised address, and then shifted tokens to a recovery address.
That firewall step appears intended to limit further loss while the company sorts ownership questions.
World Liberty Fi executed an emergency function burning 166.667M $WLFI ($22.14M) from compromised address, reallocating to a recovery address.
Function designed for two scenarios: An investor loses wallet access before vesting OR malicious account acquires WLFI via exploit pic.twitter.com/VSUDWhDPCR
— Emmett Gallic (@emmettgallic) November 19, 2025
Regulatory Spotlight GrowsThe timing of the security disclosure has drawn extra attention. Based on reports, Senators Elizabeth Warren and Jack Reed asked the DOJ and Treasury to review alleged WLFI token sales tied to sanctioned parties.
Their letter referenced a watchdog report from Accountable.US that linked transactions to the Lazarus Group — a North Korea-linked actor on sanctions lists — and to an Iranian crypto exchange. It remains unclear whether the wallet compromises are related to the transactions lawmakers flagged.
Experts Question On-Chain FindingsSecurity researchers have pushed back on some of the watchdog’s claims. Taylor Moynahan of MetaMask and Nick Bax of Ump.eth said the Accountable.US analysis misread certain on-chain activity.
Another day in crypto with wild allegations. Today, it’s that a North Korea-linked address invested in WLFI.
I do a some DPRK crypto research myself, so I decided to take a look at their findings.
They’re bad and an innocent user is out $100k because of it pic.twitter.com/yJKEH04nup
— Nick Bax.eth (@bax1337) November 18, 2025
Bax argued that the report mistakenly connected a wallet tied to an individual known as “Shryder” with DPRK-linked activity, which led to the freezing of roughly $95,000 in WLFI tokens.
WLFI has responded by emphasizing user protection and compliance. The company said it prioritized freezing vulnerable wallets and verifying rightful owners before any transfers. It also announced tests of revised smart contract logic meant to reduce the chance of similar breaches in future rollouts.
Featured image from Gemini, chart from TradingView
Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on NewsBTCRelated market context
Coinkite warns Coldcard Mk3 users of firmware flaw that may have compromised wallet seeds
The firmware flaw highlights the critical importance of robust RNGs in hardware wallets, emphasizing the need for vigilant securit...
Coldcard attack: 25 minutes, 500 wallets, $38M in BTC gone
Someone likely used AI to drain almost 600 BTC, worth $38 million, from roughly 500 dormant wallets yesterday as part of a seed ph...
Coldcard Firmware Flaw Lets Attacker Drain 594 Bitcoin From Users
An attacker swept roughly 594 bitcoin, worth about $38 million, out of around 500 separate wallets between 01:31 and 01:56 UTC on...
Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen
Bitcoin Magazine Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen The popular Bitcoin hardware wallet...
‘Funds may be at risk’: Coinkite issues warning for Coldcard Mk3 users amid 594 BTC theft reports
Coinkite recommends that Mk3 users create a strong, unique BIP-39 passphrase on the device and move funds to the resulting wallet.
Binance’s CZ warns users to split funds after $70M Coldcard exploit
The Coldcard exploit highlights the critical need for diversified security strategies in crypto storage, balancing complexity with...