Tag: Lazarus Group

  • Bitget Hack Still Ongoing as New Developments Emerge

    Bitget Hack Still Ongoing as New Developments Emerge

    Key Highlights

    • On-chain data indicates a potential exploit at cryptocurrency exchange Bitget, with over $170 million in assets moved from three hot wallets and one cold wallet across multiple networks, primarily converted to Ethereum ($ETH).
    • An attacker address on Arbitrum acquired 7,111 $ETH in six minutes using approximately 19.67 million USDT0 via UniswapX and 1inch Fusion, executing some trades at a 5% premium to spot prices.
    • Bitget has begun moving remaining funds—approximately $530 million—from the affected wallets to secure addresses in what appears to be an emergency containment effort, while the root cause and potential North Korea links remain unconfirmed.

    Massive On-Chain Outflows Trigger Hack Suspicions at Bitget

    Unusual on-chain activity detected in wallets allegedly controlled by the centralized exchange Bitget has sparked widespread suspicion of a significant security breach. Blockchain analytics reveal that high-value assets have been systematically drained from the exchange’s hot and cold wallet infrastructure, with the bulk of the stolen funds rapidly converted into Ethereum ($ETH). The incident appears to span multiple blockchain networks, suggesting a broad compromise rather than an isolated vulnerability on a single chain.

    Arbitrum Transactions Reveal Speed and Scale of Attack

    Initial alarm was raised by a flurry of transactions on the Arbitrum network. A newly created address purchased 7,111 $ETH in a mere six minutes, spending approximately 19.67 million USDT0 sourced directly from a Bitget hot wallet. The trades were routed through UniswapX and 1inch Fusion, with several executions occurring at prices roughly 5% above the prevailing spot rate. This aggressive buying pressure momentarily pushed the WETH/USDC pool price to $2,870, illustrating the urgency and volume of the asset conversion.

    Compromise Extends Across Multiple Wallets and Asset Classes

    Subsequent blockchain analysis indicates the breach is not confined to a single wallet or network. Data shared by on-chain investigators suggests three hot wallets and one cold wallet associated with Bitget have been impacted. A diverse range of assets—including $ETH, AVAX, BNB, $USDC, $USDT, USDT0, and XAUT—have been moved from these addresses. The addresses attributed to the attacker continue to swap remaining stablecoin balances ($USDC and $USDT) for $ETH, driving the total tracked on-chain loss above $170 million. Early social media speculation had placed the figure at over $100 million, but cross-network transaction tracing has since revised the estimate upward.

    Exchange Initiates Emergency Containment Measures

    In a significant development approximately five minutes prior to this report, Bitget-owned addresses began actively transferring assets remaining in the compromised wallets to new destinations. Roughly $530 million in assets are still held within the affected wallet cluster. This movement is being interpreted by analysts as an emergency fund transfer and a security measure to isolate wallets not yet believed to be compromised. The exchange has not yet issued a formal public statement detailing the root cause, leaving critical questions unanswered regarding whether private keys were exposed or if a deeper infrastructure vulnerability was exploited.

    Why This Matters

    The suspected breach at Bitget represents one of the largest exchange-related security incidents in recent months, underscoring the persistent systemic risk posed by centralized custody of digital assets. The sophistication of the attack—leveraging advanced DEX aggregators like UniswapX and 1inch Fusion for rapid, high-slippage conversion to Ether—suggests a highly capable actor. Unverified claims attributing the hack to North Korea-linked groups, such as the Lazarus Group, align with historical patterns of state-sponsored cybercrime targeting crypto exchanges to fund sanctioned regimes. If confirmed, this would mark another major success for such actors. For the broader market, the incident tests the resilience of exchange solvency proofs and the effectiveness of real-time on-chain monitoring in mitigating losses. The next 24 to 48 hours are critical: the industry will be watching for Bitget’s official incident report, proof-of-reserves updates, and whether the remaining $530 million in identified wallets can be fully secured.

