Lazarus Group
Who are the Lazarus Group and how do they launder stolen crypto?
Lazarus Group is North Korea's state-sponsored hacking operation, also tracked as TraderTraitor and APT38. Chainalysis estimates it has stolen roughly US$6.75 billion in cryptocurrency through 2025 to fund the sanctioned regime. It launders at unmatched speed: swapping the record US$1.5 billion Bybit haul into bitcoin in about ten days via cross-chain services, mixers and lightly regulated brokers.
As of August 2026: No arrests have been made for the Bybit theft; enforcement remains limited to sanctions, seizures and service takedowns. Yearly theft totals are Chainalysis estimates, and 2025 figures come from its December 2025 reporting.
What happened?
Most money launderers work for criminals. The Lazarus Group works for a state. Tracked by the US government under names including APT38 and TraderTraitor, and linked to North Korea’s Reconnaissance General Bureau intelligence agency, Lazarus exists to raise money for a regime locked out of the world’s financial system by sanctions. Chainalysis estimates its cumulative cryptocurrency haul at roughly US$6.75 billion through 2025.
The group announced itself to the financial world in February 2016, before crypto was its focus. Fraudulent orders sent through the SWIFT network from inside Bangladesh Bank’s own systems instructed the Federal Reserve Bank of New York to pay out the central bank’s money. Most of the orders were blocked, but five went through: US$81 million landed in accounts at a Manila bank opened under fictitious names, was withdrawn, and vanished into the Philippine casino industry.
Then came the pivot to crypto, where the paydays dwarf any bank raid. In March 2022, Lazarus drained the Ronin Bridge supporting the game Axie Infinity of 173,600 ETH and 25.5 million USDC, worth about US$540 million at the exploit and roughly US$620–625 million by the time it was discovered six days later. Chainalysis counted US$1.7 billion stolen by North Korea in 2022 and US$1.34 billion in 2024. And on February 21, 2025, the group set the all-time record: about US$1.5 billion in ETH taken from the exchange Bybit in a single attack, driving North Korea’s 2025 total to US$2.02 billion, roughly 60% of all crypto stolen worldwide that year.
Which techniques did it use?
Stealing the funds is the easy half; the coins land in wallets the whole world is watching. What distinguishes Lazarus is industrial-scale layering at speed.
The core move is chain-hopping: swapping assets across blockchains to break the trail and shed freezable tokens. After Bybit, the group pushed the stolen ETH through THORChain, a decentralized cross-chain protocol with no operator to subpoena, converting most of it into bitcoin; analysts tracked about 86% into some 12,836 BTC spread across roughly 9,100 wallets. The entire ~500,000 ETH was moved in about ten days, while exchanges and trackers scrambled to keep up.
Mixers do the blending. DOJ records show the mixer ChipMixer, taken down in 2023, received more than US$700 million in bitcoin from wallets tied to stolen funds including North Korean heists such as Ronin. No-KYC swap services fill the gaps: eXch kept converting Bybit proceeds even after the FBI publicly listed the addresses. The final step, turning crypto into money a state can spend, runs through over-the-counter brokers and lightly regulated intermediaries; FinCEN’s action against Cambodia’s Huione Group cited its laundering of North Korean heist proceeds among some US$4 billion in illicit flows.
How was it found?
Attribution came from following both the malware and the money. Investigators connected the Bangladesh Bank intrusion to the same North Korean toolset seen in earlier attacks, and blockchain analytics firms (Chainalysis, Elliptic, TRM Labs) mapped the wallet clusters behind the crypto heists. The US government then made the attributions official: on April 14, 2022, OFAC added the Ronin attacker’s Ethereum address to the Lazarus Group’s sanctions listing, and after Bybit the FBI issued public service announcement PSA250226 on February 26, 2025, naming TraderTraitor and publishing 51 Ethereum addresses so that every exchange and service provider could screen against them in real time.
What was the outcome?
Enforcement can reach the money and the infrastructure, but not the hackers, who operate from inside North Korea. In September 2022, Chainalysis and law enforcement announced the seizure of more than US$30 million of the Ronin proceeds, the first-ever recovery of crypto stolen by North Korea. After Bybit, a bounty program and exchange freezes blocked only about 3% of the funds; the rest was laundered. Germany’s federal police seized eXch’s servers and about €34 million in crypto on April 30, 2025, ending one of the scheme’s busiest conduits.
