Lazarus Group resurfaces with $19.4M Bitcoin move

BTC
Lazarus GroupNorth KoreaOn-ChainBitcoinhack
1 hour agoSource: crypto.news
Lazarus Group resurfaces with $19.4M Bitcoin move

North Korea-linked Lazarus Group has transferred 244.148 Bitcoin worth about $19.42 million, bringing fresh attention to wallets associated with one of the crypto industry’s most active hacking operations.

Summary

  • Lazarus Group transferred 244.148 BTC worth about $19.42 million, according to Lookonchain.
  • The transaction’s destination and connection to any earlier theft remain undisclosed.
  • Another Lazarus-linked wallet moved 262.2 BTC to a new address earlier in August.
  • U.S. sanctions generally prohibit Americans from dealing with property linked to the Lazarus Group.

Lazarus Group moves 244 BTC between wallets

Lookonchain reported the transfer in an Aug. 28 X post, saying wallets attributed to Lazarus Group had become active again and moved 244.148 BTC about an hour before its alert.

Bitcoin traded at roughly $79,500 when the analytics account published its estimate, placing the transaction’s value at $19.42 million. Lookonchain did not identify the receiving address in the text of the post or say whether the Bitcoin moved to an exchange, mixer, or another wallet controlled by the group.

Without a disclosed destination, the transaction alone does not show that Lazarus sold or attempted to cash out the Bitcoin. Public blockchain records confirm when funds move between addresses, but connecting those addresses to an organization usually depends on labels and analysis supplied by investigators or blockchain intelligence firms.

The Aug. 28 transaction followed another large Bitcoin movement attributed to the group earlier in the month. On Aug. 12, Lookonchain said Lazarus transferred 262.2 BTC, then valued at approximately $16.64 million, from an identified wallet to a newly created address.

At the time, the analytics account described the transaction as a wallet-to-wallet transfer rather than a sale. Taken at their reported dollar values, the two August movements involved more than $36 million in Bitcoin, though no source has confirmed that the transactions came from the same balance or served the same purpose.

Past wallet activity shows why the destination matters. In March 2025, five unknown addresses received a combined 44.07 BTC worth about $3.76 million from wallets attributed to Lazarus, according to earlier on-chain reporting. The transactions reduced the tracked wallet’s holdings to 13,441 BTC at the time.

Bybit theft left Bitcoin across thousands of addresses

As crypto.news previously reported, Bybit sued North Korea and Lazarus Group in a Washington, D.C., federal court on Aug. 7, seeking to recover assets tied to the exchange’s $1.5 billion theft.

The lawsuit also named North Korea’s Reconnaissance General Bureau, or RGB, which the U.S. Treasury identifies as the country’s main intelligence agency. A federal judge issued a preliminary injunction that blocked unidentified defendants from transferring, selling, or disposing of certain assets connected to the case.

Bybit filed the civil action separately from ongoing U.S. criminal investigations. A preliminary injunction preserves the identified property while litigation continues and does not amount to a final decision on ownership or liability.

The FBI attributed the February 2025 Bybit attack to North Korean actors operating under the TraderTraitor name. According to the agency, the attackers converted part of the stolen holdings into Bitcoin and other assets before spreading them across thousands of addresses on several blockchains.

In its public alert, the FBI said it expected the assets to be moved again and eventually exchanged for government-issued currency. The bureau asked exchanges, bridges, decentralized finance services, blockchain analytics companies, and node operators to block transactions involving the addresses it identified.

By April 2025, Bybit CEO Ben Zhou said 27.6% of the stolen funds could no longer be tracked, according to an August report on North Korea’s attack methods. The same report said the distribution of assets across many Bitcoin wallets had made blockchain tracing more difficult.

Lookonchain has not connected the latest 244.148 BTC transfer directly to the Bybit theft. No government agency or blockchain intelligence company cited in the available reporting has publicly identified the source of the coins involved in the Aug. 28 movement.

Lazarus-linked attacks continued into 2026

Chainalysis estimated that North Korean hackers stole at least $2.02 billion in cryptocurrency during 2025, an increase of 51% from the previous year. The firm placed the country’s cumulative crypto theft at no less than $6.75 billion by the end of that period.

According to its December 2025 report, North Korean operations accounted for 76% of the value lost through attacks on crypto services during the year. Chainalysis said the attackers carried out fewer confirmed incidents but extracted larger amounts from successful breaches.

The firm also found that North Korean operators had increasingly targeted companies through impersonation and employee access. Some actors posed as job applicants to enter crypto businesses, while others pretended to recruit for known Web3 and artificial intelligence companies, according to Chainalysis.

Activity attributed to Lazarus continued in April 2026 when attackers drained approximately 116,500 rsETH, worth about $292 million, from KelpDAO’s LayerZero-based bridge. LayerZero attributed the attack with preliminary confidence to Lazarus Group’s TraderTraitor unit.

Chainalysis later said the attackers compromised infrastructure that supplied blockchain information to LayerZero’s verification system. By feeding false data to the system, they caused an Ethereum contract to release assets even though no matching token burn had occurred on the source network.

Rapid intervention blocked a second attempted theft worth about $95 million, according to Chainalysis. The Arbitrum Security Council also froze more than 30,000 ETH that investigators connected to the attacker’s downstream transactions.

By June, the KelpDAO attacker had moved approximately $220 million in unfrozen assets through privacy services, according to subsequent tracking data. The routes included THORChain, Wasabi, Tornado Cash, and Umbra, while around $1.7 million remained in the original wallets.

U.S. sanctions restrict dealings with Lazarus Group

The U.S. Treasury’s Office of Foreign Assets Control sanctioned Lazarus Group in September 2019 under an executive order targeting the North Korean government. OFAC identified Lazarus, Bluenoroff, and Andariel as state-controlled hacking groups connected to the RGB.

Under the designation, property belonging to Lazarus that enters the United States or comes under the possession or control of a U.S. person must be blocked and reported to OFAC. Treasury regulations also generally prohibit Americans from conducting transactions with sanctioned entities unless the agency authorizes them.

Treasury said Lazarus had targeted governments, financial institutions, media companies, manufacturers, infrastructure operators and cryptocurrency businesses through cyber theft, espionage and malware attacks. The department linked the group to the 2014 Sony Pictures breach and the WannaCry ransomware attack that affected computers across at least 150 countries.

U.S. authorities have also acted against services used to process funds tied to the group. In 2022, the Treasury sanctioned the virtual currency mixer Blender.io after saying it had handled more than $20.5 million from the roughly $620 million Ronin Network theft. The FBI later attributed the Ronin attack to Lazarus Group and APT38.

In August 2023, the FBI separately warned crypto companies about movements involving Bitcoin stolen by North Korean TraderTraitor actors. The agency said the group could attempt to cash out more than $40 million in Bitcoin and published six wallet addresses for private companies to examine.