Skip to main content
AVOID.NET
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Sequence
#3
Score
Cluster
mainnet-beta
Slot
423161800
Off-chain at
2026-05-30T13:03:47.808Z
Anchored at
Block time

Independent verification

1. Database (off-chain)
BBg2H5KV283z9zJG16Kdxbi5GxsPbQD6renZ93sZXSjA
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (80569 chars)
{"actor":"system:backfill","investigation_id":"dae6a999-8c54-4b12-a684-c76c4cb85492","kind":"publish","page_slug":"lazarus-group","published_at":"2026-05-30T13:03:47.682Z","sequence_num":3,"snapshot":{"content_type":"investigation","entity_name":"Lazarus Group","sections":[{"content":"Lazarus Group was created by the North Korean government no later than 2007 and is subordinate to the 110th Research Center, 3rd Bureau of the Reconnaissance General Bureau (RGB), which oversees North Korea's offensive cyber operations. The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) designated Lazarus Group, Bluenoroff, and Andariel on September 13, 2019, under Executive Order 13722, identifying them as agencies, instrumentalities, or controlled entities of the Government of North Korea. Bluenoroff was formed specifically to generate revenue illicitly in response to international sanctions, conducting cyber-enabled heists against foreign financial institutions on behalf of the North Korean regime to fund its nuclear weapons and ballistic missile programs. Andariel is a separate operational cluster focused on critical infrastructure attacks. The group is also tracked by the cybersecurity industry under aliases including APT38, Hidden Cobra, ZINC, Jade Sleet, Slow Pisces, UNC4899, and — for its cryptocurrency-focused subcluster — TraderTraitor.","heading":"Identity and State Sponsorship","severity":"critical","sources":[{"credibility":1,"name":"Treasury Sanctions North Korean State-Sponsored Malicious Cyber Groups — U.S. Department of the Treasury","type":"regulatory","url":"https://home.treasury.gov/news/press-releases/sm774"},{"credibility":1,"name":"Lazarus Group — OFAC Sanctions Search Entry","type":"regulatory","url":"https://sanctionssearch.ofac.treas.gov/Details.aspx?id=27307"}]},{"content":"The U.S. Department of Justice has brought federal charges against multiple alleged members of Lazarus Group. In September 2018, the DOJ charged Park Jin Hyok, a North Korean national working for government front company Korea Expo Joint Venture (KEJV), with one count of conspiracy to commit computer fraud and abuse and one count of conspiracy to commit wire fraud, in connection with the 2014 Sony Pictures Entertainment hack, the 2016 Bangladesh Bank SWIFT heist, and the 2017 WannaCry ransomware attack. In February 2021, the DOJ expanded the indictment to include two additional defendants, Jon Chang Hyok and Kim Il, broadening the scope of alleged crimes to include cryptocurrency exchange thefts and the creation of malicious cryptocurrency applications. The DOJ's Office of Public Affairs formally identified these individuals as members of the Reconnaissance General Bureau, the primary intelligence agency of the North Korean government.","heading":"DOJ Indictments and Legal Actions","severity":"critical","sources":[{"credibility":1,"name":"North Korean Regime-Backed Programmer Charged With Conspiracy to Conduct Multiple Cyber Attacks — DOJ","type":"court_filing","url":"https://www.justice.gov/archives/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyber-attacks-and"},{"credibility":2,"name":"DOJ Charges Three North Korean Military Programmers For Sony Hack — Deadline","type":"news_article","url":"https://deadline.com/2021/02/doj-charges-three-north-korean-military-programmers-for-sony-hack-sweeping-cybercrimes-in-expanded-indictment-1234695409/"}]},{"content":"On February 21, 2025, Lazarus Group (acting under the TraderTraitor cluster designation) executed the largest single cryptocurrency theft in history, stealing approximately $1.46–$1.5 billion USD from Dubai-based exchange Bybit. The FBI formally attributed the attack to North Korean TraderTraitor actors in a Public Service Announcement issued on February 26, 2025 (IC3 PSA250226). The attack was a sophisticated supply chain compromise targeting Safe{Wallet}, the multi-signature smart contract wallet platform used by Bybit. Attackers compromised a Safe{Wallet} developer's workstation through social engineering, stole AWS session tokens to access Safe{Wallet}'s cloud infrastructure, and injected malicious JavaScript code into the app.safe.global front-end on February 19, 2025 at 15:29 UTC. The malicious code specifically targeted Bybit's Ethereum multisig cold wallet and activated on the next scheduled transaction, which occurred on February 21, 2025 at 14:13 UTC. By altering the transaction signing interface, the code caused Bybit's authorized signers to unknowingly approve a fraudulent transaction — effectively producing 'blind signatures.' Approximately 401,000 ETH was drained and rapidly dispersed across thousands of blockchain addresses and converted to Bitcoin and other assets. The FBI published 51 Ethereum addresses associated with the laundering activity and urged cryptocurrency service providers to block related transactions. Pre-attack infrastructure registration of bybit-assessment.com was identified by Silent Push as having occurred at 22:21 UTC on February 20, 2025, using an email address previously linked to the Lazarus-associated 'Contagious Interview' campaign.","heading":"Bybit Hack — February 2025 ($1.46–$1.5 Billion)","severity":"critical","sources":[{"credibility":1,"name":"IC3 PSA250226 — North Korea Responsible for $1.5 Billion Bybit Hack (FBI)","type":"regulatory","url":"https://www.ic3.gov/psa/2025/psa250226"},{"credibility":2,"name":"Bybit Hack Traced to Safe{Wallet} Supply Chain Attack Exploited by North Korean Hackers — The Hacker News","type":"news_article","url":"https://thehackernews.com/2025/02/bybit-hack-traced-to-safewallet-supply.html"},{"credibility":2,"name":"The Bybit Hack: Following North Korea's Largest Exploit — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/the-bybit-hack-following-north-koreas-largest-exploit"},{"credibility":2,"name":"Bybit Hack: In-Depth Technical Analysis — NCC Group","type":"research","url":"https://www.nccgroup.com/research/in-depth-technical-analysis-of-the-bybit-hack/"},{"credibility":2,"name":"FBI Confirms Lazarus Group Behind $1.5 Billion Bybit Crypto Heist — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/fbi-confirms-lazarus-hackers-were-behind-15b-bybit-crypto-heist/"}]},{"content":"On March 23, 2022, Lazarus Group drained 173,600 ETH and 25.5 million USDC from the Ronin Network bridge, a sidechain supporting the play-to-earn game Axie Infinity, operated by Sky Mavis. The total stolen was valued at approximately $625 million at the time of the theft. The attackers obtained five of the nine private validator keys required to authorize withdrawals from the Ronin bridge, enabling them to submit two fraudulent withdrawal transactions. The breach was not discovered until six days later, on March 29, 2022. The U.S. Treasury Department attributed the attack to Lazarus Group and updated the group's SDN designation with the Ronin-associated Ethereum address on April 14, 2022. The FBI and OFAC subsequently worked with cryptocurrency exchanges to seize approximately $30 million of the stolen funds.","heading":"Ronin Bridge Hack — March 2022 ($625 Million)","severity":"critical","sources":[{"credibility":2,"name":"US Officials Tie North Korea's Lazarus Hackers to $625M Axie Infinity Crypto Theft — CoinDesk","type":"news_article","url":"https://www.coindesk.com/policy/2022/04/14/us-officials-tie-north-korean-hacker-group-to-axies-ronin-exploit"},{"credibility":2,"name":"Treasury Updates Lazarus Group Sanctions with Digital Currency Address Linked to Ronin Bridge Hack — CyberScoop","type":"news_article","url":"https://cyberscoop.com/ronin-bridge-hack-lazarus-group-north-korea-treasury-sanctions/"},{"credibility":2,"name":"Axie Infinity Ronin Network Suffers $625M Exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2022/03/29/axie-infinitys-ronin-network-suffers-625m-exploit"},{"credibility":2,"name":"N Korean Lazarus Hackers Tied to $625M Theft — TechCrunch","type":"news_article","url":"https://techcrunch.com/2022/04/15/us-officials-link-north-korean-lazarus-hackers-to-625m-axie-infinity-crypto-theft/"}]},{"content":"On June 24, 2022, attackers exploited the Harmony Horizon cross-chain bridge, stealing approximately $99.7 million in cryptocurrency. The FBI confirmed Lazarus Group's responsibility in a press release dated January 24, 2023. The attack vector involved compromising the encryption keys of a multi-signature wallet through a social-engineering campaign targeting Harmony employees, allowing attackers to assume control of the MultiSigWallet contract and execute large unauthorized token transfers. In January 2023, the FBI observed Lazarus Group attempting to launder over $60 million of the stolen ETH through the RAILGUN privacy protocol, subsequently converting portions to Bitcoin. The FBI, working with virtual asset service providers, seized an undisclosed portion of the funds.","heading":"Harmony Horizon Bridge Hack — June 2022 ($100 Million)","severity":"critical","sources":[{"credibility":1,"name":"FBI Confirms Lazarus Group Cyber Actors Responsible for Harmony's Horizon Bridge Currency Theft — FBI.gov","type":"regulatory","url":"https://www.fbi.gov/news/press-releases/fbi-confirms-lazarus-group-cyber-actors-responsible-for-harmonys-horizon-bridge-currency-theft"},{"credibility":2,"name":"FBI: North Korean Hackers Stole $100 Million in Harmony Crypto Hack — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/fbi-north-korean-hackers-stole-100-million-in-harmony-crypto-hack/"},{"credibility":2,"name":"FBI Confirms North Korea's Lazarus Group as Hackers Behind Harmony Bridge Theft — Elliptic","type":"research","url":"https://www.elliptic.co/blog/analysis/fbi-confirms-north-korea-s-lazarus-group-as-hackers-behind-100-million-harmony-horizon-bridge-theft"}]},{"content":"On June 3, 2023, users of the self-custody Atomic Wallet application reported widespread unauthorized fund drains. Blockchain analytics firm Elliptic attributed the theft to Lazarus Group on June 6, 2023, based on on-chain patterns consistent with prior Lazarus operations. Total losses were subsequently estimated at over $100 million across approximately 5,500 compromised wallets. The FBI issued warnings in August 2023 that North Korean hackers were preparing to cash out approximately $40 million in stolen cryptocurrency held across six Bitcoin wallets, and published a separate advisory identifying cryptocurrency funds stolen by DPRK-affiliated actors in the broader summer 2023 campaign. Lazarus Group conducted four attacks against crypto entities in the period following the Atomic Wallet heist — CoinsPaid ($37.3 million), Alphapo ($60 million), and Stake.com ($41 million) — totaling approximately $240 million.","heading":"Atomic Wallet Hack — June 2023 (~$100 Million)","severity":"critical","sources":[{"credibility":1,"name":"FBI Identifies Cryptocurrency Funds Stolen by DPRK — FBI.gov","type":"regulatory","url":"https://www.fbi.gov/news/press-releases/fbi-identifies-cryptocurrency-funds-stolen-by-dprk"},{"credibility":2,"name":"North Korean Hackers Pocketed More Than $100M in Atomic Wallet Hack — Decrypt","type":"news_article","url":"https://decrypt.co/144444/north-korean-hackers-pocket-over-100-m-in-atomic-wallet-heist"},{"credibility":2,"name":"Lazarus Hackers Linked to the $35 Million Atomic Wallet Heist — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/lazarus-hackers-linked-to-the-35-million-atomic-wallet-heist/"},{"credibility":1,"name":"FBI Says North Korean Hackers Preparing to Cash Out After High-Profile Crypto Hacks — TechCrunch","type":"news_article","url":"https://techcrunch.com/2023/08/23/fbi-north-korea-lazarus-crypto/"}]},{"content":"In July 2024, India's largest cryptocurrency exchange WazirX suffered a security breach resulting in the theft of approximately $234.9 million in digital assets — representing roughly 45% of the exchange's total crypto holdings — from a multi-signature wallet held under a third-party custody arrangement with Liminal Custody. On January 14, 2025, the governments of the United States, Japan, and South Korea issued a joint statement formally attributing the hack to North Korea's Lazarus Group and identifying it as part of a broader pattern of DPRK-linked cyber theft operations that stole over $659 million in cryptocurrency across 2024. The attack involved social engineering, phishing, and API exploitation techniques. The attackers allegedly created a fake WazirX account, deposited tokens to build apparent legitimacy, and then conducted multi-stage wallet drains progressing from hot to cold wallets.","heading":"WazirX Hack — July 2024 ($235 Million)","severity":"critical","sources":[{"credibility":2,"name":"WazirX's $235M Hack Linked to North Korea — Business Standard","type":"news_article","url":"https://www.business-standard.com/companies/news/wazirx-crypto-hack-north-korea-us-japan-south-korea-response-125011500597_1.html"},{"credibility":2,"name":"North Korea Stole Over $659M in Crypto Heists During 2024, Deployed Fake Job Seekers — TechCrunch","type":"news_article","url":"https://techcrunch.com/2025/01/14/north-korea-stole-over-659m-in-crypto-heists-during-2024-deploys-fake-job-seekers/"},{"credibility":2,"name":"$235 Million Lost by WazirX in North Korea-Linked Breach — Elliptic","type":"research","url":"https://www.elliptic.co/blog/235-million-lost-by-wazirx-in-north-korea-linked-breach"},{"credibility":2,"name":"Joint Statement on North Korea's Involvement in $659M Crypto Thefts — WazirX Blog","type":"official","url":"https://wazirx.com/blog/a-joint-statement-highlights-north-koreas-involvement-in-659m-crypto-thefts/"}]},{"content":"The U.S. Treasury's OFAC first designated Lazarus Group on April 3, 2018 (as 'Lazarus Group' under North Korea Sanctions Regulations), and expanded sanctions on September 13, 2019, to cover the Bluenoroff and Andariel sub-clusters. OFAC subsequently updated the Lazarus Group SDN entry on April 14, 2022, to include the Ethereum address used in the Ronin Bridge hack. On March 2, 2020, Treasury sanctioned two Chinese nationals alleged to have laundered over $100 million in cryptocurrency on behalf of Lazarus Group. In May 2022, OFAC designated the Blender.io virtual currency mixer — the first-ever U.S. sanctions action against a cryptocurrency mixer — citing its role in laundering proceeds from the Ronin Bridge hack. On March 12, 2026, OFAC sanctioned six additional individuals and two entities for their roles in North Korean government-orchestrated IT worker fraud schemes supporting the RGB and Lazarus Group operations.","heading":"OFAC Sanctions and Regulatory Designations","severity":"critical","sources":[{"credibility":1,"name":"Treasury Sanctions North Korean State-Sponsored Malicious Cyber Groups — U.S. Department of the Treasury (Sept 2019)","type":"regulatory","url":"https://home.treasury.gov/news/press-releases/sm774"},{"credibility":1,"name":"Treasury Sanctions Individuals Laundering Cryptocurrency for Lazarus Group — U.S. Department of the Treasury (March 2020)","type":"regulatory","url":"https://home.treasury.gov/news/press-releases/sm924"},{"credibility":2,"name":"OFAC Sanctions Individuals, Entities, and Crypto Wallets Associated with North Korean Cyber Activities — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/ofac-sanctions-individuals-entities-and-crypto-wallets-associated-with-north-korean-cyber-activities"},{"credibility":1,"name":"U.S. Treasury Issues First-Ever Sanctions on a Virtual Currency Mixer — Treasury.gov","type":"regulatory","url":"https://home.treasury.gov/news/press-releases/jy0768"}]},{"content":"Lazarus Group employs a layered set of offensive cyber capabilities spanning social engineering, supply chain compromise, spear-phishing, and custom malware deployment. The TraderTraitor sub-cluster specializes in cryptocurrency exchange targeting and is characterized by simultaneous multi-employee social engineering to achieve initial access. Documented attack vectors include: (1) Operation Dream Job / fake recruiter campaigns distributing trojanized coding challenges via GitHub to developers at crypto firms; (2) Supply chain attacks targeting wallet infrastructure providers, as demonstrated by the Safe{Wallet} compromise in the Bybit heist; (3) Deployment of custom malware families including RN Loader, RN Stealer (harvesting SSH keys, credentials, cloud configs), and TraderTraitor-branded malicious applications; (4) Session token theft to pivot from developer workstations into cloud infrastructure (AWS S3, CloudFront); (5) Front-end JavaScript injection to manipulate transaction signing interfaces and induce authorized signers to approve fraudulent transactions. Post-theft laundering typically involves rapid conversion through mixing services, cross-chain bridges, and peer-to-peer exchangers, dispersing funds across thousands of addresses to complicate tracing. The group has also extensively used Tornado Cash, RAILGUN, and the now-sanctioned Blender.io mixer.","heading":"Tactics, Techniques, and Procedures (TTPs)","severity":"high","sources":[{"credibility":2,"name":"TraderTraitor: Deep Dive — Wiz Blog","type":"research","url":"https://www.wiz.io/blog/north-korean-tradertraitor-crypto-heist"},{"credibility":2,"name":"Crypto and Social Engineering: North Korean APTs in 2024 — CyberProof","type":"research","url":"https://www.cyberproof.com/blog/crypto-social-engineering-north-korean-apts-in-2024/"},{"credibility":2,"name":"Bybit Hack: In-Depth Technical Analysis — NCC Group","type":"research","url":"https://www.nccgroup.com/research/in-depth-technical-analysis-of-the-bybit-hack/"}]},{"content":"Prior to focusing predominantly on cryptocurrency theft, Lazarus Group conducted a series of high-profile cyberattacks. The 2014 Sony Pictures Entertainment hack, attributed by the FBI, involved the destruction of data, release of sensitive internal communications, and an extortion demand related to the film 'The Interview.' In February 2016, the group exploited the SWIFT interbank messaging network to fraudulently transfer $81 million from Bangladesh Bank's account at the Federal Reserve Bank of New York to accounts in the Philippines; the full $1 billion attempt was partially foiled by a spelling error in one transfer request. In May 2017, Lazarus Group deployed the WannaCry 2.0 ransomware worm, which infected an estimated 200,000 computers across 150 countries, causing billions of dollars in damages globally and severely impacting the UK's National Health Service.","heading":"Historical Non-Crypto Operations","severity":"high","sources":[{"credibility":1,"name":"DOJ Charges: North Korean Regime-Backed Programmer Charged — Justice.gov","type":"court_filing","url":"https://www.justice.gov/archives/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyber-attacks-and"},{"credibility":2,"name":"Bangladesh Bank Robbery — Wikipedia","type":"other","url":"https://en.wikipedia.org/wiki/Bangladesh_Bank_robbery"},{"credibility":1,"name":"U.S. Charges North Korean Operative in Conspiracy to Hack Sony Pictures, Banks — Washington Post","type":"news_article","url":"https://www.washingtonpost.com/world/national-security/justice-department-to-announce-hacking-charges-against-north-korean-operative-the-charge--stemming-from-the-2014-sony-pictures-case--is-the-first-against-a-pyongyang-spy/2018/09/06/f477bfb2-b1d0-11e8-9a6a-565d92a3585d_story.html"}]},{"content":"A United Nations Panel of Experts estimated in 2024 that illicit North Korean cyber activity — predominantly cryptocurrency theft — accounts for approximately 40% of the funding for Pyongyang's weapons of mass destruction programs. The panel further estimated that North Korea had stolen more than $3 billion in cryptocurrency since 2017. In 2024, Chainalysis reported that DPRK-linked hacking groups stole $1.3 billion across 47 incidents, more than doubling the $660 million stolen in 2023. According to The Hacker News, DPRK-linked actors stole $2.02 billion in 2025 alone — a 51% increase year-over-year — representing approximately 60% of all global crypto theft that year. Cumulative all-time estimates of Lazarus Group's cryptocurrency theft range from approximately $3.4 billion (conservative, Lazarus Group alone since 2007) to over $6.75 billion (inclusive of all DPRK-affiliated actors across all platforms). Cryptocurrency theft is understood to provide the DPRK regime with hard currency to circumvent international sanctions imposed over its nuclear weapons and ballistic missile programs.","heading":"UN Panel Reports and Strategic Context","severity":"high","sources":[{"credibility":2,"name":"North Korea-Linked Hackers Steal $2.02 Billion in 2025, Leading Global Crypto Theft — The Hacker News","type":"news_article","url":"https://thehackernews.com/2025/12/north-korea-linked-hackers-steal-202.html"},{"credibility":2,"name":"North Korean Crypto Hacks Escalate in Record Year of Theft and Laundering — The Block","type":"news_article","url":"https://www.theblock.co/post/381841/north-korean-crypto-hacks-escalate-2025"},{"credibility":2,"name":"The Lazarus Group Playbook: Inside North Korea's $6.75B All-Time Crypto Theft Operation — BlockEden.xyz","type":"research","url":"https://blockeden.xyz/blog/2026/02/03/lazarus-group-playbook-north-korea-crypto-theft-6-75-billion/"},{"credibility":2,"name":"The ByBit Heist and the Future of U.S. Crypto Regulation — CSIS","type":"research","url":"https://www.csis.org/analysis/bybit-heist-and-future-us-crypto-regulation"}]},{"content":"In April 2026, media reports indicated that North Korean hackers, alleged to be affiliated with Lazarus Group, were tied to a $290 million cryptocurrency theft involving KelpDAO and LayerZero-related infrastructure. Attribution at time of reporting remained at the investigative stage by private blockchain analytics firms, without formal FBI or OFAC confirmation. This alleged incident was characterized as the latest in a continuing escalation of DPRK-linked cryptocurrency theft.","heading":"2026 Activity — Alleged KelpDAO / LayerZero Theft","severity":"high","sources":[{"credibility":2,"name":"North Korean Hackers Tied to $290M Crypto Heist, Firm Says — UPI","type":"news_article","url":"https://www.upi.com/Top_News/World-News/2026/04/22/KelpDAO-LayerZero-North-Korea-crypto-hack-theft-Lazarus-Group/6151776848419/"},{"credibility":2,"name":"North Korean Hacker Group Lazarus Suspected Behind US$300M Crypto Heist — Malay Mail","type":"news_article","url":"https://www.malaymail.com/news/world/2026/04/22/north-korean-hacker-group-lazarus-suspected-behind-us300m-crypto-heist/217247"}]},{"body":"Lazarus Group is a North Korean state-sponsored hacking collective first identified around 2009. The U.S. government, along with international cybersecurity agencies, attributes the group to the Reconnaissance General Bureau (RGB), a military intelligence arm of the Democratic People's Republic of Korea (DPRK). The group operates under numerous aliases across the cybersecurity community, including APT38, BlueNorOff, AndAriel, Hidden Cobra, ZINC, Diamond Sleet, Stardust Chollima, Guardians of Peace, and TraderTraitor. A North Korean defector, Kim Kuk-song, has identified the group's internal designation as the '414 Liaison Office.' The U.S. Department of Justice formally asserts that the group 'is part of the North Korean government's strategy to undermine global cybersecurity and generate illicit revenue in violation of international sanctions.' The FBI, NSA, CISA, and the U.S. Treasury Department have all issued formal attributions and advisories regarding the group's operations. OFAC added Lazarus Group to the Specially Designated Nationals (SDN) list on April 14, 2022.","heading":"Overview and Attribution","severity":"critical","sources":[{"credibility":2,"name":"Lazarus Group - Wikipedia","type":"other","url":"https://en.wikipedia.org/wiki/Lazarus_Group"},{"credibility":1,"name":"OFAC SDN Listing: Lazarus Group","type":"regulatory","url":"https://sanctionssearch.ofac.treas.gov/Details.aspx?id=27307"},{"credibility":2,"name":"U.S. Charges 3 North Korean Hackers Over $1.3 Billion Cryptocurrency Heist - The Hacker News","type":"news_article","url":"https://thehackernews.com/2021/02/us-charges-3-north-korean-hackers-over.html"}]},{"body":"The U.S. Department of Justice has indicted three named members of Lazarus Group. Park Jin Hyok (age 36 at time of indictment) was first indicted in September 2018, with charges expanded in a superseding indictment filed February 2021. Jon Chang Hyok (age 31) and Kim Il (age 27) were both indicted in February 2021. All three are alleged members of units within the RGB and are charged with conspiracy to commit computer fraud and conspiracy to commit wire and bank fraud. The indictment alleges they were responsible for the 2014 Sony Pictures Entertainment hack, thefts from financial institutions across Asia and Africa via the SWIFT banking network, the 2016 Bangladesh Bank heist (in which approximately $81 million was successfully transferred of a $1 billion attempt), creation and global deployment of the WannaCry 2.0 ransomware, and thefts and extortion totaling more than $1.3 billion in cash and cryptocurrency. None of the three individuals are in U.S. custody. The FBI maintains a most-wanted listing for Park Jin Hyok.","heading":"DOJ Indictments: Park Jin Hyok, Jon Chang Hyok, Kim Il","severity":"critical","sources":[{"credibility":1,"name":"DOJ: 3 North Korean Military Hackers Indicted - Central District of California","type":"court_filing","url":"https://www.justice.gov/usao-cdca/pr/3-north-korean-military-hackers-indicted-wide-ranging-scheme-commit-cyber-attacks-and"},{"credibility":1,"name":"FBI Cyber Most Wanted: Park Jin Hyok","type":"regulatory","url":"https://www.fbi.gov/wanted/cyber/park-jin-hyok"},{"credibility":2,"name":"U.S. Charges 3 North Korean Hackers Over $1.3 Billion Cryptocurrency Heist - The Hacker News","type":"news_article","url":"https://thehackernews.com/2021/02/us-charges-3-north-korean-hackers-over.html"},{"credibility":1,"name":"NPR: 3 North Korean Hackers Charged By Justice Department For Global Attacks","type":"news_article","url":"https://www.npr.org/2021/02/17/968652939/justice-department-charges-3-north-korean-hackers-for-global-cyberattacks"}]},{"body":"On March 23, 2022, attackers compromised the Ronin Network, a sidechain connected to Ethereum that supports the play-to-earn game Axie Infinity. The exploit drained 173,600 ETH and 25.5 million USDC, valued at approximately $620–625 million at the time. The attack was not discovered for six days, becoming apparent on March 29, 2022 when a user reported being unable to withdraw 5,000 ETH from the bridge. The theft was executed by compromising five of the nine Ronin validator node private keys through social engineering. OFAC formally attributed the attack to Lazarus Group on April 14, 2022, sanctioning the primary attacker Ethereum wallet address 0x098B716B8Aaf21512996dC57EB0615e2383E2f96. The FBI and Treasury Department confirmed the attribution simultaneously. Stolen USDC was swapped for ETH through decentralized exchanges to avoid AML/KYC controls. Attackers subsequently routed at least $80.3 million through Tornado Cash to obfuscate the trail, with laundering leveraging over 12,000 different crypto addresses. Remaining funds were tracked by on-chain analysts from Elliptic and Chainalysis. This was the largest individual cryptocurrency hack at the time.","heading":"Ronin Bridge Hack (March 2022) — $620 Million","severity":"critical","sources":[{"credibility":2,"name":"US Officials Tie North Korea's Lazarus Hackers to $625M Ronin Exploit - CoinDesk","type":"news_article","url":"https://www.coindesk.com/policy/2022/04/14/us-officials-tie-north-korean-hacker-group-to-axies-ronin-exploit"},{"credibility":2,"name":"Elliptic: North Korea's Lazarus Group Identified as Exploiters Behind Ronin Bridge Heist","type":"research","url":"https://www.elliptic.co/blog/540-million-stolen-from-the-ronin-defi-bridge"},{"credibility":2,"name":"Chainalysis: Axie Infinity Ronin Bridge DPRK Hack Seizure","type":"research","url":"https://www.chainalysis.com/blog/axie-infinity-ronin-bridge-dprk-hack-seizure/"},{"credibility":1,"name":"CNBC: Ronin Hack — North Korea Linked to $615 Million Crypto Heist, U.S. Says","type":"news_article","url":"https://www.cnbc.com/2022/04/15/ronin-hack-north-korea-linked-to-615-million-crypto-heist-us-says.html"},{"credibility":2,"name":"Lazarus Group Responsible for Ronin Bridge Hack, Says US Treasury - Coinspeaker","type":"news_article","url":"https://www.coinspeaker.com/lazarus-group-ronin-bridge-hack/"}]},{"body":"On June 24, 2022, Lazarus Group exploited Harmony's Horizon Ethereum bridge, stealing approximately $100 million in crypto assets across 11 transactions. Stolen assets included ETH, Binance Coin, Tether, USD Coin, and DAI. Attackers converted the stolen assets to approximately 85,837 ETH through Tornado Cash to launder the proceeds. The FBI formally confirmed Lazarus Group's responsibility for the Harmony Horizon Bridge theft in a public statement. On January 13, 2023, North Korean cyber actors used RAILGUN, a privacy protocol, to launder over $60 million worth of ETH from this theft. Binance detected laundering attempts through the Huobi exchange and assisted in freezing and recovering some deposited assets. The FBI stated that the group used the RAILGUN privacy protocol specifically to evade detection after Tornado Cash was sanctioned by OFAC in August 2022.","heading":"Harmony Horizon Bridge Hack (June 2022) — $100 Million","severity":"critical","sources":[{"credibility":1,"name":"FBI Press Release: Lazarus Group Responsible for Harmony's Horizon Bridge