Skip to main content
AVOID.NET

v2 → v3

Scores

trust_score00
severity_base
score_modifier-22-22

Sections

Identity and State Sponsorship

unchanged

DOJ Indictments and Legal Actions

unchanged

Bybit Hack — February 2025 ($1.46–$1.5 Billion)

unchanged

Ronin Bridge Hack — March 2022 ($625 Million)

unchanged

Harmony Horizon Bridge Hack — June 2022 ($100 Million)

unchanged

Atomic Wallet Hack — June 2023 (~$100 Million)

unchanged

WazirX Hack — July 2024 ($235 Million)

unchanged

OFAC Sanctions and Regulatory Designations

unchanged

Tactics, Techniques, and Procedures (TTPs)

unchanged

Historical Non-Crypto Operations

unchanged

UN Panel Reports and Strategic Context

unchanged

2026 Activity — Alleged KelpDAO / LayerZero Theft

unchanged

Overview and Attribution

unchanged

DOJ Indictments: Park Jin Hyok, Jon Chang Hyok, Kim Il

unchanged

Ronin Bridge Hack (March 2022) — $620 Million

unchanged

Harmony Horizon Bridge Hack (June 2022) — $100 Million → Bybit Exchange Hack (February 2025) — $1.5 Billion

- On June 24, 2022, Lazarus Group exploited Harmony's Horizon Ethereum bridge, stealing approximately $100 million in crypto assets across 11 transactions. Stolen assets included ETH, Binance Coin, Tether, USD Coin, and DAI. Attackers converted the stolen assets to approximately 85,837 ETH through Tornado Cash to launder the proceeds. The FBI formally confirmed Lazarus Group's responsibility for the Harmony Horizon Bridge theft in a public statement. On January 13, 2023, North Korean cyber actors used RAILGUN, a privacy protocol, to launder over $60 million worth of ETH from this theft. Binance detected laundering attempts through the Huobi exchange and assisted in freezing and recovering some deposited assets. The FBI stated that the group used the RAILGUN privacy protocol specifically to evade detection after Tornado Cash was sanctioned by OFAC in August 2022.+ On February 21, 2025, Lazarus Group (operating under the TraderTraitor designation) carried out the single largest cryptocurrency theft in history, stealing approximately $1.5 billion USD — approximately 401,000 ETH — from Bybit, one of the world's largest cryptocurrency exchanges. The FBI confirmed attribution in a public service announcement issued February 26, 2025. The attack exploited a compromised developer machine at Safe{Wallet}, a multi-signature wallet platform used by Bybit, allowing attackers to intercept a scheduled transfer between Bybit's cold and hot wallets and redirect funds to attacker-controlled addresses. Within 48 hours, at least $160 million had been funneled through illicit channels; by February 26, over $400 million had been laundered. Attackers converted stolen ETH to Bitcoin and other virtual assets dispersed across thousands of addresses on multiple blockchains. The FBI's IC3 PSA released a list of 51 Ethereum addresses linked to the theft and urged private sector entities — including RPC node operators, exchanges, bridges, blockchain analytics firms, and DeFi services — to block transactions involving those addresses. Known TraderTraitor-linked Ethereum addresses from the FBI statement include: 0x51E9d833Ecae4E8D9D8Be17300AEE6D3398C135D, 0x96244D83DC15d36847C35209bBDc5bdDE9bEc3D8, 0x83c7678492D623fb98834F0fbcb2E7b7f5Af8950, and 0x15ec300a4895a86322f1a27dd9ba0b9f8297e65d (also linked to prior Phemex, BingX, and Poloniex breaches). This single theft exceeded Lazarus Group's entire reported haul for 2024.

