
Lazarus Group moves 244 BTC between wallets
The North Korea-linked Lazarus Group has transferred 244.148 Bitcoin worth about $19.42 million, according to blockchain analytics platform Lookonchain. In an Aug. 28 X post, Lookonchain said wallets attributed to Lazarus Group had become active again and moved 244.148 BTC about an hour before its alert. At the time, Bitcoin traded at roughly $79,500, placing the transaction’s value at $19.42 million.
Lookonchain did not identify the receiving address in the text of the post or say whether the Bitcoin moved to an exchange, a mixer, or another wallet controlled by the group. Without a disclosed destination, the transaction alone does not show that Lazarus sold or attempted to cash out the Bitcoin. Public blockchain records confirm when funds move between addresses, but connecting those addresses to an organization usually depends on labels and analysis supplied by investigators or blockchain intelligence firms.
A second large transfer in August
The Aug. 28 transaction followed another large Bitcoin movement attributed to the group earlier in the month. On Aug. 12, Lookonchain said Lazarus transferred 262.2 BTC, then valued at approximately $16.64 million, from an identified wallet to a newly created address. The analytics account described the transaction as a wallet-to-wallet transfer rather than a sale. Taken at their reported dollar values, the two August movements involved more than $36 million in Bitcoin, though no source has confirmed that the transactions came from the same balance or served the same purpose.
Past wallet activity and the Bybit connection
Past wallet activity shows why the destination matters. In March 2025, a tracked wallet received a combined 44.07 BTC worth about $3.76 million from wallets attributed to Lazarus, according to earlier on-chain reporting. Those transactions reduced the tracked wallet’s holdings to 13,441 BTC at the time.
As crypto.news previously reported, Bybit filed a civil action in a Washington, D.C., federal court on Aug. 7 against the Lazarus Group, seeking to recover assets tied to the exchange’s $1.5 billion theft. The lawsuit also named North Korea’s Reconnaissance General Bureau, or RGB, which the U.S. Treasury identifies as the country’s main intelligence agency. A federal judge issued a preliminary injunction that blocked unidentified defendants from transferring, selling, or disposing of certain assets connected to the case. Bybit filed the civil action separately from ongoing U.S. criminal investigations. A preliminary injunction preserves the identified property while litigation continues and does not amount to a final decision on ownership or liability.
The Bybit theft and its aftermath
The FBI attributed the February 2025 Bybit attack to North Korean actors operating under the TraderTraitor name. According to the agency, the attackers converted part of the stolen holdings into Bitcoin and other assets before spreading them across thousands of addresses on several blockchains. In a public alert, the FBI said it expected the assets to be moved again and eventually exchanged for government-issued currency. The bureau asked exchanges, bridges, decentralized finance services, blockchain analytics companies, and node operators to block transactions involving the addresses it identified.
By April 2025, Bybit CEO Ben Zhou said 27.6% of the stolen funds could no longer be tracked, according to an August report. The same report said the distribution of assets across many Bitcoin wallets had made blockchain tracing more difficult. Lookonchain has not connected the latest 244.148 BTC transfer directly to the Bybit theft, and no government agency or blockchain intelligence company cited in the available reporting has publicly identified the source of the coins involved in the Aug. 28 movement.
Lazarus-linked attacks continued into 2026
Chainalysis estimated that North Korean hackers stole at least $2.02 billion in cryptocurrency during 2025, an increase of 51% from the previous year. The firm placed the country’s cumulative crypto theft at no less than $6.75 billion by the end of that period. According to its December 2025 report, North Korean operations accounted for 76% of the value lost through attacks on crypto services during the year. Chainalysis said the attackers carried out fewer confirmed incidents but extracted larger amounts from successful breaches. The firm also found that North Korean operators had increasingly targeted companies through impersonation and employee access. Some actors posed as job applicants to enter crypto businesses, while others pretended to recruit for known Web3 and artificial intelligence companies.
KelpDAO bridge exploit
Activity attributed to Lazarus continued in April 2026, when attackers drained approximately 116,500 rsETH, worth about $292 million, from KelpDAO’s LayerZero-based bridge. LayerZero attributed the attack with preliminary confidence to Lazarus Group’s TraderTraitor unit. Chainalysis later said the attackers compromised infrastructure that supplied blockchain information to LayerZero’s verification system. By feeding false data, they caused an Ethereum contract to release assets even though no matching token burn had occurred on the source network. Rapid intervention blocked a second attempted theft worth about $95 million, according to Chainalysis. The Arbitrum Security Council also froze more than 30,000 ETH connected to the attacker’s downstream transactions. By June, the KelpDAO attacker had moved approximately $220 million in unfrozen assets through privacy services, including THORChain, Wasabi, Tornado Cash, and Umbra, while around $1.7 million remained in the original wallets.
U.S. sanctions restrict dealings with Lazarus Group
The U.S. Treasury’s Office of Foreign Assets Control sanctioned Lazarus Group in September 2019 under an executive order targeting the North Korean government. OFAC identified Lazarus, Bluenoroff, and Andariel as state-controlled hacking groups connected to the RGB. Under the designation, property belonging to Lazarus that enters the United States or comes under the possession or control of a U.S. person must be blocked and reported to OFAC. Treasury regulations also generally prohibit Americans from conducting transactions with sanctioned entities unless the agency authorizes them.
Treasury said Lazarus had targeted governments, financial institutions, media companies, manufacturers, infrastructure operators, and cryptocurrency businesses through cyber theft, espionage, and malware attacks. The department linked the group to the 2014 Sony Pictures breach and the WannaCry ransomware attack that affected computers across at least 150 countries.
U.S. authorities have also acted against services used to process funds tied to the group. In 2022, Treasury sanctioned the virtual currency mixer Blender.io after saying it had handled more than $20.5 million from the roughly $620 million Ronin Network theft. The FBI later attributed the Ronin attack to Lazarus Group and APT38. In August 2023, the FBI separately warned crypto companies about movements involving Bitcoin stolen by North Korean TraderTraitor actors. The agency said the group could attempt to cash out more than $40 million in Bitcoin and published six wallet addresses for private companies to examine.






