Skip to main content
AVOID.NET

v3 → v4

Scores

trust_score02
severity_base
score_modifier-22-22

Sections

Identity and State Sponsorship

unchanged

DOJ Indictments and Legal Actions → DOJ Indictments and Named Individuals

unchanged

Bybit Hack — February 2025 ($1.46–$1.5 Billion) → Bybit Exchange Hack — February 2025 (~$1.5 Billion)

unchanged

Ronin Bridge Hack — March 2022 ($625 Million) → Ronin Bridge Hack — March 2022 (~$540M–$625M)

unchanged

Harmony Horizon Bridge Hack — June 2022 ($100 Million) → Harmony Horizon Bridge Hack — June 2022 (~$100 Million)

unchanged

Atomic Wallet Hack — June 2023 (~$100 Million)

unchanged

WazirX Hack — July 2024 ($235 Million) → WazirX Exchange Hack — July 2024 (~$235 Million)

unchanged

OFAC Sanctions and Regulatory Designations → Additional Attributed Crypto Thefts (Stake.com, Alphapo/CoinsPaid, KuCoin)

unchanged

Tactics, Techniques, and Procedures (TTPs) → 2026 Activity — Alleged KelpDAO / LayerZero Theft (~$290 Million)

unchanged

Historical Non-Crypto Operations → OFAC Sanctions and Regulatory Designations

unchanged

UN Panel Reports and Strategic Context → Tactics, Techniques, and Procedures (TTPs)

unchanged

2026 Activity — Alleged KelpDAO / LayerZero Theft → Historical Non-Crypto Operations (Sony, Bangladesh Bank, WannaCry)

unchanged

Overview and Attribution → UN Panel of Experts and Strategic Context

- Lazarus Group is a North Korean state-sponsored hacking collective first identified around 2009. The U.S. government, along with international cybersecurity agencies, attributes the group to the Reconnaissance General Bureau (RGB), a military intelligence arm of the Democratic People's Republic of Korea (DPRK). The group operates under numerous aliases across the cybersecurity community, including APT38, BlueNorOff, AndAriel, Hidden Cobra, ZINC, Diamond Sleet, Stardust Chollima, Guardians of Peace, and TraderTraitor. A North Korean defector, Kim Kuk-song, has identified the group's internal designation as the '414 Liaison Office.' The U.S. Department of Justice formally asserts that the group 'is part of the North Korean government's strategy to undermine global cybersecurity and generate illicit revenue in violation of international sanctions.' The FBI, NSA, CISA, and the U.S. Treasury Department have all issued formal attributions and advisories regarding the group's operations. OFAC added Lazarus Group to the Specially Designated Nationals (SDN) list on April 14, 2022.+ 

DOJ Indictments: Park Jin Hyok, Jon Chang Hyok, Kim Il → Scale of Operations: Cumulative Theft Estimates

- The U.S. Department of Justice has indicted three named members of Lazarus Group. Park Jin Hyok (age 36 at time of indictment) was first indicted in September 2018, with charges expanded in a superseding indictment filed February 2021. Jon Chang Hyok (age 31) and Kim Il (age 27) were both indicted in February 2021. All three are alleged members of units within the RGB and are charged with conspiracy to commit computer fraud and conspiracy to commit wire and bank fraud. The indictment alleges they were responsible for the 2014 Sony Pictures Entertainment hack, thefts from financial institutions across Asia and Africa via the SWIFT banking network, the 2016 Bangladesh Bank heist (in which approximately $81 million was successfully transferred of a $1 billion attempt), creation and global deployment of the WannaCry 2.0 ransomware, and thefts and extortion totaling more than $1.3 billion in cash and cryptocurrency. None of the three individuals are in U.S. custody. The FBI maintains a most-wanted listing for Park Jin Hyok.+ 

Ronin Bridge Hack (March 2022) — $620 Million → (section 15)