The Bangladesh Bank case produced the group’s only courtroom conviction of any kind, and it was of a facilitator, not a hacker: Maia Santos-Deguito, the Manila branch manager whose bank received the US$81 million, was convicted of money laundering in January 2019. Bybit, for its part, covered its US$1.5 billion loss and made customers whole. No Lazarus operator has been arrested for any of the crypto heists.
What changed afterwards?
Lazarus reshaped how the crypto industry treats stolen funds. Real-time address screening against FBI and OFAC lists is now standard at major exchanges, and the travel rule, requiring service providers to pass originator and beneficiary information along with transfers, became the regulatory answer to anonymous hop-through laundering. Sanctions moved on-chain: wallet addresses now sit on the SDN list alongside names and passport numbers.
The group also exposed the limits of that system. Decentralized protocols like THORChain have no compliance department to receive a subpoena, and a laundering operation that finishes in ten days beats any process built around reports filed after the fact. The record keeps growing (2025 was North Korea’s biggest year yet), which is why regulators now target the chokepoints where crypto meets cash, from mixer takedowns to FinCEN’s cutoff of Huione Group from the US financial system. The contest between the fastest launderer on earth and the most transparent ledger ever built remains unresolved.
Frequently asked questions
Why does North Korea steal cryptocurrency?
Revenue. The regime is cut off from the global financial system by sanctions, and stolen crypto, converted through brokers into usable funds, has become one of its most significant income streams, which US and UN officials link to its weapons programs. Crypto theft offers deniability, scale, and no need for physical smuggling.
Are Lazarus, APT38 and TraderTraitor the same thing?
They are overlapping labels for North Korean state hacking activity. 'Lazarus Group' is the umbrella name; APT38 designates the financially focused arm behind bank raids like Bangladesh Bank; TraderTraitor is the FBI's name for the cluster targeting crypto firms, used in its Bybit attribution. All are tied to the Reconnaissance General Bureau, North Korea's intelligence agency.
Has anyone from Lazarus been arrested?
No operator has been arrested for the major crypto heists: the hackers are in North Korea, beyond extradition. Enforcement instead targets the infrastructure: OFAC sanctions on the group and its wallet addresses, seizures like the US$30 million-plus Ronin recovery in September 2022, and takedowns of laundering services such as the eXch seizure in April 2025.
How was the Bybit hack carried out?
Attackers compromised a developer machine at Safe{Wallet}, a wallet infrastructure provider, and used that access to present Bybit's signers with a disguised malicious transaction during a routine cold-to-warm wallet transfer. Roughly 499,000–500,000 ETH (about US$1.5 billion) moved to attacker addresses in the largest crypto theft ever recorded.
Did Bybit's customers lose their money?
No. Bybit covered the roughly US$1.5 billion hole with emergency ETH purchases and loans, stayed solvent, and made customers whole. Only around 3% of the stolen funds were frozen in the weeks after the hack; the rest is considered laundered.
Techniques used in this case
- Chain-hopping and cross-chain bridges · Swapping illicit crypto across blockchains through bridges and no-KYC swap services so that no single chain's analytics tell the whole story.
- Mixers, tumblers, and CoinJoin · Services that pool many users' coins and pay out equivalent amounts from the pool, breaking the on-chain link between where crypto came from and where it went.
- Stablecoins and OTC brokers · Moving illicit value through dollar-pegged stablecoins (above all USDT on Tron) and converting it to cash through over-the-counter brokers and guarantee marketplaces with little or no KYC.
Related cases
- The Bitfinex hack laundering · A married couple spent five years laundering 119,754 bitcoin stolen from the Bitfinex exchange, and the blockchain recorded every move.
Glossary
Sources
- North Korea Responsible for $1.5 Billion Bybit Hack (PSA250226) (FBI Internet Crime Complaint Center, February 26, 2025).
- US Officials Tie North Korean Hacker Group to Axie's Ronin Exploit (CoinDesk, April 14, 2022).
- Seizure of crypto stolen in the Ronin Bridge / Axie Infinity DPRK hack (Chainalysis, September 2022).
- Crypto hacking and stolen funds: North Korea's record 2025 (Chainalysis, December 18, 2025).
- Lazarus laundered Bybit hack funds via THORChain (BeInCrypto / Arkham, March 2025).
- Germany takes down eXch cryptocurrency exchange, seizes servers (BleepingComputer, May 2025).
- Philippine court jails former bank manager over Bangladesh central bank heist (CNBC, January 10, 2019).