Lazarus Group: North Korean Hackers Launder $300 Million from ByBit Heist

Mon Aug 04 2025 00:41:37 GMT+0300 (Eastern European Summer Time)
Lazarus Group: North Korean Hackers Launder $300 Million from ByBit Heist

A comprehensive look at how the Lazarus Group of North Korean hackers converted a significant portion of stolen cryptocurrency into untraceable funds, raising concerns over their impacts on military financing.


Recent developments reveal that North Korean hackers, known as the Lazarus Group, have successfully laundered $300 million from a massive $1.5 billion hack on crypto exchange ByBit. With expertise in moving funds undetected, they pose a significant threat to cybersecurity and global financial stability.


North Korean hackers, notably the Lazarus Group, have reportedly converted at least $300 million of their staggering $1.5 billion theft from the cryptocurrency exchange ByBit into unrecoverable funds. The hack took place two weeks ago, and experts are now racing against time to track and block these hackers from transforming their digital loot into usable cash.

The Lazarus Group operates with extreme sophistication, with experts believing they are working nearly around the clock to obfuscate the money trail. "Every minute is crucial for them to confuse the trail of funds, and they demonstrate remarkable skill," notes Dr. Tom Robinson, co-founder of crypto investigative firm Elliptic. In fact, he describes North Korea as a leading entity in the art of laundering cryptocurrency. "It's highly likely they have a dedicated team of individuals employing automated tools and extensive experience to execute these operations, only taking short breaks throughout the day," Robinson adds.

Elliptic's analysis aligns with ByBit's findings, indicating that about 20% of the stolen funds have "gone dark," rendering recovery efforts virtually impossible. The United States and its allies have accused the North Korean regime of executing numerous cyber attacks over the years to fund its military and nuclear initiatives. On February 21, hackers compromised one of ByBit's suppliers, effectively altering the digital wallet address and redirecting a transfer of 401,000 Ethereum coins to their own accounts instead.

Ben Zhou, ByBit's CEO, has committed to recovering some of the stolen cryptocurrencies through an incentive program dubbed Lazarus Bounty, which encourages the public to help identify and freeze the illicit funds. Despite an apparent openness to collaboration, the struggle is compounded by the fact that not all cryptocurrency exchanges are willing to support these recovery efforts.

The owners of eXch, identified as Johann Roberts, have faced criticism from ByBit and others for allegedly permitting the laundering of funds through their platform. Roberts, however, disputes this claim, emphasizing their uncertainty regarding the origins of the assets amidst a protracted dispute with ByBit.

Historically, North Korea has not officially acknowledged its involvement with the Lazarus Group, but it is widely believed to be the only nation actively utilizing cybercrime for financial gain. The group, once focused on bank infiltrations, has shifted primarily to cryptocurrency exchanges due to their relatively weaker defenses. Previous hacks associated with North Korean operatives include:

- The 2019 breach at UpBit for $41 million
- A $275 million incident involving KuCoin (in which most funds were later recovered)
- The 2022 Ronin Bridge attack, resulting in a loss of $600 million
- A $100 million theft from Atomic Wallet in 2023

In 2020, the United States officially placed members of the Lazarus Group on its Cyber Most Wanted list, although the likelihood of their apprehension remains improbably low unless they exit North Korean borders.

MORE ON THEME

Fri, 01 Aug 2025 23:58:31 GMT

Behind the Veil: North Korean IT Workers Financing the Regime through Deception

Fri, 01 Aug 2025 23:58:31 GMT
Sun, 27 Jul 2025 02:17:03 GMT

Security Breach Exposes Personal Data on Women's Dating Safety App

Sun, 27 Jul 2025 02:17:03 GMT
Sat, 26 Jul 2025 14:03:01 GMT

Data Breach Exposes Personal Images from Women-Centric Dating Safety App

Sat, 26 Jul 2025 14:03:01 GMT
Fri, 18 Jul 2025 23:12:14 GMT

North Korea Revokes Foreign Tourist Access to New Seaside Resort

Fri, 18 Jul 2025 23:12:14 GMT
Fri, 18 Jul 2025 09:57:41 GMT

North Korea Shuts Out Foreign Tourists from New Seaside Resort

Fri, 18 Jul 2025 09:57:41 GMT
Sun, 13 Jul 2025 02:53:29 GMT

North Korea's New Resort Welcomes Its First Russian Tourists Amid Human Rights Concerns

Sun, 13 Jul 2025 02:53:29 GMT
Sun, 13 Jul 2025 02:46:09 GMT

North Korea Pledges Unconditional Support for Russia's Actions in Ukraine

Sun, 13 Jul 2025 02:46:09 GMT
Sat, 12 Jul 2025 21:29:18 GMT

North Korea's New Resort Draws First Russian Tourists Amid Human Rights Concerns

Sat, 12 Jul 2025 21:29:18 GMT
Sat, 12 Jul 2025 03:29:01 GMT

North Korea's Controversial Wonsan Resort Opens to First Russian Tourists

Sat, 12 Jul 2025 03:29:01 GMT
Wed, 09 Jul 2025 07:45:26 GMT

Good-Will Gesture: South Korea Repatriates Stranded North Korean Fishermen

Wed, 09 Jul 2025 07:45:26 GMT
Wed, 09 Jul 2025 07:09:04 GMT

G8 Education Speeds Up CCTV Rollout Amid Child Abuse Allegations**

Wed, 09 Jul 2025 07:09:04 GMT
Sun, 06 Jul 2025 09:29:41 GMT

Dissecting the Fragile Alliances: China and Russia's Hesitation to Support Iran in Crisis**

Sun, 06 Jul 2025 09:29:41 GMT
Thu, 03 Jul 2025 13:16:48 GMT

North Korea's Ambitious Wonsan Kalma Resort Opens with Domestics Only

Thu, 03 Jul 2025 13:16:48 GMT
Thu, 03 Jul 2025 08:51:45 GMT

South Korea Strengthens Martial Law Regulations Amid Political Turmoil

Thu, 03 Jul 2025 08:51:45 GMT
Wed, 02 Jul 2025 21:43:11 GMT

North Korea's Remote Workers Scheme: A Growing Threat Amid Sanction Evasion

Wed, 02 Jul 2025 21:43:11 GMT
Wed, 02 Jul 2025 15:37:19 GMT

Qantas Suffers Major Data Breach Affecting Six Million Customers

Wed, 02 Jul 2025 15:37:19 GMT
Wed, 02 Jul 2025 08:59:18 GMT

**Kim Jong-un Honors North Korean Troops in Unique Display Amid Ongoing Russia-Ukraine Conflict**

Wed, 02 Jul 2025 08:59:18 GMT
Thu, 26 Jun 2025 15:47:26 GMT

North Korea Unveils Ambitious Beach Resort to Revitalize Tourism Industry

Thu, 26 Jun 2025 15:47:26 GMT
Thu, 26 Jun 2025 08:10:56 GMT

North Korea Launches Wonsan Beach Resort Amidst Tourism Revival Efforts

Thu, 26 Jun 2025 08:10:56 GMT
Wed, 25 Jun 2025 04:30:45 GMT

**The Dilemma of Nuclear Strategy: Will Pre-emptive Strikes Deter or Encourage Iran?**

Wed, 25 Jun 2025 04:30:45 GMT

Follow us

© 2024 SwissX REDD UK ltd. All Rights Reserved.