Bybit Exchange Hack (February 2025) — $1.5 Billion → WazirX Exchange Hack (July 2024) — $234.9 Million

- On February 21, 2025, Lazarus Group (operating under the TraderTraitor designation) carried out the single largest cryptocurrency theft in history, stealing approximately $1.5 billion USD — approximately 401,000 ETH — from Bybit, one of the world's largest cryptocurrency exchanges. The FBI confirmed attribution in a public service announcement issued February 26, 2025. The attack exploited a compromised developer machine at Safe{Wallet}, a multi-signature wallet platform used by Bybit, allowing attackers to intercept a scheduled transfer between Bybit's cold and hot wallets and redirect funds to attacker-controlled addresses. Within 48 hours, at least $160 million had been funneled through illicit channels; by February 26, over $400 million had been laundered. Attackers converted stolen ETH to Bitcoin and other virtual assets dispersed across thousands of addresses on multiple blockchains. The FBI's IC3 PSA released a list of 51 Ethereum addresses linked to the theft and urged private sector entities — including RPC node operators, exchanges, bridges, blockchain analytics firms, and DeFi services — to block transactions involving those addresses. Known TraderTraitor-linked Ethereum addresses from the FBI statement include: 0x51E9d833Ecae4E8D9D8Be17300AEE6D3398C135D, 0x96244D83DC15d36847C35209bBDc5bdDE9bEc3D8, 0x83c7678492D623fb98834F0fbcb2E7b7f5Af8950, and 0x15ec300a4895a86322f1a27dd9ba0b9f8297e65d (also linked to prior Phemex, BingX, and Poloniex breaches). This single theft exceeded Lazarus Group's entire reported haul for 2024.+ On July 18, 2024, Lazarus Group attacked Indian cryptocurrency exchange WazirX, draining $234.9 million in crypto assets. The attack involved creating a fake WazirX account, depositing tokens, and purchasing GALA tokens to drain the hot wallet. Attackers then targeted the cold wallet by exploiting a multisig wallet mechanism: when WazirX signatories accessed the wallet, the attackers altered the controlling smart contract, granting themselves full control. The compromised Ethereum wallet address reported in connection with the hack is 0x27fD43BABfbe83a81d14665b1a6fB8030A60C9b4. The United States, Japan, and South Korea issued a joint statement confirming Lazarus Group's responsibility. The WazirX hack was the second-largest individual crypto hack of 2024.

WazirX Exchange Hack (July 2024) — $234.9 Million → Additional Significant Crypto Thefts

- On July 18, 2024, Lazarus Group attacked Indian cryptocurrency exchange WazirX, draining $234.9 million in crypto assets. The attack involved creating a fake WazirX account, depositing tokens, and purchasing GALA tokens to drain the hot wallet. Attackers then targeted the cold wallet by exploiting a multisig wallet mechanism: when WazirX signatories accessed the wallet, the attackers altered the controlling smart contract, granting themselves full control. The compromised Ethereum wallet address reported in connection with the hack is 0x27fD43BABfbe83a81d14665b1a6fB8030A60C9b4. The United States, Japan, and South Korea issued a joint statement confirming Lazarus Group's responsibility. The WazirX hack was the second-largest individual crypto hack of 2024.+ Beyond the largest hacks, Lazarus Group has conducted numerous other major cryptocurrency thefts. In June 2023, the group attacked Atomic Wallet, a non-custodial decentralized crypto wallet, stealing over $100 million from approximately 5,500 compromised customer wallets across multiple transactions beginning June 3, 2023; at least ten addresses lost more than $1 million each. Proceeds were laundered in part through sanctioned Russian exchange Garantex. In September 2023, the FBI confirmed Lazarus Group responsible for the theft of $41 million from online crypto casino Stake.com. In July 2023, approximately $60 million was stolen from payment processor Alphapo and crypto platform CoinsPaid on or about July 22, 2023. The 2020 KuCoin exchange hack, in which approximately $275 million was taken, was also attributed to Lazarus Group by Chainalysis. The DMM Bitcoin exchange in Japan was attacked in May 2024, losing approximately 4,502.9 BTC (approximately $305 million at time of theft) via private key compromise; the stolen bitcoin was laundered through Bitcoin CoinJoin mixing services, then bridged to other chains and sent to Huione Guarantee, a Cambodia-based marketplace. DMM Bitcoin shut down in December 2024.

