{"id":17539,"date":"2025-03-28T10:49:37","date_gmt":"2025-03-28T10:49:37","guid":{"rendered":"https:\/\/gold.creditcard\/lazarus-groups-2024-pause-was-repositioning-for-1-4b-bybit-hack\/"},"modified":"2025-03-28T10:49:37","modified_gmt":"2025-03-28T10:49:37","slug":"lazarus-groups-2024-pause-was-repositioning-for-1-4b-bybit-hack","status":"publish","type":"post","link":"https:\/\/gold.creditcard\/es\/lazarus-groups-2024-pause-was-repositioning-for-1-4b-bybit-hack\/","title":{"rendered":"Lazarus Group\u2019s 2024 pause was repositioning for $1.4B Bybit hack"},"content":{"rendered":"<p>North Korea-affiliated hackers may have scaled back their operations in the second half of 2024 while preparing for what became the largest crypto hack in history.<\/p>\n<p>The crypto industry was <a href=\"https:\/\/cointelegraph.com\/news\/crypto-ftx-collapse-regulatory-evolution\" target=\"null\" title=\"null\">rocked by the enormous hack<\/a> on Feb. 21 when Bybit <a href=\"https:\/\/cointelegraph.com\/news\/bybit-exchange-hacked\" target=\"null\" title=\"null\">lost over $1.4 billion<\/a> to the infamous <a href=\"https:\/\/cointelegraph.com\/people\/top-people-in-crypto-and-blockchain-2023\/lazarus-group\/\" target=\"null\" title=\"null\">North Korean Lazarus Group<\/a>, which seems to have prepared the attack months in advance.<\/p>\n<p><a href=\"https:\/\/www.chainalysis.com\/blog\/crypto-hacking-stolen-funds-2025\/\" target=\"_blank\" title=\"https:\/\/www.chainalysis.com\/blog\/crypto-hacking-stolen-funds-2025\/\">According<\/a> to blockchain analytics firm Chainalysis, illicit activity tied to North Korean cyber actors sharply declined after July 1, 2024, despite a surge in attacks earlier that year.<\/p>\n<p>The slowdown in crypto hacks by North Korean agents had raised significant red flags, according to Eric Jardine, Chainalysis cybercrimes research Lead.<\/p>\n<p><em>North Korean hacking activity before and after July 1. Source: <\/em><a href=\"https:\/\/www.chainalysis.com\/blog\/crypto-hacking-stolen-funds-2025\/\" target=\"null\" title=\"https:\/\/www.chainalysis.com\/blog\/crypto-hacking-stolen-funds-2025\/\"><em>Chainalysis<\/em><\/a><\/p>\n<p>North Korea\u2019s slowdown \u201cstarted when Russia and DPRK [North Korea] met for their summit that led to a reallocation of North Korean resources, including military personnel to the war in Ukraine,\u201d Jardine told Cointelegraph during the <a href=\"https:\/\/x.com\/ZVardai\/status\/1904899476013117830\" target=\"null\" title=\"null\">Chainreaction<\/a> show on March 26, adding:<\/p>\n<p>\u201cSo, we speculated in the report that there might have been additional things unseen in terms of resources reallocation from the DPRK, and then you roll forward into early February, and you have the Bybit hack.\u201d<\/p>\n<p><a href=\"https:\/\/t.co\/jOlqMt4Hag\">https:\/\/t.co\/jOlqMt4Hag<\/a><\/p>\n<p>\u2014 Cointelegraph (@Cointelegraph) <a href=\"https:\/\/twitter.com\/Cointelegraph\/status\/1904896170050097465?ref_src=twsrc%5Etfw\">March 26, 2025<\/a><\/p>\n<p>\u201cThe slowdown that we observed could have been a regrouping to select new targets, probe infrastructure, or it could have been linked to those geopolitical events,\u201d he added.<\/p>\n<p><em><strong>Related: <\/strong><\/em><a href=\"https:\/\/cointelegraph.com\/news\/jelly-memecoin-whale-exploit-hyperliquid\" target=\"null\" title=\"null\"><em><strong>Hyperliquid whale still holds 10% of JELLY memecoin after $6.2M exploit<\/strong><\/em><\/a><\/p>\n<p>It took the <a href=\"https:\/\/cointelegraph.com\/news\/bybit-hacker-launders-1-billion-stolen-funds\" target=\"null\" title=\"null\">Lazarus Group 10 days to launder<\/a> 100% of the stolen Bybit funds through the decentralized crosschain protocol THORChain, Cointelegraph reported on March 4.