EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Lazarus Group reappeared and transferred $19.4 million in Bitcoin

2026-08-29 12:16:03
Bookmark

North Korea-related Lazarus Group transferred 244.148 bitcoins worth approximately US$19.42 million

North Korea-related Lazarus Group transferred 244.148 bitcoins worth approximately US$19.42 million, a move that has renewed attention to wallets associated with one of the most active hacker groups in the cryptocurrency industry.

Summary

According to Lookonchain data, Lazarus Group transferred 244.148 bitcoins worth approximately US$19.42 million. The recipient of the deal and its connection to any previous theft have not been made public. In early August this year, another wallet related to Lazarus transferred 262.2 bitcoins to a new address. U.S. sanctions generally prohibit Americans from trading in property related to the Lazarus Group.

Lazarus Group transfers 244 bitcoins between wallets

Lookonchain reported the transfer in a post on August 28, saying that the wallet belonging to the Lazarus Group was again active and that 244.148 bitcoins were transferred about an hour before it issued the alert. When the analytics account released its valuation, the Bitcoin transaction price was approximately US$79,500, making the transaction worth US$19.42 million. Lookonchain did not specify the receiving address in the body of the post, nor did it say whether bitcoin was transferred to an exchange, currency mixer or other wallet controlled by the group. Since the destination was not disclosed, the transaction alone does not prove that Lazarus Group has sold or attempted to cash in Bitcoin. Public blockchain records can confirm that funds were transferred between addresses, but linking those addresses to an organization often relies on tags and analysis provided by investigators or blockchain intelligence companies.

The August 28 transaction occurred after the group made another large bitcoin transfer earlier this month. On August 12, Lookonchain stated that Lazarus Group had transferred 262.2 bitcoins, valued at approximately $16.64 million at the time, from an identified wallet to a newly created address. At the time, the analytics account described the transaction as a transfer between wallets rather than a sale. Based on reported dollar value, two transactions in August involved more than $36 million in Bitcoin, but no source has confirmed that the transactions came from the same balance or served the same purpose.

Past wallet activity shows why destination is important. According to previous online reports, in March 2025, five unknown addresses received a total of 44.07 bitcoins, worth approximately US$3.76 million, from wallets belonging to the Lazarus Group. These transactions reduced the tracking wallet's holdings to 13,441 bitcoins at the time.

Bybit theft spreads bitcoin to thousands of addresses

On August 7, Bybit filed a lawsuit against North Korea and Lazarus Group in federal court in Washington, D.C., seeking to recover assets related to $1.5 billion in stolen funds from the exchange. The lawsuit also names North Korea's General Reconnaissance Administration (RGB), which the U.S. Treasury Department identifies as the country's main intelligence agency. A federal judge issued a preliminary injunction prohibiting the unnamed defendant from transferring, selling or disposing of certain assets related to the case. The civil lawsuit filed by Bybit is carried out separately from the ongoing criminal investigation in the United States. The preliminary injunction preserved the identified property during the litigation and did not constitute a final judgment of ownership or liability.

The FBI blamed the February 2025 Bybit attack on North Korean actors operating under the name of "TraderTraitor." According to the agency, the attackers converted some of the stolen assets into Bitcoin and other assets, and then dispersed them to thousands of addresses on multiple blockchains. In a public alert, the FBI said it expected the assets to be transferred again and eventually converted into government-issued legal tender. The bureau requires exchanges, cross-chain bridges, decentralized financial services, blockchain analytics companies and node operators to block transactions involving addresses they identify.

By April 2025, Bybit CEO Ben Zhou said that 27.6% of stolen funds were no longer traceable. The same report noted that assets are dispersed among numerous Bitcoin wallets, making blockchain tracking more difficult.

Lookonchain has not yet directly linked the latest transfer of 244.148 bitcoins to the Bybit theft. No government agency or blockchain intelligence company cited in existing reports has publicly disclosed the source of the coins involved in the August 28 transaction.

Lazarus-related attacks continue into 2026

Chainalysis estimates that North Korean hackers stole at least $2.02 billion in cryptocurrency in 2025, a 51% increase from the previous year. The company said that as of the end of the period, North Korea's cumulative amount of cryptocurrency theft was no less than US$6.75 billion. According to its December 2025 report, North Korea operations accounted for 76% of the value of losses from cryptocurrency service attacks that year. Chainalysis stated that the attacker carried out a smaller number of confirmed events, but extracted a larger amount of money in a successful breach. The company has also found that North Korean operators are increasingly targeting the company through impersonation and employee visits. Chainalysis pointed out that some actors enter cryptocurrency companies disguised as job seekers, while others pretend to recruit for well-known Web3 and artificial intelligence companies.

Activity attributed to Lazarus continued in April 2026, when attackers stole approximately 116,500 rsETH, worth approximately $292 million, from KelpDAO's LayerZero-based cross-chain bridge. LayerZero initially believed that the attack was carried out by the Lazarus Group's "TraderTraitor" unit. Chainalysis later stated that the attacker compromised the infrastructure that provided blockchain information to the LayerZero verification system. By entering fake data into the system, they caused an Ethereum contract to release assets, even though no corresponding token destruction occurred on the source network. According to Chainalysis, rapid intervention prevented a second attempted theft worth approximately $95 million. The Arbitrum Security Committee also froze more than 30,000 ETH pieces, which investigators linked to downstream transactions by attackers.

By June, according to follow-up tracking data, KelpDAO attackers had transferred approximately $220 million in unfrozen assets through privacy services. Transfer paths include THORChain, Wasabi, Tornado Cash and Umbra, while approximately $1.7 million is still in the original wallet. U.S. sanctions restrict transactions with the Lazarus Group.

U.S. sanctions restrict transactions with Lazarus Group

In September 2019, the U.S. Treasury Department's Office of Foreign Assets Control (OFAC) placed Lazarus Group on the sanctions list based on an executive order against the North Korean government. OFAC identified Lazarus, Bluenoroff and Andariel as state-controlled hacking groups related to RGB. Under the sanctions, property belonging to the Lazarus Group that enters the United States or is owned or controlled by Americans must be frozen and reported to OFAC. Treasury regulations also typically prohibit Americans from trading with sanctioned entities unless authorized by the agency. The Ministry of Finance said the Lazarus Group targets governments, financial institutions, media companies, manufacturers, infrastructure operators and cryptocurrency companies through cyber theft, espionage and malware attacks. The department linked the group to the 2014 Sony Pictures intrusion and the WannaCry ransomware attack that affected computers in at least 150 countries.

U.S. authorities also took action on services used to process funds related to the group. In 2022, the Treasury Department sanctioned virtual currency mixer Blender.io after the agency said it handled more than $20.5 million in an approximately $620 million theft case from the Ronin Network. The FBI later blamed the Ronin attack on the Lazarus Group and APT38. In August 2023, the FBI issued separate warnings to cryptocurrency companies about the transfer of bitcoins stolen by North Korean TraderTraitor actors. The agency said the group may have tried to cash in more than $40 million in Bitcoin and released six wallet addresses for inspection by private companies.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP