Lazarus Group Resurfaces With $19.4 Million Bitcoin Transfer

Evan Mercer
28 Aug 2026 17:05
Coins 0 6
6 minutes reading

Bitcoin wallets linked to the North Korean hacking group Lazarus transferred 244.148 BTC worth approximately $19.42 million, renewing attention on the group’s ongoing cryptocurrency activity.

Lazarus-linked wallets move 244.148 BTC

Blockchain analytics firm Lookonchain reported the transfer in an Aug. 28 X post, saying wallets attributed to Lazarus Group had become active and moved 244.148 BTC about an hour before the alert.

Bitcoin was trading at roughly $79,500 when Lookonchain published its estimate, placing the transaction’s value at about $19.42 million. The analytics firm did not identify the receiving address or say whether the Bitcoin was sent to an exchange, mixer or another wallet controlled by the group.

Without a disclosed destination, the transfer alone does not prove that Lazarus sold the Bitcoin or attempted to cash out. Public blockchain records show when funds move between addresses, but attributing those addresses to an organization generally depends on labels and analysis from investigators or blockchain intelligence firms.

The Aug. 28 movement followed another large Bitcoin transfer attributed to Lazarus earlier in the month. On Aug. 12, Lookonchain said the group moved 262.2 BTC, then worth approximately $16.64 million, from an identified wallet to a newly created address.

At the time, Lookonchain described that transaction as a wallet-to-wallet transfer rather than a sale. Based on the reported dollar values, the two August transactions involved more than $36 million in Bitcoin. However, no source has confirmed that the funds came from the same balance or served the same purpose.

Earlier wallet activity highlights why the destination of the latest transfer matters. In March 2025, five unknown addresses received a combined 44.07 BTC worth approximately $3.76 million from wallets attributed to Lazarus, according to previous on-chain reporting. The transactions reduced the tracked wallet’s holdings to 13,441 BTC at the time.

Bybit theft spread Bitcoin across thousands of addresses

As crypto.news previously reported, Bybit sued North Korea and Lazarus Group in a Washington, D.C., federal court on Aug. 7, seeking to recover assets linked to the exchange’s $1.5 billion theft.

The lawsuit also named North Korea’s Reconnaissance General Bureau, or RGB, which the U.S. Treasury identifies as the country’s primary intelligence agency. A federal judge issued a preliminary injunction blocking unidentified defendants from transferring, selling or disposing of certain assets connected to the case.

Bybit filed the civil lawsuit separately from ongoing U.S. criminal investigations. A preliminary injunction preserves identified property while litigation continues and does not represent a final ruling on ownership or liability.

The FBI attributed the February 2025 Bybit attack to North Korean actors operating under the TraderTraitor name. According to the agency, the attackers converted part of the stolen holdings into Bitcoin and other assets before distributing them across thousands of addresses on multiple blockchains.

In its public alert, the FBI said it expected the assets to be moved again and eventually exchanged for government-issued currency. The bureau asked exchanges, bridges, decentralized finance services, blockchain analytics companies and node operators to block transactions involving the addresses it identified.

By April 2025, Bybit CEO Ben Zhou said 27.6% of the stolen funds could no longer be tracked, according to an August report on North Korea’s attack methods. The report said that distributing the assets across numerous Bitcoin wallets had made blockchain tracing more difficult.

Lookonchain has not directly connected the latest 244.148 BTC transfer to the Bybit theft. No government agency or blockchain intelligence company cited in the available reporting has publicly identified the source of the coins involved in the Aug. 28 movement.

Lazarus-linked crypto attacks continued into 2026

Chainalysis estimated that North Korean hackers stole at least $2.02 billion in cryptocurrency during 2025, a 51% increase from the previous year. The firm estimated North Korea’s cumulative cryptocurrency theft had reached at least $6.75 billion by the end of that period.

According to its December 2025 report, North Korean operations accounted for 76% of the value lost through attacks on crypto services during the year. Chainalysis said the attackers carried out fewer confirmed incidents but extracted larger amounts from successful breaches.

The firm also found that North Korean operators increasingly targeted companies through impersonation and employee-access schemes. Some actors posed as job applicants to gain entry to crypto businesses, while others pretended to recruit for established Web3 and artificial intelligence companies, according to Chainalysis.

Activity attributed to Lazarus continued in April 2026, when attackers drained approximately 116,500 rsETH worth about $292 million from KelpDAO’s LayerZero-based bridge. LayerZero attributed the attack with preliminary confidence to the Lazarus Group’s TraderTraitor unit.

Chainalysis later said the attackers had compromised infrastructure that supplied blockchain information to LayerZero’s verification system. By feeding false data into the system, they caused an Ethereum contract to release assets even though no corresponding token burn had occurred on the source network.

Rapid intervention blocked a second attempted theft worth approximately $95 million, according to Chainalysis. The Arbitrum Security Council also froze more than 30,000 ETH that investigators connected to the attacker’s subsequent transactions.

By June, the KelpDAO attacker had moved approximately $220 million in unfrozen assets through privacy services, according to subsequent tracking data. The routes included THORChain, Wasabi, Tornado Cash and Umbra, while approximately $1.7 million remained in the original wallets.

U.S. sanctions restrict dealings with Lazarus Group

The U.S. Treasury’s Office of Foreign Assets Control sanctioned Lazarus Group in September 2019 under an executive order targeting the North Korean government. OFAC identified Lazarus, Bluenoroff and Andariel as state-controlled hacking groups connected to the RGB.

Under the designation, property belonging to Lazarus that enters the United States or comes into the possession or control of a U.S. person must be blocked and reported to OFAC. Treasury regulations also generally prohibit Americans from conducting transactions with sanctioned entities unless authorized by the agency.

The Treasury said Lazarus had targeted governments, financial institutions, media companies, manufacturers, infrastructure operators and cryptocurrency businesses through cyber theft, espionage and malware attacks. The department linked the group to the 2014 Sony Pictures breach and the WannaCry ransomware attack, which affected computers across at least 150 countries.

U.S. authorities have also taken action against services used to process funds linked to the group. In 2022, the Treasury sanctioned the virtual currency mixer Blender.io after saying it had processed more than $20.5 million from the roughly $620 million Ronin Network theft. The FBI later attributed the Ronin attack to Lazarus Group and APT38.

In August 2023, the FBI separately warned cryptocurrency companies about movements involving Bitcoin stolen by North Korean TraderTraitor actors. The agency said the group could attempt to cash out more than $40 million in Bitcoin and published six wallet addresses for private companies to investigate.

No Comments

Leave a Reply

Your email address will not be published. Required fields are marked *