Additional Significant Crypto Thefts → TraderTraitor Malware Campaign and Attack Methods

- Beyond the largest hacks, Lazarus Group has conducted numerous other major cryptocurrency thefts. In June 2023, the group attacked Atomic Wallet, a non-custodial decentralized crypto wallet, stealing over $100 million from approximately 5,500 compromised customer wallets across multiple transactions beginning June 3, 2023; at least ten addresses lost more than $1 million each. Proceeds were laundered in part through sanctioned Russian exchange Garantex. In September 2023, the FBI confirmed Lazarus Group responsible for the theft of $41 million from online crypto casino Stake.com. In July 2023, approximately $60 million was stolen from payment processor Alphapo and crypto platform CoinsPaid on or about July 22, 2023. The 2020 KuCoin exchange hack, in which approximately $275 million was taken, was also attributed to Lazarus Group by Chainalysis. The DMM Bitcoin exchange in Japan was attacked in May 2024, losing approximately 4,502.9 BTC (approximately $305 million at time of theft) via private key compromise; the stolen bitcoin was laundered through Bitcoin CoinJoin mixing services, then bridged to other chains and sent to Huione Guarantee, a Cambodia-based marketplace. DMM Bitcoin shut down in December 2024.+ The FBI, CISA, and U.S. Treasury Department issued a joint cybersecurity advisory (AA22-108A) in April 2022 describing the TraderTraitor campaign in detail. Lazarus Group initiates intrusions via spearphishing, targeting employees of cryptocurrency companies in system administration and software development roles with messages appearing as high-paying job recruitment offers. Victims are lured into downloading malicious cryptocurrency applications written in cross-platform JavaScript using the Node.js runtime and Electron framework — applications that purport to be cryptocurrency trading or price prediction tools. The group also conducts social engineering of exchange validators and multi-signature wallet signatories to gain access to private keys. In 2023, TraderTraitor expanded into open-source software supply chain attacks — one of the first known cases of a nation-state APT leveraging public package repositories as an attack vector. The Safe{Wallet} supply chain attack used in the 2025 Bybit heist exemplifies this evolution: attackers compromised a developer machine at a third-party software provider to intercept and manipulate legitimate multi-signature transactions. Private key compromise accounted for 43.8% of all stolen crypto in 2024 globally, a pattern consistent with Lazarus Group's known methods.

TraderTraitor Malware Campaign and Attack Methods → Money Laundering Infrastructure

- The FBI, CISA, and U.S. Treasury Department issued a joint cybersecurity advisory (AA22-108A) in April 2022 describing the TraderTraitor campaign in detail. Lazarus Group initiates intrusions via spearphishing, targeting employees of cryptocurrency companies in system administration and software development roles with messages appearing as high-paying job recruitment offers. Victims are lured into downloading malicious cryptocurrency applications written in cross-platform JavaScript using the Node.js runtime and Electron framework — applications that purport to be cryptocurrency trading or price prediction tools. The group also conducts social engineering of exchange validators and multi-signature wallet signatories to gain access to private keys. In 2023, TraderTraitor expanded into open-source software supply chain attacks — one of the first known cases of a nation-state APT leveraging public package repositories as an attack vector. The Safe{Wallet} supply chain attack used in the 2025 Bybit heist exemplifies this evolution: attackers compromised a developer machine at a third-party software provider to intercept and manipulate legitimate multi-signature transactions. Private key compromise accounted for 43.8% of all stolen crypto in 2024 globally, a pattern consistent with Lazarus Group's known methods.+ Lazarus Group employs a layered laundering infrastructure to convert stolen cryptocurrency into usable funds for the North Korean state. Primary methods include decentralized exchange (DEX) swaps to convert non-ETH assets into ETH — bypassing AML/KYC controls at centralized exchanges — followed by use of mixing services including Tornado Cash (sanctioned by OFAC in August 2022) and RAILGUN privacy protocol. The group has laundered proceeds through over 12,000 unique crypto addresses in a single campaign (Ronin Bridge). Cross-chain bridges and conversion to Bitcoin via CoinJoin mixers are also documented laundering paths. Chainalysis reported that between June 2023 and February 2024, Huione Pay — a Cambodia-based payment company — received cryptocurrency worth over $150,000 from a digital wallet used by Lazarus Group. OFAC issued its first-ever sanctions on a virtual currency mixer targeting Blender.io in May 2022, citing Lazarus Group's use of the service to launder $20.5 million in Ronin Bridge proceeds. The group subsequently shifted to Tornado Cash, which OFAC sanctioned in August 2022. Total laundering activity attributed to Lazarus Group across 2022–2023 exceeded $900 million, per Bitdefender analysis.

