Over the past three weeks, the Bybit hack has become one of the most talked-about events in the crypto industry. Behind this billion-dollar heist is the notorious Lazarus Group, a cybercriminal team widely believed to be backed by North Korea. This group has a long history of wreaking havoc across both traditional finance and the crypto world.
Capitalizing on the decentralized nature of crypto transactions and the high-profit potential of its assets, Lazarus made off with $1.46 billion in Ether (ETH) after attacking the popular crypto exchange Bybit in February 2025. This staggering heist sent shockwaves through the market, captivating investors and onlookers alike. Once again, the Lazarus Group has solidified its reputation as one of the most dangerous hacking entities in the crypto space. Although investigations are underway to trace the stolen funds and prevent future breaches, one thing is clear—the Lazarus Group is not backing down.
In this article, we’ll delve into the identity of the Lazarus Group, exploring their history and evolution over the years. We’ll also uncover the tactics and techniques they use while providing essential tips on how to protect yourself from becoming a victim of crypto hacking.
So, who exactly is the Lazarus Group?
Who is the Lazarus Group?
The Lazarus Group is a shadowy, state-sponsored hacking collective, widely believed to be backed by North Korea. Known by other names such as APT38 and Hidden Cobra, the group has become infamous for carrying out some of the most high-profile cyberattacks across various sectors, including finance and Web3.
Targeting financial institutions, Lazarus employs various sophisticated techniques, with social engineering being a cornerstone of their operations. The group’s attacks often aim to steal vast amounts of money, which are allegedly funneled back to North Korea to support the country’s nuclear weapons program.
In recent years, Lazarus has made headlines for its brazen cyber heists, the most notable being its recent attack on Bybit. This incident is just the latest in a series of cybercrimes that have reinforced the Lazarus Group’s reputation as one of the most dangerous and persistent threats in the global cyber landscape.
History of the Lazarus Group
As mentioned earlier, the Lazarus Group’s existence predates the crypto era. Some believe the name was inspired by the biblical figure Lazarus, symbolizing its ability to rise from setbacks and continue its operations without interruption.
The group’s earliest known activities date back to 2007, during Operation Flame. This attack targeted the South Korean government, aiming to disrupt and sabotage the regime at the time.
Over the years, the Lazarus Group evolved, adopting increasingly sophisticated techniques such as malware, spear-phishing, and other cyberattack strategies to cause widespread destruction. One of their most infamous attacks occurred in 2014 when they targeted Sony Pictures. The attack was allegedly launched in retaliation for the film The Interview, which depicted a fictional assassination of North Korea’s then-leader, Kim Jong-Un.
In 2017, the group made headlines again with WannaCry, one of the largest ransomware attacks in history. The attack affected around 230,000 computers across more than 150 countries in just one weekend. Major organizations such as the Russian Foreign Ministry, Vodafone, FedEx, and the UK’s National Health Service were among the victims, suffering significant operational disruptions.
While their early targets spanned multiple sectors, from entertainment to government institutions, the Lazarus Group eventually shifted its focus toward the rapidly growing cryptocurrency industry, seeking to exploit the high-profit potential of crypto assets.
Transition to Crypto Hacks
As mentioned earlier, the Lazarus Group gradually shifted its focus from various cybercrimes to targeting the burgeoning cryptocurrency industry. Several factors likely contributed to this transition, including the anonymous and pseudonymous nature of crypto transactions, the high-profit potential of digital assets, and the lack of regulation in the crypto space at the time.
Unlike traditional finance, which imposes strict controls on large transactions, the crypto market offered far fewer restrictions, making it easier to move large sums of money without raising alarms. As the cryptocurrency industry grew, the Lazarus Group began exploiting emerging vulnerabilities, which led to some of the most devastating hacks in the sector’s history.
Major Crypto Hacks Linked to the Lazarus Group
The Lazarus Group has been behind some of the most audacious and devastating crypto heists. From 2017 to 2025, their operations have rocked the crypto industry, targeting exchanges and exploiting vulnerabilities in DeFi protocols to steal billions in digital assets. Below, we break down some of the biggest attacks attributed to the group and examine their tactics, impact, and aftermath.
Bithumb Hack (2017)
Bithumb, a prominent South Korean crypto exchange founded in 2014, became the target of one of the first major hacks tied to the Lazarus Group. In June 2017, the group stole over $7 million worth of crypto assets in just one day. The hackers used malware, social engineering, and phishing techniques to infiltrate Bithumb’s systems. Despite Bithumb’s reputation for security, the group exploited vulnerabilities in the exchange’s network to execute the heist. This attack marked the beginning of Lazarus’ involvement in the crypto space and set the tone for future high-profile hacks.
Youbit Hack (2017)
Youbit, a South Korean crypto exchange formerly known as Yapizon, was hit by two major hacks in 2017. The second hack, linked to the Lazarus Group, occurred in December of the same year and resulted in the loss of 17% of Youbit’s total assets, amounting to roughly $50 million. The exchange was forced to file for bankruptcy due to the losses.
The Lazarus Group’s ability to strike repeatedly within a short span demonstrated their advanced cyber capabilities and understanding of exchange vulnerabilities. This attack was a clear signal of the group’s strategic focus on crypto exchanges, which would grow in scale over the next few years.
Coincheck Hack (2018)
In 2018, Coincheck, a major Japanese crypto wallet and exchange, suffered a devastating hack that resulted in the theft of $534 million worth of crypto assets, making it one of the largest heists in crypto history. Lazarus Group was suspected of carrying out the attack using spear-phishing tactics to gain access to Coincheck’s systems.
The hackers exploited the platform’s inadequate security measures, including weak private key management, to carry out the theft. Coincheck’s admission that they were understaffed and lacked sufficient security protocols left them vulnerable to this large-scale attack. The breach also led to a crackdown on security in the Japanese crypto market, with regulators demanding stronger security practices.
Upbit Exchange Hack (2019)
Upbit, South Korea’s largest cryptocurrency exchange, became another target of the Lazarus Group in 2019. The hackers stole approximately $49 million worth of crypto from the exchange’s hot wallet. Investigations into the attack revealed that Lazarus exploited several methods, including phishing, unauthorized access, and API exploitation.
By gaining access to the private keys of Upbit’s hot wallet, the hackers were able to transfer funds without triggering security alarms. The attack sent shockwaves through the crypto community, as it highlighted the risks even well-established exchanges face when targeted by sophisticated threat actors like Lazarus.
KuCoin Hack (2020)
In 2020, Lazarus executed a highly sophisticated hack on KuCoin, a popular cryptocurrency exchange, stealing approximately $275 million in crypto assets. The group gained unauthorized access to KuCoin’s private keys and hot wallet using social engineering tactics.
Lazarus Group’s method of laundering the stolen funds was notable: they used Uniswap, a decentralized finance (DeFi) platform, to swap the stolen tokens for Ethereum (ETH), thus obscuring the funds’ origin. This method of using DeFi platforms to launder funds is a recurring theme in Lazarus Group operations, as these platforms do not hold custody of users’ funds and often do not require Know Your Customer (KYC) verification.
In the end, KuCoin was able to recover $204 million of the stolen funds, but the attack raised alarms about the vulnerability of hot wallets and the increasing use of decentralized platforms for laundering.
Ronin Bridge Hack (2022)
The Ronin Bridge hack, attributed to Lazarus by the FBI, was one of the largest attacks in the decentralized finance (DeFi) sector. In March 2022, the Lazarus Group managed to steal $625 million in crypto assets from the Ronin Bridge, which connects Ethereum and the popular play-to-earn game Axie Infinity.
This attack was particularly concerning because of the tight security on the Ronin network. The hackers used a spear-phishing attack to gain unauthorized access to the system by targeting one of the validators. Through the attack, the group managed to control five of the nine validator positions required to approve transactions, thus allowing them to transfer funds undetected. The hackers used a malicious PDF sent through a fake job offer to infiltrate the system, demonstrating Lazarus’ continuing use of social engineering tactics to bypass security.