- On March 23, 2022, attackers compromised the Ronin Network, a sidechain connected to Ethereum that supports the play-to-earn game Axie Infinity. The exploit drained 173,600 ETH and 25.5 million USDC, valued at approximately $620–625 million at the time. The attack was not discovered for six days, becoming apparent on March 29, 2022 when a user reported being unable to withdraw 5,000 ETH from the bridge. The theft was executed by compromising five of the nine Ronin validator node private keys through social engineering. OFAC formally attributed the attack to Lazarus Group on April 14, 2022, sanctioning the primary attacker Ethereum wallet address 0x098B716B8Aaf21512996dC57EB0615e2383E2f96. The FBI and Treasury Department confirmed the attribution simultaneously. Stolen USDC was swapped for ETH through decentralized exchanges to avoid AML/KYC controls. Attackers subsequently routed at least $80.3 million through Tornado Cash to obfuscate the trail, with laundering leveraging over 12,000 different crypto addresses. Remaining funds were tracked by on-chain analysts from Elliptic and Chainalysis. This was the largest individual cryptocurrency hack at the time.+ 

Bybit Exchange Hack (February 2025) — $1.5 Billion → (section 16)

- On February 21, 2025, Lazarus Group (operating under the TraderTraitor designation) carried out the single largest cryptocurrency theft in history, stealing approximately $1.5 billion USD — approximately 401,000 ETH — from Bybit, one of the world's largest cryptocurrency exchanges. The FBI confirmed attribution in a public service announcement issued February 26, 2025. The attack exploited a compromised developer machine at Safe{Wallet}, a multi-signature wallet platform used by Bybit, allowing attackers to intercept a scheduled transfer between Bybit's cold and hot wallets and redirect funds to attacker-controlled addresses. Within 48 hours, at least $160 million had been funneled through illicit channels; by February 26, over $400 million had been laundered. Attackers converted stolen ETH to Bitcoin and other virtual assets dispersed across thousands of addresses on multiple blockchains. The FBI's IC3 PSA released a list of 51 Ethereum addresses linked to the theft and urged private sector entities — including RPC node operators, exchanges, bridges, blockchain analytics firms, and DeFi services — to block transactions involving those addresses. Known TraderTraitor-linked Ethereum addresses from the FBI statement include: 0x51E9d833Ecae4E8D9D8Be17300AEE6D3398C135D, 0x96244D83DC15d36847C35209bBDc5bdDE9bEc3D8, 0x83c7678492D623fb98834F0fbcb2E7b7f5Af8950, and 0x15ec300a4895a86322f1a27dd9ba0b9f8297e65d (also linked to prior Phemex, BingX, and Poloniex breaches). This single theft exceeded Lazarus Group's entire reported haul for 2024.+ 

WazirX Exchange Hack (July 2024) — $234.9 Million → (section 17)

- On July 18, 2024, Lazarus Group attacked Indian cryptocurrency exchange WazirX, draining $234.9 million in crypto assets. The attack involved creating a fake WazirX account, depositing tokens, and purchasing GALA tokens to drain the hot wallet. Attackers then targeted the cold wallet by exploiting a multisig wallet mechanism: when WazirX signatories accessed the wallet, the attackers altered the controlling smart contract, granting themselves full control. The compromised Ethereum wallet address reported in connection with the hack is 0x27fD43BABfbe83a81d14665b1a6fB8030A60C9b4. The United States, Japan, and South Korea issued a joint statement confirming Lazarus Group's responsibility. The WazirX hack was the second-largest individual crypto hack of 2024.+ 

Additional Significant Crypto Thefts → (section 18)

- Beyond the largest hacks, Lazarus Group has conducted numerous other major cryptocurrency thefts. In June 2023, the group attacked Atomic Wallet, a non-custodial decentralized crypto wallet, stealing over $100 million from approximately 5,500 compromised customer wallets across multiple transactions beginning June 3, 2023; at least ten addresses lost more than $1 million each. Proceeds were laundered in part through sanctioned Russian exchange Garantex. In September 2023, the FBI confirmed Lazarus Group responsible for the theft of $41 million from online crypto casino Stake.com. In July 2023, approximately $60 million was stolen from payment processor Alphapo and crypto platform CoinsPaid on or about July 22, 2023. The 2020 KuCoin exchange hack, in which approximately $275 million was taken, was also attributed to Lazarus Group by Chainalysis. The DMM Bitcoin exchange in Japan was attacked in May 2024, losing approximately 4,502.9 BTC (approximately $305 million at time of theft) via private key compromise; the stolen bitcoin was laundered through Bitcoin CoinJoin mixing services, then bridged to other chains and sent to Huione Guarantee, a Cambodia-based marketplace. DMM Bitcoin shut down in December 2024.+ 