Money Laundering Infrastructure → Scale of Operations: Cumulative Theft Estimates

- Lazarus Group employs a layered laundering infrastructure to convert stolen cryptocurrency into usable funds for the North Korean state. Primary methods include decentralized exchange (DEX) swaps to convert non-ETH assets into ETH — bypassing AML/KYC controls at centralized exchanges — followed by use of mixing services including Tornado Cash (sanctioned by OFAC in August 2022) and RAILGUN privacy protocol. The group has laundered proceeds through over 12,000 unique crypto addresses in a single campaign (Ronin Bridge). Cross-chain bridges and conversion to Bitcoin via CoinJoin mixers are also documented laundering paths. Chainalysis reported that between June 2023 and February 2024, Huione Pay — a Cambodia-based payment company — received cryptocurrency worth over $150,000 from a digital wallet used by Lazarus Group. OFAC issued its first-ever sanctions on a virtual currency mixer targeting Blender.io in May 2022, citing Lazarus Group's use of the service to launder $20.5 million in Ronin Bridge proceeds. The group subsequently shifted to Tornado Cash, which OFAC sanctioned in August 2022. Total laundering activity attributed to Lazarus Group across 2022–2023 exceeded $900 million, per Bitdefender analysis.+ Lazarus Group's cryptocurrency theft has escalated dramatically in scale over time. Chainalysis data shows DPRK-linked actors stole $660.5 million across 20 incidents in 2023, $1.34 billion across 47 incidents in 2024 (a 102.88% year-over-year increase, representing 61% of all global crypto theft that year), and approximately $2.02–$2.06 billion across 80 incidents in 2025. The Bybit hack alone ($1.5 billion, February 2025) exceeded the group's entire 2024 haul. Q1 2026 has seen an additional $309 million stolen across 12 incidents. Cumulative cryptocurrency theft attributed to Lazarus Group since 2017 is estimated at $6.75 billion by multiple blockchain analytics firms. The group's stolen funds are assessed by U.S. authorities to directly finance North Korea's nuclear and ballistic missile programs and fund other sanctioned state activities.

Scale of Operations: Cumulative Theft Estimates → Pre-Crypto Operations: Sony, Bangladesh Bank, WannaCry

- Lazarus Group's cryptocurrency theft has escalated dramatically in scale over time. Chainalysis data shows DPRK-linked actors stole $660.5 million across 20 incidents in 2023, $1.34 billion across 47 incidents in 2024 (a 102.88% year-over-year increase, representing 61% of all global crypto theft that year), and approximately $2.02–$2.06 billion across 80 incidents in 2025. The Bybit hack alone ($1.5 billion, February 2025) exceeded the group's entire 2024 haul. Q1 2026 has seen an additional $309 million stolen across 12 incidents. Cumulative cryptocurrency theft attributed to Lazarus Group since 2017 is estimated at $6.75 billion by multiple blockchain analytics firms. The group's stolen funds are assessed by U.S. authorities to directly finance North Korea's nuclear and ballistic missile programs and fund other sanctioned state activities.+ Lazarus Group's documented operations predate its cryptocurrency focus. The earliest attributed activity is 'Operation Troy' (2009–2012), a cyber-espionage campaign using DDoS techniques against the South Korean government. In November 2014, the group launched a destructive attack against Sony Pictures Entertainment in alleged retaliation for the film 'The Interview,' stealing confidential data including unreleased films, executive communications, and approximately 4,000 employee records, while causing estimated damages of $35–85 million in recovery costs. In February 2016, the group executed the Bangladesh Bank cyber heist, issuing 35 fraudulent SWIFT network instructions attempting to transfer $951 million from the Federal Reserve Bank of New York; five instructions successfully transferred $101 million, of which approximately $81 million was unrecovered. In May 2017, Lazarus Group deployed WannaCry 2.0 ransomware, infecting more than 200,000 computers across 150 countries including the UK's National Health Service, Boeing, and universities in China. These operations established Lazarus Group's pattern of combining cyber-espionage, financial crime, and destructive attacks on behalf of the North Korean state.