WazirX Hack (2024)
In 2024, WazirX, an Indian cryptocurrency exchange founded in 2018, became the target of a hack attributed to the Lazarus Group. The attack resulted in the unauthorized transfer of more than $230 million worth of crypto assets from WazirX’s multi-signature wallet. The stolen assets included Pepe (PEPE), Gala (GALA), and Tether (USDT), which were subsequently swapped for ETH, continuing a pattern often observed in Lazarus attacks.
This breach highlighted the vulnerabilities of exchanges that use multi-sig wallets, especially when combined with a lack of adequate monitoring systems. As with previous hacks, Lazarus capitalized on the growing adoption of crypto exchanges and the limited regulation in certain jurisdictions.
Bybit Hack (2025)
The most recent hack attributed to the Lazarus Group occurred in February 2025, when they stole $1.46 billion from Bybit, one of the largest cryptocurrency exchanges. The attack sent shockwaves through the crypto market, marking a significant milestone in the Lazarus Group’s ongoing campaign to infiltrate major exchanges. Reports later revealed that the exchange had received over $1.2 billion in recovery funds from other crypto entities, such as Bitget, Circle, and Tether, in a bid to recover from the devastating loss. This attack highlights the growing scale of Lazarus’ operations and their ability to target even the most secure exchanges, making it clear that no platform is immune to their sophisticated tactics.
How the Lazarus Group Executes Attacks
The Lazarus Group is known for employing a wide range of sophisticated tactics, from psychological manipulation to cutting-edge technology, to execute their high-profile cyberattacks. These attacks have caused significant financial losses and raised serious concerns about the security of the crypto industry. Below, we explore some of their primary methods:
Social Engineering
At the core of the Lazarus Group’s operations is social engineering. This malicious technique uses psychological manipulation to deceive individuals into revealing sensitive information or making critical security mistakes. The group is particularly skilled at crafting phishing emails, malicious attachments, fake job offers, and impersonation tactics to trick their targets.
These methods have proven highly effective, as evidenced by numerous high-profile crypto exchange hacks, including those on Bybit, Ronin Network, Bithumb, and WazirX. Their social engineering efforts are often the first step in a chain of attacks that lead to massive financial losses.
Malware Development
In addition to social engineering, the Lazarus Group relies heavily on custom-built malware to execute their attacks. The hackers deploy a variety of tools, including Remote Access Trojans (RATs), backdoors, botnets, and droppers, which are used to infiltrate vulnerable systems and maintain persistent access.
These malware tools allow the group to remain undetected in compromised systems, continuing to gather information or move funds at will. The group’s ability to create and adapt sophisticated malware demonstrates their deep technical expertise and strategic planning.
Abusing Legitimate Credentials
The Lazarus Group often goes a step further by obtaining legitimate credentials through phishing or malware. With access to valid login information, they can bypass security measures and perform fraudulent transactions without triggering alarms. This tactic makes their operations appear as legitimate user activity, complicating detection and increasing the duration of their attacks.
Using Advanced Persistent Threats (APTs)
Considered one of the most advanced and persistent cybercriminal organizations, Lazarus employs Advanced Persistent Threat (APT) tactics. These strategies involve extensive intelligence gathering on targets before launching an attack, which may include profiling employees, gathering data from LinkedIn, X (formerly Twitter), and monitoring public communications.
Lazarus focuses on high-value targets such as financial institutions and leading crypto exchanges, ensuring they have a worthwhile payoff before executing the attack. This careful planning and execution make them one of the most sophisticated hacking groups in the world.
Sophisticated Money Laundering
Once the group has successfully stolen funds, they employ complex money laundering techniques to cover their tracks. This often starts with the use of crypto mixers, such as Tornado Cash or Sinbad, which obfuscate the transaction trails and make it difficult for authorities to trace the stolen funds.
After mixing the funds, they are moved to exchanges or swapped for fiat currency, further complicating efforts to recover the stolen assets. The group constantly adapts its laundering tactics, monitoring industry responses to refine their methods and stay one step ahead of security measures.
The Lazarus Group’s tactics are continuously evolving as they adapt to new technology and the ever-changing vulnerabilities in the crypto ecosystem. They carefully study human behavior and security weaknesses to exploit them, making their operations highly effective and difficult to detect.