    Frequently Asked Questions

    How much money was stolen in the Bitget hack?

    On-chain analysis currently estimates the total value of assets moved by the attacker exceeds $170 million. Approximately $530 million remains in the affected wallets, which Bitget is actively moving to secure addresses.

    Which networks and tokens were affected?

    The exploit spanned multiple networks, with initial major activity on Arbitrum. Assets moved include Ethereum ($ETH), AVAX, BNB, $USDC, $USDT, USDT0, and XAUT. The attacker is converting stablecoins into $ETH.

    Has Bitget confirmed the hack and are user funds safe?

    As of this report, Bitget has not released an official statement confirming the hack or detailing the cause. However, on-chain data shows the exchange has begun transferring remaining funds from the compromised wallets, suggesting an active emergency response. Users should monitor official Bitget channels for updates.

  • North Korean Hackers Move Tens of Millions on Hyperliquid as Trump Pushes to Bring Crypto Platform Onshore

    North Korean Hackers Move Tens of Millions on Hyperliquid as Trump Pushes to Bring Crypto Platform Onshore

    Kraken said compliance is central to its operations and that it uses blockchain analytics partnerships to monitor onchain activity and block assets linked to sanctioned wallets before they reach the exchange. A representative for Kraken told CoinDesk that “compliance is foundational to how we operate. Kraken maintains a best-in-class compliance program, including partnerships with leading blockchain analytics providers that continuously monitor onchain activity. These controls are designed to identify and block any assets associated with sanctioned wallets before they enter our platform.”

    LBank said it has consistently relied on industry-standard compliance tools for ongoing monitoring. However, the exchange acknowledged that the crypto industry is “inherently cross-platform, cross-chain, and cross-jurisdictional.”

    “As a result,” the spokesperson added, “relevant risks are often not generated by, or capable of being independently identified and addressed by, any single platform, but instead represent an ongoing challenge faced by the industry as a whole.”

    KuCoin said it could not verify or comment on the sanctioned-wallet activity without reviewing the underlying data. CoinDesk declined to provide that data before publication.

    “We would also note that public onchain data reflects the movement of assets but does not necessarily provide a complete picture of compliance actions taken by a centralized platform after assets reach the platform. Measures such as account restrictions, regulatory reporting, or other risk-control actions may occur at the account or platform level and may not be visible from public blockchain data alone,” the representative said, adding that the exchange “maintains sanctions compliance policies and procedures designed to meet applicable legal and regulatory requirements.”

    Lazarus Group’s Hyperliquid activity

    The Lazarus Group’s use of Hyperliquid could expose the platform to scrutiny from authorities if it violates U.S. sanctions laws. The activity comes as the Trump administration considers how Hyperliquid could be integrated into the regulated U.S. financial system.

  • Lazarus Moves $30 Million Through Hyperliquid as U.S. Talks Advance

    Lazarus Moves $30 Million Through Hyperliquid as U.S. Talks Advance

    Wallets linked to North Korea’s Lazarus Group have sold more than $30 million worth of Bitcoin through Hyperliquid over the past three weeks, converting the proceeds into Ethereum and Solana before transferring the assets to centralized exchanges, according to Arkham blockchain data.

    Lazarus-linked wallets move Bitcoin into ETH and SOL

    Arkham said wallets associated with the North Korean state-sponsored Lazarus Group sold more than $30 million in Bitcoin on Hyperliquid during the three-week period. The wallets then used the proceeds to buy Ethereum and Solana, sending the assets to exchanges including Kraken, LBank and KuCoin.

    Crypto investigator ZachXBT first identified the addresses in 2024. Arkham later labeled them as connected to Lazarus.

    Public blockchain records show transfers between addresses but do not identify the individuals or entities controlling receiving exchange accounts. CoinDesk reported that it could not determine who held the accounts or whether the exchanges knew about the reported source of the funds.

    Kraken said compliance is central to its operations and that it continuously monitors blockchain activity with support from analytics providers. The exchange said its controls are designed to identify and block assets connected to sanctioned wallets before they reach the platform.

    LBank said it uses industry-standard compliance tools for continuous monitoring. The exchange described illicit transfers across platforms, blockchains and jurisdictions as an industry-wide problem that no single company can independently detect or resolve.

    KuCoin said it could not confirm the reported activity without reviewing the underlying wallet data. It also cautioned that public blockchain records do not reveal every action taken after assets arrive at a centralized platform, including account restrictions, regulatory reports and other risk controls.

    Hyperliquid transfers raise U.S. sanctions concerns

    The reported transfers have a direct U.S. regulatory dimension because the Treasury Department has sanctioned Lazarus Group and identified it as a cyber organization controlled by the North Korean government.

    U.S. authorities have linked Lazarus to several digital-asset thefts, including the $625 million Ronin Network attack in 2022. As previously reported by crypto.news, former Defense Secretary Mark Esper recently cited North Korean hacking groups while arguing that regulated domestic crypto markets could give U.S. law enforcement better access to customer and transaction records.

    Using a decentralized trading venue can complicate enforcement because Hyperliquid allows users to connect a wallet and trade without opening a traditional brokerage account. Its public blockchain still records transactions, enabling firms such as Arkham to trace transfers between labeled addresses.

    However, the presence of assets linked to a sanctioned actor on a decentralized platform does not establish that Hyperliquid assisted the activity or knew who controlled the wallets. CoinDesk’s report also did not establish that Kraken, LBank or KuCoin credited the transferred assets to unrestricted customer accounts.

    Any U.S. plan to offer Hyperliquid-linked products domestically would need to address sanctions screening, customer identification and account-level controls. Wallet checks can identify previously labeled addresses, but funds may pass through multiple assets or wallets before reaching another venue.

    A recent Hyperliquid testnet deployment illustrated how a permissioned version of its infrastructure could operate. In August, a deployer using Kraken’s name whitelisted 10 wallets and tested controls for canceling orders, reducing positions and moving collateral.

    Neither Kraken nor Hyperliquid had confirmed ownership of the deployment when the report appeared. Because Hyperliquid’s testnet allows outside deployments, the use of the Kraken name alone did not prove that the exchange created or operated it.

    Payward explores regulated Hyperliquid access for U.S. traders

    Bloomberg reported that Kraken parent company Payward is in advanced discussions with Hyperliquid Labs about offering selected perpetual contracts to American traders through Bitnomial, its CFTC-regulated derivatives business.

    People familiar with the talks told Bloomberg that Payward had presented the Commodity Futures Trading Commission with an outline of the proposed structure. Any agreement would still require regulatory approval, while the financial terms remain unknown. Payward and Hyperliquid Labs declined to comment to Bloomberg.

    President Donald Trump brought the potential U.S. expansion into public view during an Aug. 19 White House event. Referring to CFTC Chair Michael Selig, Trump said he understood that the regulator was working to bring Hyperliquid into the United States in a “fully compliant and legal fashion.”

    A Payward arrangement would give eligible U.S. customers access through a registered operator rather than Hyperliquid’s permissionless interface. Commodity derivatives offered to American retail traders generally must use CFTC-regulated entities, and wallet screening alone does not replace exchange, clearing and brokerage requirements.

    Payward already has the regulatory infrastructure required to operate in the U.S. derivatives market. The company completed its Bitnomial purchase in May after agreeing to pay as much as $550 million in cash and stock.

    The acquisition gave Payward control of a designated contract market, a derivatives clearing organization and a futures commission merchant. Together, the three registrations cover trading, clearing and brokerage services under CFTC oversight.

    Kraken launched regulated perpetuals for eligible U.S. customers in June. The service allows supported users to trade spot, margin, traditional futures and perpetual futures through Kraken Pro while using Bitnomial’s regulated structure.

    Hyperliquid remains a leading decentralized perpetuals platform

    Hyperliquid operates its main exchange through HyperCore, an on-chain trading system that handles order matching, margin calculations and liquidations. Users trade from connected crypto wallets, while the platform’s primary permissionless interface does not require a conventional brokerage account.