Theft","type":"regulatory","url":"https://www.fbi.gov/news/press-releases/fbi-confirms-lazarus-group-cyber-actors-responsible-for-harmonys-horizon-bridge-currency-theft"},{"credibility":2,"name":"BleepingComputer: FBI — North Korean Hackers Stole $100 Million in Harmony Crypto Hack","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/fbi-north-korean-hackers-stole-100-million-in-harmony-crypto-hack/"},{"credibility":2,"name":"Elliptic: Harmony Horizon Bridge Hack Briefing","type":"research","url":"https://www.elliptic.co/hubfs/Harmony%20Horizon%20Bridge%20Hack%20P1%20briefing%20note%20final.pdf"},{"credibility":1,"name":"TechCrunch: North Korean Lazarus Hackers Linked to Harmony Bridge Theft","type":"news_article","url":"https://techcrunch.com/2022/06/30/north-korea-lazarus-harmony-theft/"}]},{"body":"On February 21, 2025, Lazarus Group (operating under the TraderTraitor designation) carried out the single largest cryptocurrency theft in history, stealing approximately $1.5 billion USD — approximately 401,000 ETH — from Bybit, one of the world's largest cryptocurrency exchanges. The FBI confirmed attribution in a public service announcement issued February 26, 2025. The attack exploited a compromised developer machine at Safe{Wallet}, a multi-signature wallet platform used by Bybit, allowing attackers to intercept a scheduled transfer between Bybit's cold and hot wallets and redirect funds to attacker-controlled addresses. Within 48 hours, at least $160 million had been funneled through illicit channels; by February 26, over $400 million had been laundered. Attackers converted stolen ETH to Bitcoin and other virtual assets dispersed across thousands of addresses on multiple blockchains. The FBI's IC3 PSA released a list of 51 Ethereum addresses linked to the theft and urged private sector entities — including RPC node operators, exchanges, bridges, blockchain analytics firms, and DeFi services — to block transactions involving those addresses. Known TraderTraitor-linked Ethereum addresses from the FBI statement include: 0x51E9d833Ecae4E8D9D8Be17300AEE6D3398C135D, 0x96244D83DC15d36847C35209bBDc5bdDE9bEc3D8, 0x83c7678492D623fb98834F0fbcb2E7b7f5Af8950, and 0x15ec300a4895a86322f1a27dd9ba0b9f8297e65d (also linked to prior Phemex, BingX, and Poloniex breaches). This single theft exceeded Lazarus Group's entire reported haul for 2024.","heading":"Bybit Exchange Hack (February 2025) — $1.5 Billion","severity":"critical","sources":[{"credibility":1,"name":"FBI IC3 PSA: North Korea Responsible for $1.5 Billion Bybit Hack","type":"regulatory","url":"https://www.ic3.gov/psa/2025/psa250226"},{"credibility":2,"name":"BleepingComputer: FBI Confirms Lazarus Hackers Were Behind $1.5B Bybit Crypto Heist","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/fbi-confirms-lazarus-hackers-were-behind-15b-bybit-crypto-heist/"},{"credibility":1,"name":"CSIS: The ByBit Heist and the Future of U.S. Crypto Regulation","type":"research","url":"https://www.csis.org/analysis/bybit-heist-and-future-us-crypto-regulation"},{"credibility":2,"name":"TRM Labs: The Bybit Hack — Following North Korea's Largest Exploit","type":"research","url":"https://www.trmlabs.com/resources/blog/the-bybit-hack-following-north-koreas-largest-exploit"},{"credibility":1,"name":"UPI: North Korea Behind $1.5 Billion Crypto Theft, FBI Confirms","type":"news_article","url":"https://www.upi.com/Top_News/World-News/2025/02/27/North-Korea-Bybit-crypto-heist-15-billion-FBI-Lazarus/8591740642756/"}]},{"body":"On July 18, 2024, Lazarus Group attacked Indian cryptocurrency exchange WazirX, draining $234.9 million in crypto assets. The attack involved creating a fake WazirX account, depositing tokens, and purchasing GALA tokens to drain the hot wallet. Attackers then targeted the cold wallet by exploiting a multisig wallet mechanism: when WazirX signatories accessed the wallet, the attackers altered the controlling smart contract, granting themselves full control. The compromised Ethereum wallet address reported in connection with the hack is 0x27fD43BABfbe83a81d14665b1a6fB8030A60C9b4. The United States, Japan, and South Korea issued a joint statement confirming Lazarus Group's responsibility. The WazirX hack was the second-largest individual crypto hack of 2024.","heading":"WazirX Exchange Hack (July 2024) — $234.9 Million","severity":"critical","sources":[{"credibility":2,"name":"2024 WazirX Hack - Wikipedia","type":"other","url":"https://en.wikipedia.org/wiki/2024_WazirX_hack"},{"credibility":1,"name":"Business Standard: WazirX Crypto Hack North Korea — US, Japan, South Korea Response","type":"news_article","url":"https://www.business-standard.com/companies/news/wazirx-crypto-hack-north-korea-us-japan-south-korea-response-125011500597_1.html"},{"credibility":2,"name":"Crystal Intelligence: Expert Analysis — How the $230M WazirX Hack Happened","type":"research","url":"https://crystalintelligence.com/investigations/expert-analysis-wazirx-hack/"}]},{"body":"Beyond the largest hacks, Lazarus Group has conducted numerous other major cryptocurrency thefts. In June 2023, the group attacked Atomic Wallet, a non-custodial decentralized crypto wallet, stealing over $100 million from approximately 5,500 compromised customer wallets across multiple transactions beginning June 3, 2023; at least ten addresses lost more than $1 million each. Proceeds were laundered in part through sanctioned Russian exchange Garantex. In September 2023, the FBI confirmed Lazarus Group responsible for the theft of $41 million from online crypto casino Stake.com. In July 2023, approximately $60 million was stolen from payment processor Alphapo and crypto platform CoinsPaid on or about July 22, 2023. The 2020 KuCoin exchange hack, in which approximately $275 million was taken, was also attributed to Lazarus Group by Chainalysis. The DMM Bitcoin exchange in Japan was attacked in May 2024, losing approximately 4,502.9 BTC (approximately $305 million at time of theft) via private key compromise; the stolen bitcoin was laundered through Bitcoin CoinJoin mixing services, then bridged to other chains and sent to Huione Guarantee, a Cambodia-based marketplace. DMM Bitcoin shut down in December 2024.","heading":"Additional Significant Crypto Thefts","severity":"high","sources":[{"credibility":1,"name":"FBI Press Release: Lazarus Group Responsible for Theft of $41 Million from Stake.com","type":"regulatory","url":"https://www.fbi.gov/news/press-releases/fbi-identifies-lazarus-group-cyber-actors-as-responsible-for-theft-of-41-million-from-stakecom"},{"credibility":2,"name":"Elliptic: North Korea-Linked Atomic Wallet Heist Tops $100 Million","type":"research","url":"https://www.elliptic.co/blog/analysis/north-korea-linked-atomic-wallet-heist-tops-100-million"},{"credibility":2,"name":"Chainalysis: $2.2 Billion Stolen in Crypto in 2024","type":"research","url":"https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2025/"},{"credibility":2,"name":"Chainalysis: Lazarus Group Pulled Off 2020's Biggest Exchange Hack","type":"research","url":"https://www.chainalysis.com/blog/lazarus-group-kucoin-exchange-hack/"}]},{"body":"The FBI, CISA, and U.S. Treasury Department issued a joint cybersecurity advisory (AA22-108A) in April 2022 describing the TraderTraitor campaign in detail. Lazarus Group initiates intrusions via spearphishing, targeting employees of cryptocurrency companies in system administration and software development roles with messages appearing as high-paying job recruitment offers. Victims are lured into downloading malicious cryptocurrency applications written in cross-platform JavaScript using the Node.js runtime and Electron framework — applications that purport to be cryptocurrency trading or price prediction tools. The group also conducts social engineering of exchange validators and multi-signature wallet signatories to gain access to private keys. In 2023, TraderTraitor expanded into open-source software supply chain attacks — one of the first known cases of a nation-state APT leveraging public package repositories as an attack vector. The Safe{Wallet} supply chain attack used in the 2025 Bybit heist exemplifies this evolution: attackers compromised a developer machine at a third-party software provider to intercept and manipulate legitimate multi-signature transactions. Private key compromise accounted for 43.8% of all stolen crypto in 2024 globally, a pattern consistent with Lazarus Group's known methods.","heading":"TraderTraitor Malware Campaign and Attack Methods","severity":"high","sources":[{"credibility":1,"name":"CISA Advisory AA22-108A: TraderTraitor — North Korean State-Sponsored APT Targets Blockchain Companies","type":"regulatory","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-108a"},{"credibility":2,"name":"Elliptic: How the Lazarus Group Is Stepping Up Crypto Hacks and Changing Its Tactics","type":"research","url":"https://www.elliptic.co/blog/how-the-lazarus-group-is-stepping-up-crypto-hacks-and-changing-its-tactics"},{"credibility":2,"name":"TRM Labs: North Korea's Lazarus Group Moves Funds Through Tornado Cash","type":"research","url":"https://www.trmlabs.com/resources/blog/north-koreas-lazarus-group-moves-funds-through-tornado-cash"}]},{"body":"Lazarus Group employs a layered laundering infrastructure to convert stolen cryptocurrency into usable funds for the North Korean state. Primary methods include decentralized exchange (DEX) swaps to convert non-ETH assets into ETH — bypassing AML/KYC controls at centralized exchanges — followed by use of mixing services including Tornado Cash (sanctioned by OFAC in August 2022) and RAILGUN privacy protocol. The group has laundered proceeds through over 12,000 unique crypto addresses in a single campaign (Ronin Bridge). Cross-chain bridges and conversion to Bitcoin via CoinJoin mixers are also documented laundering paths. Chainalysis reported that between June 2023 and February 2024, Huione Pay — a Cambodia-based payment company — received cryptocurrency worth over $150,000 from a digital wallet used by Lazarus Group. OFAC issued its first-ever sanctions on a virtual currency mixer targeting Blender.io in May 2022, citing Lazarus Group's use of the service to launder $20.5 million in Ronin Bridge proceeds. The group subsequently shifted to Tornado Cash, which OFAC sanctioned in August 2022. Total laundering activity attributed to Lazarus Group across 2022–2023 exceeded $900 million, per Bitdefender analysis.","heading":"Money Laundering Infrastructure","severity":"high","sources":[{"credibility":1,"name":"U.S. Treasury: First-Ever Sanctions on a Virtual Currency Mixer — Targets DPRK Cyber Threats","type":"regulatory","url":"https://home.treasury.gov/news/press-releases/jy0768"},{"credibility":2,"name":"Chainalysis: OFAC Sanctions Tornado Cash for Laundering Crypto Stolen by Lazarus Group","type":"research","url":"https://www.chainalysis.com/blog/tornado-cash-ofac-designation-sanctions/"},{"credibility":2,"name":"Elliptic: Further Sanctions Against North Korea's Lazarus Group for Laundering Stolen Ronin Funds","type":"research","url":"https://www.elliptic.co/blog/further-sanctions-against-north-koreas-lazarus-group-for-laundering-stolen-ronin-funds"},{"credibility":2,"name":"Bitdefender: North Korea-Linked Lazarus Group Laundered $900 Million in Crypto","type":"news_article","url":"https://www.bitdefender.com/en-us/blog/hotforsecurity/north-korea-linked-lazarus-group-laundered-900-million-in-crypto"}]},{"body":"Lazarus Group's cryptocurrency theft has escalated dramatically in scale over time. Chainalysis data shows DPRK-linked actors stole $660.5 million across 20 incidents in 2023, $1.34 billion across 47 incidents in 2024 (a 102.88% year-over-year increase, representing 61% of all global crypto theft that year), and approximately $2.02–$2.06 billion across 80 incidents in 2025. The Bybit hack alone ($1.5 billion, February 2025) exceeded the group's entire 2024 haul. Q1 2026 has seen an additional $309 million stolen across 12 incidents. Cumulative cryptocurrency theft attributed to Lazarus Group since 2017 is estimated at $6.75 billion by multiple blockchain analytics firms. The group's stolen funds are assessed by U.S. authorities to directly finance North Korea's nuclear and ballistic missile programs and fund other sanctioned state activities.","heading":"Scale of Operations: Cumulative Theft Estimates","severity":"critical","sources":[{"credibility":2,"name":"Chainalysis: $2.2 Billion Stolen in Crypto in 2024","type":"research","url":"https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2025/"},{"credibility":2,"name":"CyberScoop: Crypto Analysts Stunned by Lazarus Group's Capabilities in $1.46B Bybit Theft","type":"news_article","url":"https://cyberscoop.com/bybit-lazarus-group-north-korea-ethereum/"},{"credibility":2,"name":"Elliptic: How the Lazarus Group Is Stepping Up Crypto Hacks and Changing Its Tactics","type":"research","url":"https://www.elliptic.co/blog/how-the-lazarus-group-is-stepping-up-crypto-hacks-and-changing-its-tactics"}]},{"body":"Lazarus Group's documented operations predate its cryptocurrency focus. The earliest attributed activity is 'Operation Troy' (2009–2012), a cyber-espionage campaign using DDoS techniques against the South Korean government. In November 2014, the group launched a destructive attack against Sony Pictures Entertainment in alleged retaliation for the film 'The Interview,' stealing confidential data including unreleased films, executive communications, and approximately 4,000 employee records, while causing estimated damages of $35–85 million in recovery costs. In February 2016, the group executed the Bangladesh Bank cyber heist, issuing 35 fraudulent SWIFT network instructions attempting to transfer $951 million from the Federal Reserve Bank of New York; five instructions successfully transferred $101 million, of which approximately $81 million was unrecovered. In May 2017, Lazarus Group deployed WannaCry 2.0 ransomware, infecting more than 200,000 computers across 150 countries including the UK's National Health Service, Boeing, and universities in China. These operations established Lazarus Group's pattern of combining cyber-espionage, financial crime, and destructive attacks on behalf of the North Korean state.","heading":"Pre-Crypto Operations: Sony, Bangladesh Bank, WannaCry","severity":"high","sources":[{"credibility":2,"name":"Lazarus Group - Wikipedia","type":"other","url":"https://en.wikipedia.org/wiki/Lazarus_Group"},{"credibility":2,"name":"Bangladesh Bank Robbery - Wikipedia","type":"other","url":"https://en.wikipedia.org/wiki/Bangladesh_Bank_robbery"},{"credibility":2,"name":"NCC Group: The Lazarus Group — North Korean Scourge for 10+ Years","type":"research","url":"https://www.nccgroup.com/the-lazarus-group-north-korean-scourge-for-plus10-years/"}]},{"body":"The U.S. Treasury's Office of Foreign Assets Control (OFAC) has imposed multiple rounds of sanctions directly linked to Lazarus Group activity. On April 14, 2022, OFAC placed Lazarus Group on the SDN list and sanctioned the primary Ronin Bridge attacker Ethereum wallet 0x098B716B8Aaf21512996dC57EB0615e2383E2f96. In May 2022, OFAC identified four additional virtual currency wallet addresses used by Lazarus Group to launder remaining Ronin Bridge proceeds. In August 2022, OFAC sanctioned Tornado Cash mixer, listing 38 unique cryptocurrency addresses as identifiers, citing Lazarus Group's use of the mixer to launder $455 million from the Ronin Bridge hack. Additional TraderTraitor-linked Ethereum addresses published by the FBI in connection with the February 2025 Bybit hack include 0x51E9d833Ecae4E8D9D8Be17300AEE6D3398C135D, 0x96244D83DC15d36847C35209bBDc5bdDE9bEc3D8, 0x83c7678492D623fb98834F0fbcb2E7b7f5Af8950, and 0x15ec300a4895a86322f1a27dd9ba0b9f8297e65d (the latter also linked to prior Phemex, BingX, and Poloniex breaches). U.S. persons are prohibited from transacting with OFAC-sanctioned addresses.","heading":"OFAC Sanctions and Known Sanctioned Wallet Addresses","severity":"critical","sources":[{"credibility":1,"name":"OFAC SDN Listing: Lazarus Group","type":"regulatory","url":"https://sanctionssearch.ofac.treas.gov/Details.aspx?id=27307"},{"credibility":2,"name":"CoinTelegraph: US Treasury Dept Sanctions 3 Ethereum Addresses Allegedly Linked to North Korea","type":"news_article","url":"https://cointelegraph.com/news/us-treasury-dept-sanctions-3-ethereum-addresses-allegedly-linked-to-north-korea"},{"credibility":2,"name":"Chainalysis: OFAC Sanctions Tornado Cash for Laundering Crypto Stolen by Lazarus Group","type":"research","url":"https://www.chainalysis.com/blog/tornado-cash-ofac-designation-sanctions/"},{"credibility":1,"name":"FBI IC3 PSA: North Korea Responsible for $1.5 Billion Bybit Hack","type":"regulatory","url":"https://www.ic3.gov/psa/2025/psa250226"},{"credibility":1,"name":"OFAC Cyber-Related Designation August 8, 2022","type":"regulatory","url":"https://ofac.treasury.gov/recent-actions/20220808"}]}],"sources_used":[{"archive_timestamp":"2026-05-15T20:49:17+00:00","archive_url":"http://web.archive.org/web/20260515204917/https://www.ic3.gov/PSA/2025/PSA250226","credibility":1,"name":"IC3 PSA250226 — North Korea Responsible for $1.5 Billion Bybit Hack (FBI)","type":"regulatory","url":"http://web.archive.org/web/20260515204917/https://www.ic3.gov/PSA/2025/PSA250226"},{"archive_timestamp":"2026-05-17T09:23:54+00:00","archive_url":"http://web.archive.org/web/20260517092354/https://home.treasury.gov/news/press-releases/sm774","credibility":1,"name":"Treasury Sanctions North Korean State-Sponsored Malicious Cyber Groups — Treasury.gov (SM774)","type":"regulatory","url":"https://home.treasury.gov/news/press-releases/sm774"},{"archive_timestamp":"2026-05-20T23:33:28+00:00","archive_url":"http://web.archive.org/web/20260520233328/https://home.treasury.gov/news/press-releases/sm924","credibility":1,"name":"Treasury Sanctions Individuals Laundering Cryptocurrency for Lazarus Group — Treasury.gov (SM924)","type":"regulatory","url":"http://web.archive.org/web/20260520233328/https://home.treasury.gov/news/press-releases/sm924"},{"archive_timestamp":null,"archive_url":null,"credibility":1,"name":"U.S. Treasury First-Ever Sanctions on a Virtual Currency Mixer (Blender.io) — Treasury.gov","type":"regulatory","url":"http://web.archive.org/web/20260526035433/https://home.treasury.gov/news/press-releases/jy0768"},{"archive_timestamp":"2026-05-07T14:49:18+00:00","archive_url":"http://web.archive.org/web/20260507144918/https://home.treasury.gov/news/press-releases/sb0190","credibility":1,"name":"Sanctions Imposed on DPRK IT Workers — Treasury.gov (SB0190)","type":"regulatory","url":"http://web.archive.org/web/20260507144918/https://home.treasury.gov/news/press-releases/sb0190"},{"archive_timestamp":null,"archive_url":null,"credibility":1,"name":"FBI Confirms Lazarus Group Responsible for Harmony's Horizon Bridge Theft — FBI.gov","type":"regulatory","url":"https://www.fbi.gov/news/press-releases/fbi-confirms-lazarus-group-cyber-actors-responsible-for-harmonys-horizon-bridge-currency-theft"},{"archive_timestamp":"2026-05-18T11:34:19+00:00","archive_url":"http://web.archive.org/web/20260518113419/https://www.fbi.gov/news/press-releases/fbi-identifies-lazarus-group-cyber-actors-as-responsible-for-theft-of-41-million-from-stakecom","credibility":1,"name":"FBI Identifies Lazarus Group as Responsible for Theft of $41 Million from Stake.com — FBI.gov","type":"regulatory","url":"http://web.archive.org/web/20260518113419/https://www.fbi.gov/news/press-releases/fbi-identifies-lazarus-group-cyber-actors-as-responsible-for-theft-of-41-million-from-stakecom"},{"archive_timestamp":"2026-04-28T07:36:11+00:00","archive_url":"http://web.archive.org/web/20260428073611/https://www.fbi.gov/news/press-releases/fbi-identifies-cryptocurrency-funds-stolen-by-dprk","credibility":1,"name":"FBI Identifies Cryptocurrency Funds Stolen by DPRK — FBI.gov","type":"regulatory","url":"http://web.archive.org/web/20260428073611/https://www.fbi.gov/news/press-releases/fbi-identifies-cryptocurrency-funds-stolen-by-dprk"},{"archive_timestamp":null,"archive_url":null,"credibility":1,"name":"DOJ — North Korean Regime-Backed Programmer Charged — Justice.gov","type":"court_filing","url":"http://web.archive.org/web/20260518175650/https://www.justice.gov/archives/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyber-attacks-and"},{"archive_timestamp":"2025-11-17T04:00:56+00:00","archive_url":"http://web.archive.org/web/20251117040056/https://sanctionssearch.ofac.treas.gov/Details.aspx?id=27307","credibility":1,"name":"Lazarus Group OFAC SDN Listing","type":"regulatory","url":"http://web.archive.org/web/20251117040056/https://sanctionssearch.ofac.treas.gov/Details.aspx?id=27307"},{"archive_timestamp":"2026-03-27T07:48:15+00:00","archive_url":"http://web.archive.org/web/20260327074815/https://www.coindesk.com/policy/2022/04/14/us-officials-tie-north-korean-hacker-group-to-axies-ronin-exploit","credibility":2,"name":"US Officials Tie North Korea's Lazarus Hackers to $625M Axie Infinity Crypto Theft — CoinDesk","type":"news_article","url":"http://web.archive.org/web/20260327074815/https://www.coindesk.com/policy/2022/04/14/us-officials-tie-north-korean-hacker-group-to-axies-ronin-exploit"},{"archive_timestamp":"2026-05-11T14:54:31+00:00","archive_url":"http://web.archive.org/web/20260511145431/https://www.coindesk.com/tech/2022/03/29/axie-infinitys-ronin-network-suffers-625m-exploit","credibility":2,"name":"Axie Infinity Ronin Network Suffers $625M Exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2022/03/29/axie-infinitys-ronin-network-suffers-625m-exploit"},{"archive_timestamp":null,"archive_url":null,"credibility":2,"name":"The Bybit Hack: Following North Korea's Largest Exploit — TRM Labs","type":"research","url":"http://web.archive.org/web/20260320024842/https://www.trmlabs.com/resources/blog/the-bybit-hack-following-north-koreas-largest-exploit"},{"archive_timestamp":"2026-05-05T09:58:54+00:00","archive_url":"http://web.archive.org/web/20260505095854/https://thehackernews.com/2025/02/bybit-hack-traced-to-safewallet-supply.html","credibility":2,"name":"Bybit Hack Traced to Safe{Wallet} Supply Chain Attack — The Hacker News","type":"news_article","url":"http://web.archive.org/web/20260505095854/https://thehackernews.com/2025/02/bybit-hack-traced-to-safewallet-supply.html"},{"archive_timestamp":"2026-04-20T23:34:45+00:00","archive_url":"http://web.archive.org/web/20260420233445/https://www.nccgroup.com/research/in-depth-technical-analysis-of-the-bybit-hack/","credibility":2,"name":"Bybit Hack: In-Depth Technical Analysis — NCC Group","type":"research","url":"http://web.archive.org/web/20260420233445/https://www.nccgroup.com/research/in-depth-technical-analysis-of-the-bybit-hack/"},{"archive_timestamp":null,"archive_url":null,"credibility":2,"name":"FBI Confirms Lazarus Group Behind $1.5 Billion Bybit Crypto Heist — BleepingComputer","type":"news_article","url":"http://web.archive.org/web/20260102100752/https://www.bleepingcomputer.com/news/security/fbi-confirms-lazarus-hackers-were-behind-15b-bybit-crypto-heist/"},{"archive_timestamp":"2026-03-11T03:52:21+00:00","archive_url":"http://web.archive.org/web/20260311035221/https://decrypt.co/144444/north-korean-hackers-pocket-over-100-m-in-atomic-wallet-heist","credibility":2,"name":"North Korean Hackers Pocketed More Than $100M in Atomic Wallet Hack — Decrypt","type":"news_article","url":"http://web.archive.org/web/20260311035221/https://decrypt.co/144444/north-korean-hackers-pocket-over-100-m-in-atomic-wallet-heist"},{"archive_timestamp":"2026-03-26T17:50:50+00:00","archive_url":"http://web.archive.org/web/20260326175050/https://www.elliptic.co/blog/235-million-lost-by-wazirx-in-north-korea-linked-breach","credibility":2,"name":"$235 Million Lost by WazirX in North Korea-Linked Breach — Elliptic","type":"research","url":"http://web.archive.org/web/20260326175050/https://www.elliptic.co/blog/235-million-lost-by-wazirx-in-north-korea-linked-breach"},{"archive_timestamp":"2025-11-14T17:53:58+00:00","archive_url":"http://web.archive.org/web/20251114175358/https://techcrunch.com/2025/01/14/north-korea-stole-over-659m-in-crypto-heists-during-2024-deploys-fake-job-seekers/","credibility":2,"name":"North Korea Stole Over $659M in Crypto Heists During 2024 — TechCrunch","type":"news_article","url":"https://techcrunch.com/2025/01/14/north-korea-stole-over-659m-in-crypto-heists-during-2024-deploys-fake-job-seekers/"},{"archive_timestamp":"2026-05-08T23:21:25+00:00","archive_url":"http://web.archive.org/web/20260508232125/https://thehackernews.com/2025/12/north-korea-linked-hackers-steal-202.html","credibility":2,"name":"North Korea-Linked Hackers Steal $2.02 Billion in 2025 — The Hacker News","type":"news_article","url":"http://web.archive.org/web/20260508232125/https://thehackernews.com/2025/12/north-korea-linked-hackers-steal-202.html"},{"archive_timestamp":null,"archive_url":null,"credibility":2,"name":"North Korean Crypto Hacks Escalate in Record Year — The Block","type":"news_article","url":"http://web.archive.org/web/20251231122406/https://www.theblock.co/post/381841/north-korean-crypto-hacks-escalate-2025"},{"archive_timestamp":"2026-03-09T19:19:46+00:00","archive_url":"http://web.archive.org/web/20260309191946/https://www.csis.org/analysis/bybit-heist-and-future-us-crypto-regulation","credibility":2,"name":"The ByBit Heist and the Future of U.S. Crypto Regulation — CSIS","type":"research","url":"http://web.archive.org/web/20260309191946/https://www.csis.org/analysis/bybit-heist-and-future-us-crypto-regulation"},{"archive_timestamp":null,"archive_url":null,"credibility":2,"name":"TraderTraitor: Deep Dive — Wiz Blog","type":"research","url":"https://www.wiz.io/blog/north-korean-tradertraitor-crypto-heist"},{"archive_timestamp":"2025-07-25T01:24:35+00:00","archive_url":"http://web.archive.org/web/20250725012435/https://techcrunch.com/2023/08/23/fbi-north-korea-lazarus-crypto/","credibility":1,"name":"FBI Says North Korean Hackers Preparing to Cash Out — TechCrunch","type":"news_article","url":"http://web.archive.org/web/20250725012435/https://techcrunch.com/2023/08/23/fbi-north-korea-lazarus-crypto/"},{"archive_timestamp":null,"archive_url":null,"credibility":2,"name":"The Lazarus Group Playbook: North Korea's $6.75B All-Time Crypto Theft — BlockEden.xyz","type":"research","url":"http://web.archive.org/web/20260525195814/https://blockeden.xyz/blog/2026/02/03/lazarus-group-playbook-north-korea-crypto-theft-6-75-billion/"},{"archive_timestamp":"2026-04-23T07:50:46+00:00","archive_url":"http://web.archive.org/web/20260423075046/https://www.upi.com/Top_News/World-News/2026/04/22/KelpDAO-LayerZero-North-Korea-crypto-hack-theft-Lazarus-Group/6151776848419/","credibility":2,"name":"North Korean Hackers Tied to $290M Crypto Heist (KelpDAO) — UPI","type":"news_article","url":"https://www.upi.com/Top_News/World-News/2026/04/22/KelpDAO-LayerZero-North-Korea-crypto-hack-theft-Lazarus-Group/6151776848419/"},{"archive_timestamp":"2026-03-23T17:16:55+00:00","archive_url":"http://web.archive.org/web/20260323171655/https://www.chainalysis.com/blog/ofac-targets-north-korean-it-workers-crypto-march-2026/","credibility":2,"name":"OFAC Targets DPRK IT Workers Using Crypto — Chainalysis","type":"research","url":"http://web.archive.org/web/20260323171655/https://www.chainalysis.com/blog/ofac-targets-north-korean-it-workers-crypto-march-2026/"},{"archive_timestamp":"2026-05-16T18:14:51+00:00","archive_url":"http://web.archive.org/web/20260516181451/https://en.wikipedia.org/wiki/Lazarus_Group","credibility":2,"name":"Lazarus Group — Wikipedia","type":"other","url":"http://web.archive.org/web/20260516181451/https://en.wikipedia.org/wiki/Lazarus_Group"},{"archive_timestamp":"2026-05-09T12:12:33+00:00","archive_url":"http://web.archive.org/web/20260509121233/https://en.wikipedia.org/wiki/Bangladesh_Bank_robbery","name":"https://en.wikipedia.org/wiki/Bangladesh_Bank_robbery","url":"https://en.wikipedia.org/wiki/Bangladesh_Bank_robbery"},{"archive_timestamp":"2026-05-12T04:33:16+00:00","archive_url":"http://web.archive.org/web/20260512043316/https://en.wikipedia.org/wiki/2024_WazirX_hack","name":"https://en.wikipedia.org/wiki/2024_WazirX_hack","url":"http://web.archive.org/web/20260512043316/https://en.wikipedia.org/wiki/2024_WazirX_hack"},{"archive_timestamp":"2026-04-21T10:49:32+00:00","archive_url":"http://web.archive.org/web/20260421104932/https://ofac.treasury.gov/recent-actions/20220808","name":"https://ofac.treasury.gov/recent-actions/20220808","url":"http://web.archive.org/web/20260421104932/https://ofac.treasury.gov/recent-actions/20220808"},{"archive_timestamp":null,"archive_url":null,"name":"https://www.fbi.gov/wanted/cyber/park-jin-hyok","url":"http://web.archive.org/web/20260514192333/https://www.fbi.gov/wanted/cyber/park-jin-hyok"},{"archive_timestamp":null,"archive_url":null,"name":"https://www.justice.gov/usao-cdca/pr/3-north-korean-military-hackers-indicted-wide-ranging-scheme-commit-cyber-attacks-and","url":"https://www.justice.gov/usao-cdca/pr/3-north-korean-military-hackers-indicted-wide-ranging-scheme-commit-cyber-attacks-and"},{"archive_timestamp":"2026-03-06T03:12:35+00:00","archive_url":"http://web.archive.org/web/20260306031235/https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-108a","name":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-108a","url":"http://web.archive.org/web/20260306031235/https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-108a"},{"archive_timestamp":"2026-05-18T22:42:42+00:00","archive_url":"http://web.archive.org/web/20260518224242/https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2025/","name":"https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2025/","url":"http://web.archive.org/web/20260518224242/https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2025/"},{"archive_timestamp":"2026-03-26T18:21:30+00:00","archive_url":"http://web.archive.org/web/20260326182130/https://www.chainalysis.com/blog/axie-infinity-ronin-bridge-dprk-hack-seizure/","name":"https://www.chainalysis