In February 2025, hackers stole $1.5 billion from Bybit, one of the world's largest cryptocurrency exchanges. This was the largest theft in the history of cryptocurrency - larger than any bank robbery in history, adjusted for any measure. The US and several allied governments attributed it within weeks to the Lazarus Group, a North Korean state-sponsored hacking organization. North Korea denied it, as North Korea always denies it, while the stolen funds were being laundered through mixing services and bridge protocols at a pace that suggested institutional-scale money movement.
Lazarus Group is not a single team of hackers. It is the attribution label attached to a constellation of North Korean cyber operations units that operate under the direction of the Reconnaissance General Bureau - North Korea's intelligence organization responsible for foreign operations. What distinguishes Lazarus from most state-sponsored groups is the explicit financial mandate. They don't just collect intelligence. They steal money. For a country under severe international sanctions, with limited export revenue and a regime that requires hard currency to fund weapons programs and elite patronage, cyber theft has become a primary revenue source.
The Financial Mission
North Korea's cyber program began in the 1990s as an intelligence and information warfare capability. The financial mission emerged gradually as sanctions tightened and the regime looked for ways to generate hard currency that bypassed the international financial system. The pivot became apparent around 2016, when a group attributed to Lazarus attempted to steal $1 billion from the central bank of Bangladesh through the SWIFT interbank messaging system. They successfully transferred $81 million before a misspelling in a transfer instruction triggered a review that stopped the rest.
The Bangladesh bank heist established the template: target financial institutions' own transfer infrastructure, move fast, and convert to forms of value that are difficult to freeze. Cryptocurrency, with its pseudonymous nature, 24/7 operation, and lack of centralized control, proved ideal. Lazarus Group pivoted heavily toward cryptocurrency exchanges beginning around 2017 and has been the dominant threat actor in the crypto space ever since.
The Bybit Hack (February 2025)
The Bybit hack was notable not for the exchange itself being compromised, but for the attack vector: a supply chain attack against the third-party multisignature wallet infrastructure that Bybit used to authorize large transfers. Bybit used Safe (formerly Gnosis Safe), an open-source multisig wallet platform, to manage cold storage. The attack compromised the Safe infrastructure to deliver a malicious version of the Safe user interface to Bybit's signers.
When Bybit's authorized signers reviewed and approved what appeared to be a routine transfer to a warm wallet, they were looking at a UI that displayed correct-looking transaction details while the actual transaction data they were signing had been modified to transfer control of the wallet to an attacker-controlled address. The multisig process worked correctly - multiple parties reviewed and approved the transaction. But they reviewed a fraudulent display while signing a fraudulent transaction.
The attack was a social engineering and supply chain operation, not a brute-force cryptographic compromise. The underlying cryptography was not broken. The human processes around it were attacked. This pattern - targeting the interfaces and processes humans use to interact with secure systems rather than the cryptographic core - is increasingly characteristic of sophisticated crypto theft operations.
Known Attacks and Scale
Lazarus Group's documented attacks span financial institutions, cryptocurrency exchanges, DeFi protocols, and critical infrastructure. The major incidents include the Sony Pictures hack in 2014 (following the planned release of "The Interview," a film depicting the assassination of Kim Jong-un), the Bangladesh Bank SWIFT theft in 2016, and WannaCry ransomware in 2017 - an unusually aggressive global ransomware deployment that caused billions in damage but generated relatively modest ransom revenue, suggesting it may have been partially motivated by disruption rather than purely financial goals.
The cryptocurrency theft campaign runs from 2017 to the present and includes the Coincheck theft ($530M, 2018), the Harmony Horizon bridge ($100M, 2022), the Atomic Wallet exploit ($35M, 2023), the Radiant Capital bridge compromise ($50M, 2024), and the Bybit hack ($1.5B, 2025), among dozens of smaller incidents. The scale has increased as the group has developed more sophisticated capabilities and as cryptocurrency markets have grown the pool of accessible value.
