BTC $- · ETH $- · SOL $- · BNB $- · XRP $- · DOGE $- · TON $- · ADA $- · AVAX $- · LINK $- · SUI $- · TRX $- · gas - gwei degen 74/100

~/defi/hacks $ cat lazarus-severokoreyskiy-kripto-konveyer.md

defi Hacks und Exploits ·28. Juni 2026

Lazarus: How a Government Operation Became the Biggest Crypto Thief

das crptch-Team · Analytikabteilung · 2 Lesezeit

Lazarus and related North Korean groups are not “hackers” in the romantic sense, but rather a state-run operation for generating foreign currency. They are responsible for some of the industry’s largest heists, including those targeting Ronin and Bybit.

Methods

  • Months-long social engineering: fake recruiters with “test assignments” for developers, bogus investors, and LinkedIn profiles with fabricated backstories. The goal: an employee’s computer with administrative access.
  • Fake IT specialists: Remote developers using someone else’s documents get hired by crypto companies-gaining access from the inside.
  • Attacks on the signing chain: a modern specialization-compromising multisig signing interfaces: signers see one thing, but sign another (the Bybit case).
  • Money-laundering pipeline: Stolen funds are split up, routed through mixers and cross-chain swaps along well-trodden paths. Analysts track these trails-funds are sometimes recovered, but rarely.

What This Means for the Market

A state-sponsored adversary with unlimited time is changing the threat landscape: both audits and “cold” wallets with flawed signing processes are vulnerable to it. The industry responds with verification of signers on independent devices and an obsessive focus on personnel processes. Users should remember: their exchange is the number one target in the world, and the platform’s security buffer is not just an abstraction.

[tg @crptchs] ✓ Erfolgsbilanz