.com/blog/axie-infinity-ronin-bridge-dprk-hack-seizure/","url":"http://web.archive.org/web/20260326182130/https://www.chainalysis.com/blog/axie-infinity-ronin-bridge-dprk-hack-seizure/"},{"archive_timestamp":"2026-03-03T01:47:26+00:00","archive_url":"http://web.archive.org/web/20260303014726/https://www.chainalysis.com/blog/tornado-cash-ofac-designation-sanctions/","name":"https://www.chainalysis.com/blog/tornado-cash-ofac-designation-sanctions/","url":"https://www.chainalysis.com/blog/tornado-cash-ofac-designation-sanctions/"},{"archive_timestamp":"2026-03-27T06:49:55+00:00","archive_url":"http://web.archive.org/web/20260327064955/https://www.chainalysis.com/blog/lazarus-group-kucoin-exchange-hack/","name":"https://www.chainalysis.com/blog/lazarus-group-kucoin-exchange-hack/","url":"http://web.archive.org/web/20260327064955/https://www.chainalysis.com/blog/lazarus-group-kucoin-exchange-hack/"},{"archive_timestamp":"2026-02-28T04:07:14+00:00","archive_url":"http://web.archive.org/web/20260228040714/https://www.elliptic.co/blog/540-million-stolen-from-the-ronin-defi-bridge","name":"https://www.elliptic.co/blog/540-million-stolen-from-the-ronin-defi-bridge","url":"https://www.elliptic.co/blog/540-million-stolen-from-the-ronin-defi-bridge"},{"archive_timestamp":"2026-03-15T18:07:34+00:00","archive_url":"http://web.archive.org/web/20260315180734/https://www.elliptic.co/blog/analysis/north-korea-linked-atomic-wallet-heist-tops-100-million","name":"https://www.elliptic.co/blog/analysis/north-korea-linked-atomic-wallet-heist-tops-100-million","url":"http://web.archive.org/web/20260315180734/https://www.elliptic.co/blog/analysis/north-korea-linked-atomic-wallet-heist-tops-100-million"},{"archive_timestamp":"2026-02-22T17:08:52+00:00","archive_url":"http://web.archive.org/web/20260222170852/https://www.elliptic.co/blog/how-the-lazarus-group-is-stepping-up-crypto-hacks-and-changing-its-tactics","name":"https://www.elliptic.co/blog/how-the-lazarus-group-is-stepping-up-crypto-hacks-and-changing-its-tactics","url":"http://web.archive.org/web/20260222170852/https://www.elliptic.co/blog/how-the-lazarus-group-is-stepping-up-crypto-hacks-and-changing-its-tactics"},{"archive_timestamp":null,"archive_url":null,"name":"https://www.elliptic.co/blog/further-sanctions-against-north-koreas-lazarus-group-for-laundering-stolen-ronin-funds","url":"https://www.elliptic.co/blog/further-sanctions-against-north-koreas-lazarus-group-for-laundering-stolen-ronin-funds"},{"archive_timestamp":"2026-03-08T13:36:34+00:00","archive_url":"http://web.archive.org/web/20260308133634/https://www.trmlabs.com/resources/blog/north-koreas-lazarus-group-moves-funds-through-tornado-cash","name":"https://www.trmlabs.com/resources/blog/north-koreas-lazarus-group-moves-funds-through-tornado-cash","url":"http://web.archive.org/web/20260308133634/https://www.trmlabs.com/resources/blog/north-koreas-lazarus-group-moves-funds-through-tornado-cash"},{"archive_timestamp":"2026-03-21T17:27:58+00:00","archive_url":"http://web.archive.org/web/20260321172758/https://www.bleepingcomputer.com/news/security/fbi-north-korean-hackers-stole-100-million-in-harmony-crypto-hack/","name":"https://www.bleepingcomputer.com/news/security/fbi-north-korean-hackers-stole-100-million-in-harmony-crypto-hack/","url":"http://web.archive.org/web/20260321172758/https://www.bleepingcomputer.com/news/security/fbi-north-korean-hackers-stole-100-million-in-harmony-crypto-hack/"},{"archive_timestamp":null,"archive_url":null,"name":"https://www.cnbc.com/2022/04/15/ronin-hack-north-korea-linked-to-615-million-crypto-heist-us-says.html","url":"http://web.archive.org/web/20260507160900/https://www.cnbc.com/2022/04/15/ronin-hack-north-korea-linked-to-615-million-crypto-heist-us-says.html"},{"archive_timestamp":"2025-07-21T23:22:11+00:00","archive_url":"http://web.archive.org/web/20250721232211/https://techcrunch.com/2022/06/30/north-korea-lazarus-harmony-theft/","name":"https://techcrunch.com/2022/06/30/north-korea-lazarus-harmony-theft/","url":"https://techcrunch.com/2022/06/30/north-korea-lazarus-harmony-theft/"},{"archive_timestamp":"2026-03-17T09:07:41+00:00","archive_url":"http://web.archive.org/web/20260317090741/https://cyberscoop.com/bybit-lazarus-group-north-korea-ethereum/","name":"https://cyberscoop.com/bybit-lazarus-group-north-korea-ethereum/","url":"http://web.archive.org/web/20260317090741/https://cyberscoop.com/bybit-lazarus-group-north-korea-ethereum/"},{"archive_timestamp":null,"archive_url":null,"name":"https://www.upi.com/Top_News/World-News/2025/02/27/North-Korea-Bybit-crypto-heist-15-billion-FBI-Lazarus/8591740642756/","url":"http://web.archive.org/web/20250429154000/https://www.upi.com/Top_News/World-News/2025/02/27/North-Korea-Bybit-crypto-heist-15-billion-FBI-Lazarus/8591740642756/"},{"archive_timestamp":"2026-03-10T04:11:59+00:00","archive_url":"http://web.archive.org/web/20260310041159/https://www.business-standard.com/companies/news/wazirx-crypto-hack-north-korea-us-japan-south-korea-response-125011500597_1.html","name":"https://www.business-standard.com/companies/news/wazirx-crypto-hack-north-korea-us-japan-south-korea-response-125011500597_1.html","url":"http://web.archive.org/web/20260310041159/https://www.business-standard.com/companies/news/wazirx-crypto-hack-north-korea-us-japan-south-korea-response-125011500597_1.html"},{"archive_timestamp":"2026-05-20T15:53:16+00:00","archive_url":"http://web.archive.org/web/20260520155316/https://crystalintelligence.com/investigations/expert-analysis-wazirx-hack/","name":"https://crystalintelligence.com/investigations/expert-analysis-wazirx-hack/","url":"http://web.archive.org/web/20260520155316/https://crystalintelligence.com/investigations/expert-analysis-wazirx-hack/"},{"archive_timestamp":"2025-08-27T09:55:00+00:00","archive_url":"http://web.archive.org/web/20250827095500/https://cointelegraph.com/news/north-korea-s-lazarus-group-masterminded-100m-harmony-hack-fbi-confirms","name":"https://cointelegraph.com/news/north-korea-s-lazarus-group-masterminded-100m-harmony-hack-fbi-confirms","url":"http://web.archive.org/web/20250827095500/https://cointelegraph.com/news/north-korea-s-lazarus-group-masterminded-100m-harmony-hack-fbi-confirms"},{"archive_timestamp":null,"archive_url":null,"name":"https://cointelegraph.com/news/us-treasury-dept-sanctions-3-ethereum-addresses-allegedly-linked-to-north-korea","url":"http://web.archive.org/web/20240530165310/https://cointelegraph.com/news/us-treasury-dept-sanctions-3-ethereum-addresses-allegedly-linked-to-north-korea"},{"archive_timestamp":null,"archive_url":null,"name":"https://www.npr.org/2021/02/17/968652939/justice-department-charges-3-north-korean-hackers-for-global-cyberattacks","url":"http://web.archive.org/web/20260102101313/https://www.npr.org/2021/02/17/968652939/justice-department-charges-3-north-korean-hackers-for-global-cyberattacks"},{"archive_timestamp":"2026-03-08T16:23:58+00:00","archive_url":"http://web.archive.org/web/20260308162358/https://thehackernews.com/2021/02/us-charges-3-north-korean-hackers-over.html","name":"https://thehackernews.com/2021/02/us-charges-3-north-korean-hackers-over.html","url":"https://thehackernews.com/2021/02/us-charges-3-north-korean-hackers-over.html"},{"archive_timestamp":null,"archive_url":null,"name":"https://www.nccgroup.com/the-lazarus-group-north-korean-scourge-for-plus10-years/","url":"http://web.archive.org/web/20260120222607/https://www.nccgroup.com/the-lazarus-group-north-korean-scourge-for-plus10-years/"},{"archive_timestamp":null,"archive_url":null,"name":"https://www.bitdefender.com/en-us/blog/hotforsecurity/north-korea-linked-lazarus-group-laundered-900-million-in-crypto","url":"http://web.archive.org/web/20250222085206/https://www.bitdefender.com/en-us/blog/hotforsecurity/north-korea-linked-lazarus-group-laundered-900-million-in-crypto"},{"archive_timestamp":"2026-02-12T00:22:12+00:00","archive_url":"http://web.archive.org/web/20260212002212/https://www.coinspeaker.com/lazarus-group-ronin-bridge-hack/","name":"https://www.coinspeaker.com/lazarus-group-ronin-bridge-hack/","url":"http://web.archive.org/web/20260212002212/https://www.coinspeaker.com/lazarus-group-ronin-bridge-hack/"}],"summary":"Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor, also tracked as APT38, TraderTraitor, BlueNorOff, Hidden Cobra, and ZINC, operating under the Reconnaissance General Bureau (RGB) of the Korean People's Army. Active since approximately 2009, the group has stolen an estimated $6.75 billion in cryptocurrency through targeted attacks on exchanges, bridges, and blockchain companies, using stolen funds to finance North Korea's weapons programs and circumvent international sanctions. The U.S. Department of Justice has indicted three named members, and OFAC placed the group on the Specially Designated Nationals (SDN) list in April 2022.","timeline":[{"date":"2007-01-01","event":"Lazarus Group established by the North Korean government under the RGB's 110th Research Center, according to OFAC designation documents.","source":"U.S. Department of the Treasury OFAC — Press Release SM774","source_url":"https://home.treasury.gov/news/press-releases/sm774"},{"date":"2009-01-01","event":"Lazarus Group begins 'Operation Troy,' a DDoS-based cyber-espionage campaign targeting the South Korean government, representing the earliest known activity attributed to the group.","source":"Wikipedia / NCC Group","source_url":"https://en.wikipedia.org/wiki/Lazarus_Group"},{"date":"2014-11-01","event":"Lazarus Group attacks Sony Pictures Entertainment, stealing confidential data including unreleased films, executive emails, and employee records; causing an estimated $35–85 million in recovery costs.","source":"Wikipedia","source_url":"https://en.wikipedia.org/wiki/Lazarus_Group"},{"date":"2014-11-24","event":"Sony Pictures Entertainment hack: Lazarus Group destroys data, leaks internal communications, and issues extortion demands linked to the film 'The Interview.'","source":"DOJ / Washington