<\/p>\n<p>Still, blockchain security experts were hopeful that a portion of the funds could be frozen and recovered by Bybit. As of March 20, over <a href=\"https:\/\/cointelegraph.com\/news\/bybit-1-4b-hack-88-percent-traceable-lazarus-group\" target=\"null\" title=\"null\">80% of the stolen $1.4 billion<\/a> was still traceable as blockchain investigators continue their efforts to freeze and recover the funds.<\/p>\n<p><em><strong>Related: <\/strong><\/em><a href=\"https:\/\/cointelegraph.com\/news\/polymarket-trump-ukraine-bet-whale-governance-attack\" target=\"null\" title=\"null\"><em><strong>Polymarket faces scrutiny over $7M Ukraine mineral deal bet<\/strong><\/em><\/a><\/p>\n<h2>How hackers staged the world\u2019s biggest crypto hack<\/h2>\n<p>The Bybit attack highlights that even centralized exchanges with strong security measures remain <a href=\"https:\/\/cointelegraph.com\/news\/bybit-exchange-hacked\" target=\"null\" title=\"null\">vulnerable to sophisticated cyberattacks<\/a>, analysts said.<\/p>\n<p>The attack shares similarities with <a href=\"https:\/\/cointelegraph.com\/news\/indian-crypto-exchange-wazirx-hack-235m\" target=\"null\" title=\"null\">the $230 million WazirX<\/a> hack and the <a href=\"https:\/\/cointelegraph.com\/news\/radiant-capital-resumes-lending-post-hack\" target=\"null\" title=\"null\">$58 million Radiant Capital hack<\/a>, according to Meir Dolev, co-founder and chief technical officer at Cyvers.<\/p>\n<p>Dolev said the Ethereum multisig cold wallet was compromised through a deceptive transaction, tricking signers into unknowingly approving a malicious smart contract logic change.<\/p>\n<p>\u201cThis allowed the hacker to gain control of the cold wallet and transfer all ETH to an unknown address,\u201d Dolev told Cointelegraph.<\/p>\n<p><em>North Korea hacking activity. Source: Chainalysis<\/em><\/p>\n<p>Throughout 2024, North Korean hackers stole over $1.34 billion worth of digital assets across 47 incidents, a 102% increase from the $660 million stolen in 2023, <a href=\"https:\/\/www.chainalysis.com\/blog\/crypto-hacking-stolen-funds-2025\/\" target=\"null\" title=\"null\">according<\/a> to Chainalysis data.<\/p>\n<p>This accounted for 61% of the total crypto stolen in 2024.<\/p>\n<p><em><strong>Magazine: <\/strong><\/em><a href=\"https:\/\/cointelegraph.com\/magazine\/beyond-peak-memecoin-solana-100x-better-despite-revenue-plunge\/\" target=\"null\" title=\"null\"><em><strong>Memecoins are ded \u2014 But Solana \u2018100x better\u2019 despite revenue plunge<\/strong><\/em><\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>North Korea-affiliated hackers may have scaled back their operations in the second half of 2024 while preparing for what became the largest crypto hack in history. The crypto industry was rocked by the enormous hack on Feb. 21 when Bybit lost over $1.4 billion to the infamous North Korean Lazarus Group, which seems to have [&hellip;]<\/p>","protected":false},"author":0,"featured_media":17540,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_eb_attr":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[9],"tags":[],"class_list":["post-17539","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-finance"],"_links":{"self":[{"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/posts\/17539","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/comments?post=17539"}],"version-history":[{"count":0,"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/posts\/17539\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/media\/17540"}],"wp:attachment":[{"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/media?parent=17539"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/categories?post=17539"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/tags?post=17539"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}