On March 23, 2022, the Ronin Network - the blockchain bridge connecting the Axie Infinity play-to-earn game to Ethereum - was drained of $625 million in cryptocurrency. It was the largest cryptocurrency theft in history at the time. The attackers were Lazarus Group, North Korea's state-sponsored hacking organization. The theft took six days to be noticed: the Ronin team only discovered the drain when a user tried to withdraw funds and couldn't. For six days, $625 million was simply gone, and nobody had noticed.
The Ronin hack was not an anomaly in Lazarus Group's cryptocurrency operations - it was the pinnacle of a systematic multi-year campaign to steal cryptocurrency for the North Korean regime. Between 2017 and 2024, Lazarus Group stole an estimated $3-5 billion in cryptocurrency across dozens of operations targeting exchanges, DeFi protocols, and individual holders. For a country with a GDP of approximately $18 billion and an economy crippled by international sanctions, cryptocurrency theft represented a major revenue stream - funding weapons programs, luxury imports, and regime operations.
The Ronin Bridge Hack
The Ronin Network was a sidechain built by Sky Mavis, the Vietnamese company behind Axie Infinity. It used a proof-of-authority consensus mechanism with nine validator nodes - four operated by Sky Mavis and five by Axie Infinity's DAO. For a transaction to be approved, five of nine validators needed to sign it. This was intended as a security mechanism.
Lazarus Group compromised five of the nine validator private keys. Four were obtained by compromising Sky Mavis's internal systems through a spear-phishing attack that targeted Sky Mavis employees - specifically a senior engineer who received a fraudulent job offer, went through a fake interview process, and was sent a PDF containing malware as part of a "job offer." The malware provided access to Sky Mavis's internal network, from which the validator keys were extracted. The fifth key was obtained through a separate vulnerability: Sky Mavis had temporarily whitelisted the Axie DAO's validator to reduce transaction load, and this configuration had not been revoked, allowing Sky Mavis's compromised systems to effectively sign for both Sky Mavis's four validators and the DAO's validator.
With five validator signatures, Lazarus created two fraudulent withdrawal transactions: 173,600 ETH and 25.5 million USDC, totaling approximately $625 million at the time of theft. The transactions appeared valid to the Ronin bridge smart contract because they had the required five validator signatures. The funds moved out of the bridge contract to attacker-controlled wallets.
Lazarus Group's Cryptocurrency Theft Methodology
Lazarus Group's cryptocurrency operations follow consistent patterns across different targets. Initial access typically involves spear-phishing - targeting employees of cryptocurrency companies with fake job offers, fake investment opportunities, or fraudulent DeFi protocol interactions. The phishing is tailored to the cryptocurrency context: fake recruiters on LinkedIn, fake DEX trading opportunities, fake VC term sheets.
Once inside a cryptocurrency company's infrastructure, Lazarus engages in extended reconnaissance before executing the theft. They map the company's internal systems, identify where private keys and signing infrastructure are located, and understand the withdrawal and transaction approval processes. This reconnaissance can take weeks or months. When ready, they execute the theft in a single coordinated action designed to be as large as possible while remaining fast enough to complete before detection.
Post-theft, Lazarus employs sophisticated cryptocurrency laundering techniques. They use crypto mixing services, chain-hopping (converting between cryptocurrencies to break transaction trails), and exchanges in jurisdictions with limited AML enforcement to convert stolen crypto to fiat. The US government has sanctioned multiple cryptocurrency mixing services (Tornado Cash, Sinbad) specifically to disrupt Lazarus Group laundering.
Other Major Lazarus Cryptocurrency Operations
The Ronin hack was the largest single theft but not the only major Lazarus cryptocurrency operation. Highlights include: Harmony Horizon Bridge ($100M, June 2022) - similar bridge attack using compromised validator keys. The Harmony bridge had a 2/5 signing threshold; Lazarus compromised two keys. Atomic Wallet ($35M, June 2023) - compromised the Atomic Wallet software to inject malicious code affecting individual wallet users. Alphapo payment processor ($60M, July 2023). Stake.com gambling platform ($41M, September 2023). Coincheck ($530M, January 2018, attributed to Lazarus by some researchers though attribution is disputed). The cumulative total from tracked Lazarus cryptocurrency operations through 2024 exceeds $3 billion by most estimates.
The Bybit exchange hack of February 2025, in which Lazarus Group stole approximately $1.5 billion by compromising the exchange's Safe multisig wallet signing infrastructure (through a supply chain attack on the front-end interface, manipulating the signing transaction presented to the exchange's multi-sig signers), represented a new technical approach: rather than compromising private keys directly, the attackers compromised the user interface used to approve transactions, causing the exchange's own authorized signers to unknowingly approve fraudulent withdrawals.