Post","source_url":"https://www.washingtonpost.com/world/national-security/justice-department-to-announce-hacking-charges-against-north-korean-operative-the-charge--stemming-from-the-2014-sony-pictures-case--is-the-first-against-a-pyongyang-spy/2018/09/06/f477bfb2-b1d0-11e8-9a6a-565d92a3585d_story.html"},{"date":"2016-02-01","event":"Lazarus Group executes the Bangladesh Bank cyber heist via fraudulent SWIFT network instructions, successfully transferring approximately $81 million of a $951 million attempted theft.","source":"Wikipedia: Bangladesh Bank Robbery","source_url":"https://en.wikipedia.org/wiki/Bangladesh_Bank_robbery"},{"date":"2016-02-04","event":"Bangladesh Bank SWIFT heist: $81 million fraudulently transferred from Bangladesh Bank's New York Federal Reserve account; full $1 billion attempt partially blocked.","source":"Bangladesh Bank Robbery — Wikipedia","source_url":"https://en.wikipedia.org/wiki/Bangladesh_Bank_robbery"},{"date":"2017-05-12","event":"WannaCry 2.0 ransomware attack launched globally, attributed to Lazarus Group by the FBI and allied intelligence agencies; approximately 200,000 computers in 150 countries affected.","source":"DOJ Press Release","source_url":"https://www.justice.gov/archives/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyber-attacks-and"},{"date":"2017-05-12","event":"Lazarus Group deploys WannaCry 2.0 ransomware, infecting 200,000+ computers in 150 countries including the UK's National Health Service.","source":"Wikipedia / NCC Group","source_url":"https://en.wikipedia.org/wiki/Lazarus_Group"},{"date":"2018-04-03","event":"OFAC first designates Lazarus Group on the SDN list under North Korea Sanctions Regulations.","source":"OFAC Sanctions Search","source_url":"https://sanctionssearch.ofac.treas.gov/Details.aspx?id=27307"},{"date":"2018-09-06","event":"DOJ charges North Korean national Park Jin Hyok in connection with the Sony hack, Bangladesh Bank SWIFT theft, and WannaCry ransomware attack.","source":"DOJ Office of Public Affairs","source_url":"https://www.justice.gov/archives/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyber-attacks-and"},{"date":"2019-09-13","event":"OFAC sanctions Lazarus Group, Bluenoroff, and Andariel under Executive Order 13722, identifying all three as agencies or instrumentalities of the DPRK government.","source":"U.S. Department of the Treasury — SM774","source_url":"https://home.treasury.gov/news/press-releases/sm774"},{"date":"2020-03-02","event":"Treasury sanctions two Chinese nationals for laundering over $100 million in cryptocurrency on behalf of Lazarus Group.","source":"U.S. Department of the Treasury — SM924","source_url":"https://home.treasury.gov/news/press-releases/sm924"},{"date":"2021-02-17","event":"DOJ expands North Korea indictment to three defendants — Park Jin Hyok, Jon Chang Hyok, Kim Il — broadening charges to include cryptocurrency exchange thefts.","source":"Deadline / DOJ","source_url":"https://deadline.com/2021/02/doj-charges-three-north-korean-military-programmers-for-sony-hack-sweeping-cybercrimes-in-expanded-indictment-1234695409/"},{"date":"2021-02-17","event":"DOJ unseals a superseding indictment charging Jon Chang Hyok (31), Kim Il (27), and expanding charges against Park Jin Hyok (36) for conspiracy to commit computer fraud and wire/bank fraud totaling over $1.3 billion. All three remain at large.","source":"DOJ / NPR","source_url":"https://www.justice.gov/usao-cdca/pr/3-north-korean-military-hackers-indicted-wide-ranging-scheme-commit-cyber-attacks-and"},{"date":"2022-03-23","event":"Ronin Bridge hack: Lazarus Group steals 173,600 ETH and 25.5 million USDC (~$625 million) from the Axie Infinity sidechain by compromising five of nine validator keys.","source":"CoinDesk","source_url":"https://www.coindesk.com/tech/2022/03/29/axie-infinitys-ronin-network-suffers-625m-exploit"},{"date":"2022-03-23","event":"Lazarus Group exploits the Ronin Network bridge supporting Axie Infinity, stealing 173,600 ETH and 25.5 million USDC (approximately $620 million). Attacker primary wallet: 0x098B716B8Aaf21512996dC57EB0615e2383E2f96.","source":"CoinDesk / Elliptic","source_url":"https://www.coindesk.com/policy/2022/04/14/us-officials-tie-north-korean-hacker-group-to-axies-ronin-exploit"},{"date":"2022-04-14","event":"U.S. Treasury attributes Ronin Bridge hack to Lazarus Group and updates group's SDN listing with associated Ethereum address.","source":"CoinDesk / CyberScoop","source_url":"https://www.coindesk.com/policy/2022/04/14/us-officials-tie-north-korean-hacker-group-to-axies-ronin-exploit"},{"date":"2022-05-06","event":"OFAC designates Blender.io cryptocurrency mixer — the first-ever U.S. sanctions on a virtual currency mixer — citing its use to launder Ronin Bridge hack proceeds.","source":"U.S. Department of the Treasury","source_url":"https://home.treasury.gov/news/press-releases/jy0768"},{"date":"2022-06-24","event":"Harmony Horizon Bridge hack: Approximately $99.7 million stolen via compromise of multi-signature wallet keys; later confirmed by FBI as Lazarus Group operation.","source":"FBI.gov","source_url":"https://www.fbi.gov/news/press-releases/fbi-confirms-lazarus-group-cyber-actors-responsible-for-harmonys-horizon-bridge-currency-theft"},{"date":"2022-08-08","event":"OFAC sanctions Tornado Cash mixer, listing 38 unique cryptocurrency addresses and citing Lazarus Group's use of the mixer to launder $455 million from the Ronin Bridge hack.","source":"OFAC / Chainalysis","source_url":"https://ofac.treasury.gov/recent-actions/20220808"},{"date":"2023-01-13","event":"North Korean cyber actors use RAILGUN privacy protocol to launder over $60 million worth of ETH stolen in the June 2022 Harmony Bridge hack, shifting laundering infrastructure after Tornado Cash sanctions.","source":"FBI / CoinTelegraph","source_url":"https://cointelegraph.com/news/north-korea-s-lazarus-group-masterminded-100m-harmony-hack-fbi-confirms"},{"date":"2023-01-24","event":"FBI formally confirms Lazarus Group responsible for the June 2022 Harmony Horizon Bridge theft.","source":"FBI.gov","source_url":"https://www.fbi.gov/news/press-releases/fbi-confirms-lazarus-group-cyber-actors-responsible-for-harmonys-horizon-bridge-currency-theft"},{"date":"2023-06-03","event":"Atomic Wallet hack: Over $100 million drained from approximately 5,500 user wallets; Elliptic attributes the theft to Lazarus Group on June 6, 2023.","source":"Decrypt","source_url":"https://decrypt.co/144444/north-korean-hackers-pocket-over-100-m-in-atomic-wallet-heist"},{"date":"2023-06-03","event":"Lazarus Group attacks Atomic Wallet, stealing over $100 million from approximately 5,500 customer wallets. Proceeds laundered through sanctioned Russian exchange Garantex.","source":"Elliptic / Decrypt","source_url":"https://www.elliptic.co/blog/analysis/north-korea-linked-atomic-wallet-heist-tops-100-million"},{"date":"2023-07-22","event":"Lazarus Group steals approximately $60 million from Alphapo and CoinsPaid.","source":"FBI","source_url":"https://www.fbi.gov/news/press-releases/fbi-identifies-lazarus-group-cyber-actors-as-responsible-for-theft-of-41-million-from-stakecom"},{"date":"2023-09-04","event":"FBI identifies Lazarus Group as responsible for the $41 million Stake.com theft, part of a broader multi-platform campaign totaling ~$240 million in summer 2023.","source":"FBI.gov","source_url":"https://www.fbi.gov/news/press-releases/fbi-identifies-lazarus-group-cyber-actors-as-responsible-for-theft-of-41-million-from-stakecom"},{"date":"2024-05-01","event":"Lazarus Group attacks DMM Bitcoin exchange in Japan, stealing approximately 4,502.9 BTC (~$305 million) via private key compromise. DMM Bitcoin shuts down in December 2024.","source":"Chainalysis","source_url":"https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2025/"},{"date":"2024-07-01","event":"WazirX hack: Approximately $234.9 million stolen from India's largest cryptocurrency exchange via a compromised multi-signature wallet held with Liminal Custody.","source":"Elliptic","source_url":"https://www.elliptic.co/blog/235-million-lost-by-wazirx-in-north-korea-linked-breach"},{"date":"2024-07-18","event":"Lazarus Group attacks Indian exchange WazirX, draining $234.9 million via a multisig wallet smart contract manipulation. Compromised Ethereum wallet: 0x27fD43BABfbe83a81d14665b1a6fB8030A60C9b4.","source":"Wikipedia / Business Standard","source_url":"https://en.wikipedia.org/wiki/2024_WazirX_hack"},{"date":"2025-01-14","event":"Joint statement by the United States, Japan, and South Korea formally attributes WazirX hack and other 2024 thefts totaling over $659 million to North Korea's Lazarus Group.","source":"TechCrunch","source_url":"https://techcrunch.com/2025/01/14/north-korea-stole-over-659m-in-crypto-heists-during-2024-deploys-fake-job-seekers/"},{"date":"2025-02-21","event":"Bybit hack: TraderTraitor (Lazarus sub-cluster) steals approximately $1.46–$1.5 billion in ETH from Bybit via a Safe{Wallet} supply chain attack — the largest single cryptocurrency theft in history.","source":"FBI IC3 PSA250226","source_url":"https://www.ic3.gov/psa/2025/psa250226"},{"date":"2025-02-26","event":"FBI issues Public Service Announcement PSA250226 formally attributing the Bybit hack to North Korean TraderTraitor actors and publishing 51 Ethereum addresses associated with the laundering.","source":"FBI IC3","source_url":"https://www.ic3.gov/psa/2025/psa250226"},{"date":"2026-03-12","event":"OFAC sanctions six individuals and two entities for roles in North Korean IT worker fraud schemes supporting Lazarus Group operations.","source":"U.S. Department of the Treasury","source_url":"https://home.treasury.gov/news/press-releases/sb0190"},{"date":"2026-04-22","event":"Media reports allege North Korean Lazarus Group hackers tied to a $290 million theft involving KelpDAO and LayerZero infrastructure; formal attribution pending.","source":"UPI","source_url":"https://www.upi.com/Top_News/World-News/2026/04/22/KelpDAO-LayerZero-North-Korea-crypto-hack-theft-Lazarus-Group/6151776848419/"}]},"v":1}