North Korea-linked Lazarus Group reactivated dormant wallets on Aug. 28, moving 244.148 Bitcoin worth $19.42 million.
North Korea-linked Lazarus Group reactivated dormant wallets on Aug. 28, moving 244.148 Bitcoin worth $19.42 million.

North Korea-linked Lazarus Group moved 244.148 Bitcoin worth $19.42 million on Aug. 28, reactivating labeled wallets tied to the sanctioned hacking operation.
Lookonchain reported the transfer in an Aug. 28 X post, saying the wallets became active about an hour before its alert. The analytics account did not identify the receiving address or say whether the funds reached an exchange, mixer, or another wallet.
Bitcoin traded at roughly $79,500 when the estimate was published. The transaction followed another large movement on Aug. 12, when Lazarus transferred 262.2 BTC valued at approximately $16.64 million to a newly created address. Combined, the two August movements involved more than $36 million in Bitcoin.
The destination matters because past movements have preceded cash-out attempts. In March 2025, five unknown addresses received 44.07 BTC worth about $3.76 million from Lazarus-attributed wallets. The FBI has warned that North Korean actors typically convert stolen assets and spread them across thousands of addresses before attempting to exchange them for fiat currency.
Bybit lawsuit targets $1.5B theft recovery
Bybit filed a lawsuit against North Korea and Lazarus Group in a Washington, D.C., federal court on Aug. 7, seeking to recover assets tied to the exchange's $1.5 billion theft. The suit also named North Korea's Reconnaissance General Bureau, which the U.S. Treasury identifies as the country's main intelligence agency. A federal judge issued a preliminary injunction blocking unidentified defendants from transferring, selling, or disposing of certain assets connected to the case.
The FBI attributed the February 2025 Bybit attack to North Korean actors operating under the TraderTraitor name. According to the agency, the attackers converted part of the stolen holdings into Bitcoin and other assets before spreading them across thousands of addresses on several blockchains. By April 2025, Bybit CEO Ben Zhou said 27.6% of the stolen funds could no longer be tracked.
North Korean thefts reached $2.02B in 2025
Chainalysis estimated that North Korean hackers stole at least $2.02 billion in cryptocurrency during 2025, an increase of 51% from the previous year. The firm placed the country's cumulative crypto theft at no less than $6.75 billion by the end of that period. North Korean operations accounted for 76% of the value lost through attacks on crypto services during the year.
Activity attributed to Lazarus continued in April 2026 when attackers drained approximately 116,500 rsETH, worth about $292 million, from KelpDAO's LayerZero-based bridge. By June, the attacker had moved approximately $220 million in unfrozen assets through privacy services including THORChain, Wasabi, Tornado Cash, and Umbra.
The U.S. Treasury's Office of Foreign Assets Control sanctioned Lazarus Group in September 2019 under an executive order targeting the North Korean government. Treasury regulations generally prohibit Americans from conducting transactions with sanctioned entities unless the agency authorizes them. In 2022, the Treasury also sanctioned the mixer Blender.io after saying it had handled more than $20.5 million from the roughly $620 million Ronin Network theft.
The latest transfer has not been connected directly to the Bybit theft, and no government agency has publicly identified the source of the coins involved. But the reactivation of labeled wallets keeps the group's laundering infrastructure under scrutiny as exchanges and blockchain intelligence firms tighten their monitoring.
This article is for informational purposes only and does not constitute investment advice.