Impact on the Crypto Industry
The existence and operations of the Lazarus Group have had profound effects on the cryptocurrency industry. Below are some of the key impacts:
Financial Impact
The Lazarus Group is one of the world’s most financially successful hacking organizations, and their attacks have left an indelible mark on the crypto industry. Their massive heists have caused hundreds of millions of dollars in losses, with many exchanges still struggling to recover. Some platforms have faced significant operational disruptions, while others were forced to declare bankruptcy. These attacks highlight the vulnerability of crypto exchanges and emphasize the risks of holding assets on centralized platforms.
Reduced Trust in Crypto Platforms
The Lazarus Group’s successful attacks have seriously undermined user confidence in both centralized exchanges and DeFi platforms. As a result, investor trust has dwindled, especially during times of significant market fluctuations following these high-profile hacks.
These breaches have also harmed the reputations of the affected projects, mounting increased regulatory pressure on crypto platforms to enhance their security measures. The fear of losing funds in future attacks has led many investors to reconsider their participation in the market.
Weaponizing Cryptocurrencies for Geopolitical Goals
Perhaps the most troubling impact is the geopolitical implications of the Lazarus Group’s activities. The group has allegedly used the funds stolen from crypto exchanges to finance North Korea’s nuclear and missile development programs. This use of cryptocurrency for political and military purposes has raised significant concerns among governments worldwide, especially regarding the role of decentralized assets in funding state-sponsored cybercriminal activities.
Advancement of Attack Techniques
The Lazarus Group is known for constantly evolving their tactics, blending advanced technical tools with psychological manipulation. Their ability to exploit human behavior—such as targeting vulnerable employees through social engineering—has made them a formidable adversary. Their highly sophisticated combination of psychological and technical tactics has set a benchmark for other hacking groups, who now often imitate their strategies to defraud victims. This has created a broader cyber threat landscape, where malicious actors are increasingly using the same playbook.
Prompting Industry Reforms
While the Lazarus Group’s activities have caused widespread damage, they’ve also prompted positive changes in the industry. In response to these persistent threats, many exchanges, wallets, and DeFi platforms have implemented stronger security measures.
These reforms include the adoption of multi-signature (multi-sig) wallets, hardware security modules (HSMs), cold storage, and employee security training to defend against social engineering attacks. Platforms are also tightening Know Your Customer (KYC) and Anti-Money Laundering (AML) regulations to better monitor suspicious activity and prevent illicit fund transfers. Collaborations with blockchain analysis firms like Chainalysis and Elliptic have increased to help trace stolen funds and identify laundering schemes.
Legal and Political Impact
The Lazarus Group’s actions have triggered legal and political consequences. Governments have sanctioned North Korean entities and Lazarus-linked wallets. For example, after the Ronin Bridge hack, the U.S. Treasury imposed sanctions on the wallets connected to the laundering of the stolen funds.
International agencies, including the FBI, Interpol, and Europol, are working in tandem to track down Lazarus Group members and trace laundered funds. Furthermore, regulations surrounding crypto mixers and privacy coins have become stricter to prevent their use in laundering stolen assets.
What Crypto Users and Exchanges Can Do to Stay Safe
Given the sophisticated and dangerous nature of the Lazarus Group, it is crucial for crypto users, investors, and exchanges to implement robust security measures to protect their assets and avoid falling victim to attacks. Below are key measures for each category to enhance security:
For Crypto Users
- Use Hardware Wallets: Store your crypto on hardware wallets like Ledger or Trezor instead of exchanges or hot wallets. This keeps your assets offline, making them less vulnerable to hacks.
- Enable Multi-Factor Authentication (MFA): Ensure MFA is enabled on all your crypto accounts. Use strong, unique passwords for each platform and never share them with others.
- Prevent Phishing Attacks: Always verify URLs before logging into crypto exchanges, and avoid clicking on suspicious links in emails, Discord, or Telegram messages, even if they look legitimate. Always conduct proper background checks. Only download wallet apps from official and trusted sources.
- Secure Your Private Keys and Recovery Phrases: Store your private keys and recovery phrases offline, ideally on paper or in a secure location. For large transactions, consider using offline wallets for added security.
- Beware of Fake Job Offers: The Lazarus Group has been known to target crypto employees with fake job offers on platforms like LinkedIn. Always verify job offers or business contacts through multiple channels before engaging with them.