    Perpetual futures differ from dated futures because they have no fixed expiry. Funding payments between long and short traders help keep contract prices close to the value of their underlying assets, allowing positions to remain open as long as traders meet margin requirements.

    DefiLlama data showed that Hyperliquid had processed approximately $5.19 trillion in cumulative perpetual trading volume at the time of writing. Its perpetual markets recorded about $60.44 billion in seven-day volume and $204.95 billion during the previous 30 days.

    Open interest stood at roughly $13.3 billion, representing the notional value of outstanding perpetual positions. DefiLlama also recorded more than $32.6 billion in cumulative liquidations on the platform, including approximately $2.25 billion during the preceding 30 days.

    Beyond markets operated by the core protocol, Hyperliquid Improvement Proposal 3 allows outside developers to launch independent perpetual exchanges using HyperCore. Deployers select their contracts, collateral, leverage limits, funding settings and price sources after staking 500,000 HYPE.

    Validators can slash the stake if a deployer manipulates an oracle or violates market rules. HIP-3 operators receive half of the trading fees generated by their markets, while newer permission tools tested on the network could allow individual deployers to restrict access to approved wallets.

  • Lazarus Group Resurfaces With $19.4 Million Bitcoin Transfer

    Lazarus Group Resurfaces With $19.4 Million Bitcoin Transfer

    Bitcoin wallets linked to the North Korean hacking group Lazarus transferred 244.148 BTC worth approximately $19.42 million, renewing attention on the group’s ongoing cryptocurrency activity.

    Lazarus-linked wallets move 244.148 BTC

    Blockchain analytics firm Lookonchain reported the transfer in an Aug. 28 X post, saying wallets attributed to Lazarus Group had become active and moved 244.148 BTC about an hour before the alert.

    Bitcoin was trading at roughly $79,500 when Lookonchain published its estimate, placing the transaction’s value at about $19.42 million. The analytics firm did not identify the receiving address or say whether the Bitcoin was sent to an exchange, mixer or another wallet controlled by the group.

    Without a disclosed destination, the transfer alone does not prove that Lazarus sold the Bitcoin or attempted to cash out. Public blockchain records show when funds move between addresses, but attributing those addresses to an organization generally depends on labels and analysis from investigators or blockchain intelligence firms.

    The Aug. 28 movement followed another large Bitcoin transfer attributed to Lazarus earlier in the month. On Aug. 12, Lookonchain said the group moved 262.2 BTC, then worth approximately $16.64 million, from an identified wallet to a newly created address.

    At the time, Lookonchain described that transaction as a wallet-to-wallet transfer rather than a sale. Based on the reported dollar values, the two August transactions involved more than $36 million in Bitcoin. However, no source has confirmed that the funds came from the same balance or served the same purpose.

    Earlier wallet activity highlights why the destination of the latest transfer matters. In March 2025, five unknown addresses received a combined 44.07 BTC worth approximately $3.76 million from wallets attributed to Lazarus, according to previous on-chain reporting. The transactions reduced the tracked wallet’s holdings to 13,441 BTC at the time.

    Bybit theft spread Bitcoin across thousands of addresses

    As crypto.news previously reported, Bybit sued North Korea and Lazarus Group in a Washington, D.C., federal court on Aug. 7, seeking to recover assets linked to the exchange’s $1.5 billion theft.

    The lawsuit also named North Korea’s Reconnaissance General Bureau, or RGB, which the U.S. Treasury identifies as the country’s primary intelligence agency. A federal judge issued a preliminary injunction blocking unidentified defendants from transferring, selling or disposing of certain assets connected to the case.

    Bybit filed the civil lawsuit separately from ongoing U.S. criminal investigations. A preliminary injunction preserves identified property while litigation continues and does not represent a final ruling on ownership or liability.