TraderTraitor Malware Campaign and Attack Methods → (section 19)

- The FBI, CISA, and U.S. Treasury Department issued a joint cybersecurity advisory (AA22-108A) in April 2022 describing the TraderTraitor campaign in detail. Lazarus Group initiates intrusions via spearphishing, targeting employees of cryptocurrency companies in system administration and software development roles with messages appearing as high-paying job recruitment offers. Victims are lured into downloading malicious cryptocurrency applications written in cross-platform JavaScript using the Node.js runtime and Electron framework — applications that purport to be cryptocurrency trading or price prediction tools. The group also conducts social engineering of exchange validators and multi-signature wallet signatories to gain access to private keys. In 2023, TraderTraitor expanded into open-source software supply chain attacks — one of the first known cases of a nation-state APT leveraging public package repositories as an attack vector. The Safe{Wallet} supply chain attack used in the 2025 Bybit heist exemplifies this evolution: attackers compromised a developer machine at a third-party software provider to intercept and manipulate legitimate multi-signature transactions. Private key compromise accounted for 43.8% of all stolen crypto in 2024 globally, a pattern consistent with Lazarus Group's known methods.+ 

Money Laundering Infrastructure → (section 20)

- Lazarus Group employs a layered laundering infrastructure to convert stolen cryptocurrency into usable funds for the North Korean state. Primary methods include decentralized exchange (DEX) swaps to convert non-ETH assets into ETH — bypassing AML/KYC controls at centralized exchanges — followed by use of mixing services including Tornado Cash (sanctioned by OFAC in August 2022) and RAILGUN privacy protocol. The group has laundered proceeds through over 12,000 unique crypto addresses in a single campaign (Ronin Bridge). Cross-chain bridges and conversion to Bitcoin via CoinJoin mixers are also documented laundering paths. Chainalysis reported that between June 2023 and February 2024, Huione Pay — a Cambodia-based payment company — received cryptocurrency worth over $150,000 from a digital wallet used by Lazarus Group. OFAC issued its first-ever sanctions on a virtual currency mixer targeting Blender.io in May 2022, citing Lazarus Group's use of the service to launder $20.5 million in Ronin Bridge proceeds. The group subsequently shifted to Tornado Cash, which OFAC sanctioned in August 2022. Total laundering activity attributed to Lazarus Group across 2022–2023 exceeded $900 million, per Bitdefender analysis.+ 

Scale of Operations: Cumulative Theft Estimates → (section 21)

- Lazarus Group's cryptocurrency theft has escalated dramatically in scale over time. Chainalysis data shows DPRK-linked actors stole $660.5 million across 20 incidents in 2023, $1.34 billion across 47 incidents in 2024 (a 102.88% year-over-year increase, representing 61% of all global crypto theft that year), and approximately $2.02–$2.06 billion across 80 incidents in 2025. The Bybit hack alone ($1.5 billion, February 2025) exceeded the group's entire 2024 haul. Q1 2026 has seen an additional $309 million stolen across 12 incidents. Cumulative cryptocurrency theft attributed to Lazarus Group since 2017 is estimated at $6.75 billion by multiple blockchain analytics firms. The group's stolen funds are assessed by U.S. authorities to directly finance North Korea's nuclear and ballistic missile programs and fund other sanctioned state activities.+ 

Pre-Crypto Operations: Sony, Bangladesh Bank, WannaCry → (section 22)

