How Lazarus Group Became One of Crypto’s Biggest Security Threats
Lazarus Group has escalated its crypto attacks, targeting exchanges, bridges, governance systems and trusted infrastructure in billion dollar thefts.
Lazarus Group has become one of the most closely watched threats in the cryptocurrency field, with North Korean-affiliated operations targeting exchanges, bridges, governance systems, and the infrastructure that connects them. The scope became inevitable after the FBI suspected North Korea of the $1.5 billion Bybit theft in February 2025.
As more recent cases with KelpDAO and Drift Protocol show, attackers now exploit trusted access and supporting infrastructure instead of relying solely on smart-contract vulnerabilities.
How Lazarus Became a Crypto Threat
Crypto was not Lazarus Group's initial focus. Before cryptocurrency became one of its most lucrative targets, the North Korean-affiliated outfit was already well-known for significant cyberattacks. But as time went on, digital assets provided attackers with something especially useful. Without requiring access to conventional banking infrastructure, large sums of money might be stolen, transferred over several networks, and converted.
The figures demonstrate the growth of the activity. According to Chainalysis, North Korean hackers stole $2.02 billion in bitcoin in 2025, bringing the total amount of theft connected to the DPRK since 2017 to roughly $6.75 billion. Nearly $1.5 billion was spent on the Bybit attack alone.

North Korea was accused by the FBI for the Bybit theft, which they named TraderTraitor. According to investigators, the stolen goods were quickly transformed and scattered among numerous blockchains and hundreds of addresses.
A shift in access is also reflected in that scale. According to Chainalysis, impersonation and infiltration by North Korean IT workers are crucial ways to obtain privileged access to cryptocurrency firms before theft.
The Billion-Dollar Trail of Hacks
The $292 million KelpDAO attack showed how much harm can be caused by technology that is not part of a blockchain's core contracts. Attackers connected to Lazarus breached the RPC infrastructure utilised in KelpDAO's LayerZero bridge environment on April 18, 2026.
In order to give the impression that tokens had been burned on the source chain when none had, they sent fake information into a verification mechanism. After that, the destination contract released about 116,500 rsETH, or roughly $292 million.

Beyond the initial theft, the act had repercussions. Following the catastrophic $292 million exploit, KelpDAO decided to leave LayerZero. As outlined in DeFi Unites, following the KelpDAO $292 million theft, the broader DeFi response was also noteworthy, with projects coordinating to confine damaged assets and limit further losses.
Bridge infrastructure is still under significant strain, as seen by several 2026 events. In a Syscoin incident, almost $5 billion worth of SYS coins were created without authorisation, and ZetaChain stopped cross-chain operations following an exploit involving about $300,000. Both incidents demonstrate how much value can rely on technologies that link several blockchain settings, even though neither is a Lazarus operation.

How Lazarus’ Attack Methods Evolved
The Drift Protocol attack unveiled an additional technique that does not rely on identifying a traditional smart contract flaw. After attackers obtained privileged administrative power, Drift lost over $285 million on April 1, 2026. Although formal attribution was still pending in its study, Chainalysis reported that preliminary on-chain signs were consistent with prior DPRK operations.
Before persuading Security Council members to unintentionally pre-sign transactions utilising Solana's durable nonce feature, the attackers allegedly spent months cultivating connections with Drift team members. They whitelisted a worthless token with an artificially inflated value after gaining administrative control, and they used it as collateral to withdraw real assets.

EtherWorld reported on the North Korean hackers linked to the $285 million Drift Protocol attack after originally covering the $280 million loss from the hack.
Smaller attacks show the same general trend toward compromised user environments. Following sensitive wallet data being exposed, a malicious Chrome extension was held accountable for a cryptocurrency loss of about $90,000. This incident was discussed in the $90K crypto loss following a Chrome extension breach.
Why Crypto Keeps Falling Victim
The Lazarus threat is emerging during a period of increasing attack volume in the broader cryptocurrency industry. According to EtherWorld, August 2026 was one of the worst months for DeFi attacks. This review emphasised how multiple events can occur in a single month, impacting protocols, bridges, and other related services.
Another illustration of how quickly an exchange must react following a significant compromise is the Bitget incident. After reporting losses of almost $351.6 million, Bitget suspended withdrawals; however, following behavior indicated that other networks would interfere with the transfer of linked cash. Without proof, the incident shouldn't be linked to the group because it hasn't been proven to be a Lazarus attack.
This distinction is important since Lazarus is a component of a much broader issue with crypto security. Treating every significant hack as a North Korean operation would make it difficult to identify the various reasons for each event. Simultaneously, the organisation serves as a crucial case study for the evolution of cyberattacks due to the recurring scope of theft associated with the DPRK.

Can the Industry Stop the Next Lazarus Attack?
The recent events demonstrate that the amount of money that eventually leaves a compromised system can be determined by response time. After identifying the unusual conduct, the team at KelpDAO halted the impacted contracts. A second effort to drain an additional $95 million in rsETH was thwarted by that intervention. Additionally, over 30,000 ETH associated with the attacker were frozen by the Arbitrum Security Council.
A similar strategy was used elsewhere. While investigators looked into the situation, Bitget decided to restrict withdrawals, and NEAR blocked $50 million linked with the Bitget hackers. Therefore, once stolen assets start to move between networks, cross-chain services can be included in the response.

Additionally, ZetaChain showed how important it is to be able to stop activity fast. As stated in ZetaChain halts cross-chain activities following a $300K attack, the network stopped cross-chain operations after its approximately $300,000 incident while the exploit was researched.
Finding the compromise before an attacker reaches the signature or authorisation stage is the challenging component of Lazarus-linked attacks. While KelpDAO and Drift revealed two quite distinct paths into systems that were intended to be trusted, Bybit demonstrated the financial scope of a successful enterprise. As a result, transaction authorisation, verification infrastructure, and privileged access are becoming more crucial areas of scrutiny for cryptocurrency platforms.
If you find any issues in this article or notice missing information, please feel free to reach out at team@etherworld.co for clarifications or updates.
To promote your Web3 articles, events, and projects, you may reach out anytime via EtherWorld PR for submissions and collaboration.
Related Articles
- S&P Global to Acquire OpenZeppelin
- Derive.xyz Bets Big on On-Chain Options Trading
- CoinEx Shuts Down After Nine Years
- Bitcoin ETFs Lose $463M, Ethereum ETFs Gain $197M
- Revolut Shares Customer Data After Fake Government Email
To follow blockchain news, track Ethereum protocol progress, and read our latest stories, subscribe to our weekly today.
Join the EtherWorld & Avarch Internship Program and build your career in blockchain, content, social media, video, podcast editing, or operations. Send your resume and brief introduction to contact@etherworld.co.
Disclaimer: The information contained in this website is for general informational purposes only. The content provided on this website, including articles, blog posts, opinions, & analysis related to blockchain technology & cryptocurrencies, is not intended as financial or investment advice. The website & its content should not be relied upon for making financial decisions. Read full disclaimer & privacy policy.
To stay updated on blockchain news, Ethereum protocol progress, and our latest stories, subscribe to our weekly digest and YouTube channel for ELI5 content.
To promote your Web3 articles, events, project updates, and Press Releases, reach out anytime via EtherWorld PR for submissions and collaboration. For other queries, email contact@etherworld.co.
If you’d like to support our work, share the content and consider donating at avarch.eth.
Join our community on Discord and follow us on Twitter, Facebook, LinkedIn & Instagram.