North Korea’s Lazarus Group steals over $5.2M from a crypto trader

Source Cryptopolitan

North Korea’s Lazarus Group has been linked to a cyberattack that stole more than $5.2 million from a crypto trader on May 24, according to blockchain investigator ZackXBT. The theft occurred through a sophisticated malware attack, with funds siphoned from several wallet types including multisig, externally owned accounts (EOAs), and exchange wallets. 

The incident, revealed on ZackXBT’s Telegram channel on Tuesday, insinuated that the group could be changing their focus from high-net-worth individuals and companies to intraday individual traders. 

After the heist, approximately 1,000 ETH was funneled into Tornado Cash, a crypto-mixing service commonly used to obscure the origin of stolen digital assets. The stolen assets were then promptly liquidated on the open market.

Addresses traced, Tornado Cash used to launder funds

ZachXBT’s channel listed three Ethereum addresses tied to the heist. Along with minor token balances of QBX, Blocklords, Astra Protocol, and DAI totaling around $1,340, the principal address had more than 40 ETH, which is around $107,000 at current market values. It is thought that these funds were part of the malware attack’s profits.

Last weekend, just nine transactions were processed using the second address, which seemed to be new. It sent more than 200 ETH to the main address. Finally, as of this publication, the other crypto address held around $2.7 million DAI, which was the majority of the stolen funds.

This pattern of conduct is consistent with what was found in a recent study by TRM Labs, which details the worldwide web of Russian criminal organizations and Chinese over-the-counter brokers that North Korea uses to launder its illegal profits.

The report alleges that Lazarus supplies the technical expertise, but their partners provide the channels to integrate stolen funds into markets legitimately.

Money laundering continues in Q2 2025 

In April, blockchain analytics firm SpotOnChain reported that a wallet believed to be associated with Lazarus offloaded 40.78 Wrapped Bitcoin (WBTC) for $3.51 million. The Bitcoin, originally purchased in February 2023 for about $999,900 when WBTC traded at $24,521, was sold at $83,459 per coin for a profit of 251% over two years. 

The proceeds were converted into 1,847 ETH and later split among three wallets. The largest tranche of 1,865 ETH was traced to another wallet reportedly operated by the group. Instead of holding the converted ETH, Lazarus distributed 2,507 ETH across multiple addresses.

DPRK-linked hackers were also connected to the infamous $1.5 billion hack on the Bybit crypto exchange. In the aftermath of the breach, the group allegedly laundered nearly 500,000 ETH, equivalent to about $1.39 billion, across multiple transactions within just ten days. 

At least $605 million was funneled through the decentralized liquidity protocol THORChain in a single day. Yet, blockchain intelligence platform Arkham Intelligence estimates that wallets tied to Lazarus still hold approximately $1.1 billion in crypto reserves, including significant holdings in Bitcoin, Ethereum, and Tether.

Cybercrime funding nuclear ambitions

United Nations investigators monitoring sanctions compliance believe that the proceeds from these cyberattacks are being funneled into North Korea’s weapons development programs. Between 2017 and 2023, the country reportedly used crypto-based revenue streams to improve its missile technology, increasing its capacity to strike targets far beyond the Korean peninsula.

In a report published last December, Chainalysis confirmed that hackers connected to the regime stole over $1.3 billion in cryptocurrency in 2024 across 47 incidents.

Hackers linked to North Korea have become notorious for their sophisticated and relentless tradecraft,” the Chainalysis insight said, noting that these efforts are used to bypass international sanctions and fund the state’s illicit operations.

Cryptopolitan Academy: Want to grow your money in 2025? Learn how to do it with DeFi in our upcoming webclass. Save Your Spot

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Cardano (ADA) Capped Below Resistance — Will Buyers Regain Control?Cardano price started a fresh decline below the $0.80 zone. ADA is now consolidating and might aim for a recovery above $0.780. ADA price started a fresh decline below $0.80 and $0.780. The price is
Author  NewsBTC
11 hours ago
Cardano price started a fresh decline below the $0.80 zone. ADA is now consolidating and might aim for a recovery above $0.780. ADA price started a fresh decline below $0.80 and $0.780. The price is
placeholder
Gold price seems vulnerable below $3,300 amid tariffs news, stronger USDGold price (XAU/USD) touched a one-and-a-half week low, around the $3,246-3,245 area during the Asian session on Thursday in reaction to the news that a federal court blocked US President Donald Trump's trade tariffs from going into effect.
Author  FXStreet
11 hours ago
Gold price (XAU/USD) touched a one-and-a-half week low, around the $3,246-3,245 area during the Asian session on Thursday in reaction to the news that a federal court blocked US President Donald Trump's trade tariffs from going into effect.
placeholder
Shiba Inu Trapped Inside Triangle: 17% Move Incoming?An analyst has pointed out that Shiba Inu is currently trading within a triangle pattern, which could set up a 17% move for the memecoin. 4-Hour Price Of Shiba Inu Has Been Consolidating Inside A
Author  NewsBTC
11 hours ago
An analyst has pointed out that Shiba Inu is currently trading within a triangle pattern, which could set up a 17% move for the memecoin. 4-Hour Price Of Shiba Inu Has Been Consolidating Inside A
placeholder
Ethereum Price Flexes Strength — Outpaces Bitcoin With Bullish BreakoutEthereum price found support at $2,550 and started a fresh increase. ETH is now up over 5% and might attempt to clear the $2,800 resistance. Ethereum started a decent increase above the $2,550 and
Author  NewsBTC
11 hours ago
Ethereum price found support at $2,550 and started a fresh increase. ETH is now up over 5% and might attempt to clear the $2,800 resistance. Ethereum started a decent increase above the $2,550 and
placeholder
Bitcoin Set For 50%+ Move Within 6 Months, Says Hedge Fund BossBitcoin is currently changing hands just above $108,000, consolidating after Tuesday’s fresh all-time high. Charles Edwards, founder of the digital-asset hedge fund Capriole Investments, believes
Author  NewsBTC
11 hours ago
Bitcoin is currently changing hands just above $108,000, consolidating after Tuesday’s fresh all-time high. Charles Edwards, founder of the digital-asset hedge fund Capriole Investments, believes
goTop
quote