    The FBI attributed the February 2025 Bybit attack to North Korean actors operating under the TraderTraitor name. According to the agency, the attackers converted part of the stolen holdings into Bitcoin and other assets before distributing them across thousands of addresses on multiple blockchains.

    In its public alert, the FBI said it expected the assets to be moved again and eventually exchanged for government-issued currency. The bureau asked exchanges, bridges, decentralized finance services, blockchain analytics companies and node operators to block transactions involving the addresses it identified.

    By April 2025, Bybit CEO Ben Zhou said 27.6% of the stolen funds could no longer be tracked, according to an August report on North Korea’s attack methods. The report said that distributing the assets across numerous Bitcoin wallets had made blockchain tracing more difficult.

    Lookonchain has not directly connected the latest 244.148 BTC transfer to the Bybit theft. No government agency or blockchain intelligence company cited in the available reporting has publicly identified the source of the coins involved in the Aug. 28 movement.

    Lazarus-linked crypto attacks continued into 2026

    Chainalysis estimated that North Korean hackers stole at least $2.02 billion in cryptocurrency during 2025, a 51% increase from the previous year. The firm estimated North Korea’s cumulative cryptocurrency theft had reached at least $6.75 billion by the end of that period.

    According to its December 2025 report, North Korean operations accounted for 76% of the value lost through attacks on crypto services during the year. Chainalysis said the attackers carried out fewer confirmed incidents but extracted larger amounts from successful breaches.

    The firm also found that North Korean operators increasingly targeted companies through impersonation and employee-access schemes. Some actors posed as job applicants to gain entry to crypto businesses, while others pretended to recruit for established Web3 and artificial intelligence companies, according to Chainalysis.

    Activity attributed to Lazarus continued in April 2026, when attackers drained approximately 116,500 rsETH worth about $292 million from KelpDAO’s LayerZero-based bridge. LayerZero attributed the attack with preliminary confidence to the Lazarus Group’s TraderTraitor unit.

    Chainalysis later said the attackers had compromised infrastructure that supplied blockchain information to LayerZero’s verification system. By feeding false data into the system, they caused an Ethereum contract to release assets even though no corresponding token burn had occurred on the source network.

    Rapid intervention blocked a second attempted theft worth approximately $95 million, according to Chainalysis. The Arbitrum Security Council also froze more than 30,000 ETH that investigators connected to the attacker’s subsequent transactions.

    By June, the KelpDAO attacker had moved approximately $220 million in unfrozen assets through privacy services, according to subsequent tracking data. The routes included THORChain, Wasabi, Tornado Cash and Umbra, while approximately $1.7 million remained in the original wallets.

    U.S. sanctions restrict dealings with Lazarus Group

    The U.S. Treasury’s Office of Foreign Assets Control sanctioned Lazarus Group in September 2019 under an executive order targeting the North Korean government. OFAC identified Lazarus, Bluenoroff and Andariel as state-controlled hacking groups connected to the RGB.

    Under the designation, property belonging to Lazarus that enters the United States or comes into the possession or control of a U.S. person must be blocked and reported to OFAC. Treasury regulations also generally prohibit Americans from conducting transactions with sanctioned entities unless authorized by the agency.

    The Treasury said Lazarus had targeted governments, financial institutions, media companies, manufacturers, infrastructure operators and cryptocurrency businesses through cyber theft, espionage and malware attacks. The department linked the group to the 2014 Sony Pictures breach and the WannaCry ransomware attack, which affected computers across at least 150 countries.

    U.S. authorities have also taken action against services used to process funds linked to the group. In 2022, the Treasury sanctioned the virtual currency mixer Blender.io after saying it had processed more than $20.5 million from the roughly $620 million Ronin Network theft. The FBI later attributed the Ronin attack to Lazarus Group and APT38.

    In August 2023, the FBI separately warned cryptocurrency companies about movements involving Bitcoin stolen by North Korean TraderTraitor actors. The agency said the group could attempt to cash out more than $40 million in Bitcoin and published six wallet addresses for private companies to investigate.