- Lazarus Group's documented operations predate its cryptocurrency focus. The earliest attributed activity is 'Operation Troy' (2009–2012), a cyber-espionage campaign using DDoS techniques against the South Korean government. In November 2014, the group launched a destructive attack against Sony Pictures Entertainment in alleged retaliation for the film 'The Interview,' stealing confidential data including unreleased films, executive communications, and approximately 4,000 employee records, while causing estimated damages of $35–85 million in recovery costs. In February 2016, the group executed the Bangladesh Bank cyber heist, issuing 35 fraudulent SWIFT network instructions attempting to transfer $951 million from the Federal Reserve Bank of New York; five instructions successfully transferred $101 million, of which approximately $81 million was unrecovered. In May 2017, Lazarus Group deployed WannaCry 2.0 ransomware, infecting more than 200,000 computers across 150 countries including the UK's National Health Service, Boeing, and universities in China. These operations established Lazarus Group's pattern of combining cyber-espionage, financial crime, and destructive attacks on behalf of the North Korean state.+ 

OFAC Sanctions and Known Sanctioned Wallet Addresses → (section 23)

- The U.S. Treasury's Office of Foreign Assets Control (OFAC) has imposed multiple rounds of sanctions directly linked to Lazarus Group activity. On April 14, 2022, OFAC placed Lazarus Group on the SDN list and sanctioned the primary Ronin Bridge attacker Ethereum wallet 0x098B716B8Aaf21512996dC57EB0615e2383E2f96. In May 2022, OFAC identified four additional virtual currency wallet addresses used by Lazarus Group to launder remaining Ronin Bridge proceeds. In August 2022, OFAC sanctioned Tornado Cash mixer, listing 38 unique cryptocurrency addresses as identifiers, citing Lazarus Group's use of the mixer to launder $455 million from the Ronin Bridge hack. Additional TraderTraitor-linked Ethereum addresses published by the FBI in connection with the February 2025 Bybit hack include 0x51E9d833Ecae4E8D9D8Be17300AEE6D3398C135D, 0x96244D83DC15d36847C35209bBDc5bdDE9bEc3D8, 0x83c7678492D623fb98834F0fbcb2E7b7f5Af8950, and 0x15ec300a4895a86322f1a27dd9ba0b9f8297e65d (the latter also linked to prior Phemex, BingX, and Poloniex breaches). U.S. persons are prohibited from transacting with OFAC-sanctioned addresses.+ 

Timeline events

+ added2017-05(no description)
+ added2018-09(no description)
+ added2019(no description)
+ added2020(no description)
+ added2022-03(no description)
+ added2022-04(no description)
+ added2022-05(no description)
+ added2022-06(no description)
+ added2022-08(no description)
+ added2023-01(no description)
+ added2023-06(no description)
+ added2023-07(no description)
+ added2023-09(no description)
+ added2025-01(no description)
+ added2025-03(no description)
+ added2025-12(no description)
+ added2026-04-18(no description)
- removed2007(no description)
- removed2009(no description)
- removed2014-11-24(no description)
- removed2016-02-04(no description)
- removed2017-05-12(no description)
- removed2018-04-03(no description)
- removed2018-09-06(no description)
- removed2019-09-13(no description)
- removed2020-03-02(no description)
- removed2022-03-23(no description)
- removed2022-04-14(no description)
- removed2022-05-06(no description)
- removed2022-06-24(no description)
- removed2022-08-08(no description)
- removed2023-01-13(no description)
- removed2023-01-24(no description)
- removed2023-06-03(no description)
- removed2023-07-22(no description)
- removed2023-09-04(no description)
- removed2024-05(no description)
- removed2024-07(no description)
- removed2025-01-14(no description)
- removed2026-03-12(no description)
- removed2026-04-22(no description)
~ changed2014-11: “” → “
~ changed2016-02: “” → “
~ changed2021-02-17: “” → “
~ changed2024-07-18: “” → “
~ changed2025-02-21: “” → “
~ changed2025-02-26: “” → “

Accepted submissions

No changes to accepted submissions.

Each version is bound to the decision event that created it. Verify the chain anchor for either via the audit log.

v3 hash: d79f7197484f3346b5cd3892b85985db18cb90347576d46b1ff4055460ce900f
v4 hash: 4dcd4e9fb5af887a948fc1a7cb5cd18ebbaced70a26d9ae4019aa6f0d4ca2da5