The Laundering Infrastructure
Stealing cryptocurrency is one challenge. Converting it to usable currency while avoiding seizure and attribution is another. The North Korean operations have developed sophisticated laundering pipelines that use multiple techniques in sequence.
After a major theft, funds are typically moved rapidly through several hops to obscure the trail. Cross-chain bridges transfer value between blockchains, complicating analysis. Mixing services blend stolen funds with other transactions, breaking the direct link between theft address and eventual destination. Peel chains - long sequences of small transactions - further obscure the trail. Over time, small amounts are withdrawn through exchanges in jurisdictions with limited KYC enforcement, converted to fiat currency.
Despite these techniques, blockchain analytics firms like Chainalysis, Elliptic, and TRM Labs have had considerable success tracking North Korean funds. Blockchains are permanent and public ledgers - every transaction is recorded forever. The analytics firms have developed attribution heuristics that can follow funds even through multiple layers of obfuscation. After the Bybit hack, blockchain analysts tracked the movement of stolen ETH in near-real-time, identifying mixer services and bridge transfers as they happened.
Operational Security
Lazarus Group operations exhibit a level of patience and operational security that reflects institutional rather than individual discipline. Pre-attack reconnaissance can take months. The Bybit attack involved compromising Safe's infrastructure before Bybit became the target - the attackers built the capability first, then selected the target where it would be most valuable. This is the kind of long-lead-time investment that individual criminal groups rarely make.
Personnel operational security is also notable. North Korean cyber operators typically work from outside North Korea - historical reporting places them in China, Southeast Asia, and other locations where their access to internet infrastructure is better. Front companies in third countries provide cover. Some North Korean IT workers have been documented working remotely for Western technology companies, earning salaries that flow back to the regime while providing access to systems and development environments.
Attribution is robust but indirect. No North Korean operator has ever been arrested by Western authorities. Indictments have been issued - the US Department of Justice has indicted multiple individuals linked to North Korean cyber operations - but the individuals remain beyond the reach of US law enforcement as long as they stay in countries that don't extradite to the US.
The Crypto-Sanctions Loop
The irony of North Korea's cryptocurrency theft program is that it exists in a feedback loop with the sanctions intended to pressure the regime. Sanctions restrict North Korea's access to hard currency and the international financial system. The regime responds by investing in cyber capabilities to generate hard currency outside the formal financial system. Some of those capabilities are deployed against the same Western financial institutions and technology companies that enforce the sanctions.
The US Treasury's Office of Foreign Assets Control has sanctioned North Korean-linked cryptocurrency addresses and mixer services repeatedly. Tornado Cash, a privacy mixer used extensively by Lazarus Group, was sanctioned in August 2022 - an unprecedented step that raised significant legal questions about sanctioning open-source software. The sanctioning of Tornado Cash addresses slowed but did not stop their use; the code continues to operate on the Ethereum blockchain regardless of whether US persons are permitted to interact with it.
What the Bybit Hack Changed
The Bybit hack at $1.5 billion is a qualitative shift, not just a quantitative one. Previous large Lazarus thefts had targeted DeFi protocols with known smart contract vulnerabilities or bridge infrastructure with less sophisticated security practices. Bybit was a centralized exchange with dedicated security teams, institutional-grade multisig infrastructure, and awareness of the North Korean threat.
The supply chain attack on Safe's infrastructure demonstrated that targeting the humans and tooling in the signing process can bypass cryptographic security entirely. This has implications beyond cryptocurrency. The same attack pattern - compromise a trusted tool used to authorize sensitive operations, serve a modified version that displays misleading information while recording a different action - is applicable anywhere that humans must review and authorize complex technical operations.
The response has accelerated interest in hardware signing devices that display transaction details on a trusted screen independent of the host computer, making UI manipulation attacks harder. It has also prompted review of the supply chain security of tools used in sensitive operations across industries beyond cryptocurrency.
The $1.5 billion remains substantially unrecovered. Some small portions have been frozen through coordinated action between blockchain analytics firms, exchanges, and law enforcement. The bulk has moved through the laundering pipeline toward eventual conversion. This is North Korea's program working as designed.