Pre-Crypto Operations: Sony, Bangladesh Bank, WannaCry → OFAC Sanctions and Known Sanctioned Wallet Addresses

- Lazarus Group's documented operations predate its cryptocurrency focus. The earliest attributed activity is 'Operation Troy' (2009–2012), a cyber-espionage campaign using DDoS techniques against the South Korean government. In November 2014, the group launched a destructive attack against Sony Pictures Entertainment in alleged retaliation for the film 'The Interview,' stealing confidential data including unreleased films, executive communications, and approximately 4,000 employee records, while causing estimated damages of $35–85 million in recovery costs. In February 2016, the group executed the Bangladesh Bank cyber heist, issuing 35 fraudulent SWIFT network instructions attempting to transfer $951 million from the Federal Reserve Bank of New York; five instructions successfully transferred $101 million, of which approximately $81 million was unrecovered. In May 2017, Lazarus Group deployed WannaCry 2.0 ransomware, infecting more than 200,000 computers across 150 countries including the UK's National Health Service, Boeing, and universities in China. These operations established Lazarus Group's pattern of combining cyber-espionage, financial crime, and destructive attacks on behalf of the North Korean state.+ The U.S. Treasury's Office of Foreign Assets Control (OFAC) has imposed multiple rounds of sanctions directly linked to Lazarus Group activity. On April 14, 2022, OFAC placed Lazarus Group on the SDN list and sanctioned the primary Ronin Bridge attacker Ethereum wallet 0x098B716B8Aaf21512996dC57EB0615e2383E2f96. In May 2022, OFAC identified four additional virtual currency wallet addresses used by Lazarus Group to launder remaining Ronin Bridge proceeds. In August 2022, OFAC sanctioned Tornado Cash mixer, listing 38 unique cryptocurrency addresses as identifiers, citing Lazarus Group's use of the mixer to launder $455 million from the Ronin Bridge hack. Additional TraderTraitor-linked Ethereum addresses published by the FBI in connection with the February 2025 Bybit hack include 0x51E9d833Ecae4E8D9D8Be17300AEE6D3398C135D, 0x96244D83DC15d36847C35209bBDc5bdDE9bEc3D8, 0x83c7678492D623fb98834F0fbcb2E7b7f5Af8950, and 0x15ec300a4895a86322f1a27dd9ba0b9f8297e65d (the latter also linked to prior Phemex, BingX, and Poloniex breaches). U.S. persons are prohibited from transacting with OFAC-sanctioned addresses.

OFAC Sanctions and Known Sanctioned Wallet Addresses → (section 24)

- The U.S. Treasury's Office of Foreign Assets Control (OFAC) has imposed multiple rounds of sanctions directly linked to Lazarus Group activity. On April 14, 2022, OFAC placed Lazarus Group on the SDN list and sanctioned the primary Ronin Bridge attacker Ethereum wallet 0x098B716B8Aaf21512996dC57EB0615e2383E2f96. In May 2022, OFAC identified four additional virtual currency wallet addresses used by Lazarus Group to launder remaining Ronin Bridge proceeds. In August 2022, OFAC sanctioned Tornado Cash mixer, listing 38 unique cryptocurrency addresses as identifiers, citing Lazarus Group's use of the mixer to launder $455 million from the Ronin Bridge hack. Additional TraderTraitor-linked Ethereum addresses published by the FBI in connection with the February 2025 Bybit hack include 0x51E9d833Ecae4E8D9D8Be17300AEE6D3398C135D, 0x96244D83DC15d36847C35209bBDc5bdDE9bEc3D8, 0x83c7678492D623fb98834F0fbcb2E7b7f5Af8950, and 0x15ec300a4895a86322f1a27dd9ba0b9f8297e65d (the latter also linked to prior Phemex, BingX, and Poloniex breaches). U.S. persons are prohibited from transacting with OFAC-sanctioned addresses.+ 

Timeline events

No timeline changes.

Accepted submissions

No changes to accepted submissions.

Each version is bound to the decision event that created it. Verify the chain anchor for either via the audit log.

v2 hash: cdb55b5c75b904289c1fc41e51599febf439d01bb72dedcb1c55334681da5c08
v3 hash: d79f7197484f3346b5cd3892b85985db18cb90347576d46b1ff4055460ce900f