- Use Secure Networks: Avoid using public Wi-Fi when accessing your crypto accounts. Always ensure that your operating systems and wallets are up-to-date to prevent vulnerabilities.
For Crypto Exchanges
- Implement Strong Access Controls: Use multi-signature (multi-sig) transactions for large withdrawals. Store most funds in cold storage (hardware wallets) and only keep small amounts in hot wallets for operational purposes.
- Follow Regulatory and Security Standards: Adhere to KYC (Know Your Customer) and AML (Anti-Money Laundering) regulations to identify suspicious activities and illicit funds. Collaborate with cybersecurity agencies and law enforcement for proactive threat intelligence.
- Monitor Suspicious Activities: Set up real-time transaction monitoring to spot anomalies quickly. Utilize behavioral analytics to detect unusual patterns, such as odd login locations, IP addresses, or trading activities.
- Partner with Blockchain Analysis Firms: Work closely with blockchain analysis firms like Chainalysis or Elliptic to track stolen funds and identify suspicious transactions.
- Educate Employees on Security: Train employees on various social engineering tactics, including LinkedIn phishing scams. Conduct thorough background checks on new hires to minimize the risk of insider threats.
- Require Hardware Security Keys for Internal Access: Ensure that only employees with hardware security keys have internal access to sensitive information.
- Prepare for Supply Chain Attacks: Vet all code updates thoroughly to avoid backdoors. Utilize code signing certificates and secure software development practices to safeguard your platform.
For Regulators
- Mandate Strong Security Standards: Enforce robust security measures for crypto platforms to ensure they meet industry best practices.
- Sanction Suspicious Wallets: Block, freeze, and sanction wallets and transactions linked to the Lazarus Group’s operations.
- Require Timely Breach Reporting: Require platforms to immediately report breaches to regulators to ensure quick responses.
- Regulate Crypto Mixers and Privacy Coins: Set regulations around crypto mixers like Tornado Cash and privacy coins such as Monero to prevent their use in laundering stolen funds.
- Collaborate with Blockchain Analytics Platforms: Fund and collaborate with blockchain analytics firms and forensics teams to enhance the tracking of illicit activities.
- Facilitate Industry Awareness: Run awareness campaigns and provide industry guidance to help crypto platforms stay secure and comply with regulations.
- Encourage Cross-Border Cooperation: Lazarus operates globally, so international cooperation between regulators, intelligence agencies, and law enforcement is essential. Organizations like Interpol, Europol, and the FATF (Financial Action Task Force) should collaborate to ensure a unified global response.
Lazarus Group and the Crypto Industry: What Does the Future Hold?
As with previous hacks, the Bybit attack has raised many concerns about the future of the crypto industry, especially as Lazarus Group continues to launch increasingly sophisticated attacks. With their ability to evolve, it wouldn’t be surprising if they began using AI-generated content, such as fake videos and voices, to bolster their phishing and impersonation schemes in the near future.
Moreover, there is no confirmed report of the Lazarus Group targeting a decentralized exchange (DEX) in any publicly known cyberattack. However, this has led to many questions about whether DEXs are inherently safer and more reliable than centralized platforms.
Although DEXs are built with innovative features like smart contracts and liquidity pools, which make them more resistant to attack, they are not invincible. The Lazarus Group’s technical expertise and adaptability mean they could exploit vulnerabilities in DEXs if weaknesses are found, particularly in smart contracts, governance mechanisms, or bridges between different blockchains.
Final Thoughts
The Lazarus Group remains a significant threat to the cryptocurrency industry. Their ability to exploit weaknesses and continuously adapt strategies has solidified their reputation as one of the most dangerous cybercriminal organizations.
Despite the ongoing efforts to curb their activities and improve security, the Lazarus Group continues to wreak havoc. Understanding how the group operates and staying informed is critical for individuals and platforms hoping to avoid becoming their next target. The tips provided in this article are essential to safeguarding your crypto assets in this volatile landscape.
The big question remains: Will the industry fight back effectively? Will the Lazarus Group ever be stopped? Only time will tell.












