SECTIONS
CYNTRI AI$CYNT PRESALE
🔍SEARCH
THE BODY COUNT
THE RAP SHEET·

Lazarus Group: North Korea's Crypto Army

A state-sponsored hacking unit that has stolen over $6 billion in crypto to fund a nuclear program.

S
SYNTH·The Rap Sheet
Lazarus Group: North Korea's Crypto Army

The Lazarus Group is not a person - it's a cyber army. Operated by North Korea's Reconnaissance General Bureau (their intelligence agency), Lazarus has become the most prolific and successful crypto theft operation in history. They don't hack for profit. They hack to fund a nuclear weapons program.

Lazarus first hit crypto in 2017, targeting South Korean exchanges. They stole an estimated $200 million from exchanges including Youbit (which went bankrupt), Bithumb, and others. Their techniques evolved rapidly: spear-phishing campaigns targeting exchange employees, fake job interviews that delivered malware, and supply chain attacks through compromised software.

CyntriAI
PREDICTIVE DEFI
Stop chasing yields across five chains.
Cyntri AI agents predict, execute, and rebalance your DeFi positions using advanced predictive models. Built by SYNTH.
ETHSOLARBBASEOP
Read the Whitepaper
cyntriai.org
A Cyntri AI Project

By 2022, Lazarus had graduated to the big leagues. They were behind the $624 million Ronin Bridge hack (Axie Infinity's blockchain bridge), the $100 million Harmony Horizon Bridge hack, and numerous other DeFi exploits. The UN estimated that North Korean hackers had stolen $1.7 billion in crypto by 2022 alone.

Then came the Bybit hack. In February 2025, Lazarus compromised Bybit's infrastructure through a sophisticated supply chain attack targeting the Safe{Wallet} UI. They stole approximately $1.5 billion in a single operation - the largest crypto hack in history. The stolen ETH was rapidly laundered through mixers and cross-chain bridges.

US authorities estimate that Lazarus Group-affiliated hackers have stolen over $6 billion in crypto total. The funds directly finance North Korea's weapons programs. Unlike every other criminal on this list, Lazarus can't be arrested - they operate under the protection of a sovereign state. They are crypto's permanent, unkillable threat.

The Aftermath

Elliptic estimates DPRK actors have stolen over $6 billion in crypto since 2017. The Bybit hack alone ($1.5B) exceeded their entire 2024 haul ($1.34B). OFAC sanctioned Lazarus in 2019 and continued expanding designations through 2026, including sanctions on Sinbad mixer in Nov 2023.

LESSONS LEARNED

!State-sponsored hackers are crypto's most dangerous adversary
!Bridge protocols are high-value targets
!Stolen crypto can fund real-world weapons programs

COMMENTS

CMZ
END OF FILE
Filed under The Rap Sheet