Currencies32904
Market Cap$ 2.58T-8.15%
24h Spot Volume$ 63.03B+21.1%
DominanceBTC59.46%+1.12%ETH7.23%-6.75%
ETH Gas2.03 Gwei
Cryptorank
 icon
 icon
 icon
 icon
MainNewsFBI confirms...

FBI confirms North Korea-backed Lazarus hackers stole $1.5 billion from Bybit


Feb, 27, 2025
2 min read
by Oluwapelumi Adejumo
for CryptoSlate
FBI confirms North Korea-backed Lazarus hackers stole $1.5 billion from Bybit

The Federal Bureau of Investigation (FBI) has confirmed North Korea as the culprit behind the recent $1.5 billion exploit on Bybit.

In a Feb. 26 Public Service Announcement (PSA), the agency attributed the attack to TraderTraitor, a malicious cyber campaign linked to North Korean threat actors.

TraderTraitor refers to a series of malware-infested applications disguised as crypto trading and price prediction tools.

These applications, built using cross-platform JavaScript and the Electron framework, originate from various open-source projects. Cybercriminals behind the campaign use well-designed websites to lure victims, showcasing fake features to build credibility.

Fund laundering

The FBI reported that the stolen funds are already being laundered, with attackers converting portions of the assets into Bitcoin and dispersing them across multiple blockchain networks.

The agency expects the funds to eventually be exchanged for fiat currency through illicit channels.

To counter this, the FBI released a list of flagged blockchain addresses linked to the hackers. It urged virtual asset service providers—including exchanges, DeFi platforms, and blockchain analytics firms—to block transactions associated with these addresses to prevent further money laundering.

This confirms prior reports from blockchain analysis firm SpotOnChain, which revealed that the hackers laundered 100,000 ETH, valued at approximately $250 million, in under four days.

SpotOnChain noted that the laundered funds represent 20% of the stolen 499,000 ETH. According to the firm, the cybercriminals have been splitting the assets across multiple addresses and using THORChain for cross-chain swaps into Bitcoin, DAI, and other cryptocurrencies.

North Korea’s expanding cyber threat

This attack illustrates North Korea’s growing success in using cybercrime to finance state operations. The Lazarus Group, a notorious government-backed hacking unit, has been behind several major digital asset heists.

The FBI noted that Lazarus Group is responsible for several previous attacks on crypto platforms. The group attacked Horizon Bridge in June 2022, attacked Ronin Bridge in March 2022, and has carried out other attacks as well.

Reports indicate that North Korean hackers stole more than $1.3 billion in digital assets in 2024, far surpassing the $660 million taken in 2023.

Analysts believe these stolen funds support the country’s nuclear weapons program, allowing it to bypass international sanctions.

Both Bybit and Safe have further confirmed to CryptoSlate that the North Korean hacking group Lazarus Group was responsible for the attack. A developer machine was compromised, allowing the hackers to trick owners of a multisig cold wallet into signing a malicious transaction. Safe stated,

“The Safe{Wallet} team has fully rebuilt, reconfigured all infrastructure, and rotated all credentials, ensuring the attack vector is fully eliminated.”

ByBit also confirmed that the majority of its assets held with Safe have been withdrawn from vaults to protect against any further vulnerability.

The post FBI confirms North Korea-backed Lazarus hackers stole $1.5 billion from Bybit appeared first on CryptoSlate.

Read the article at CryptoSlate

Read More

Stablecoin bill advances in Senate: Could it strengthen US dollar dominance?

Stablecoin bill advances in Senate: Could it strengthen US dollar dominance?

The following is a guest post and opinion of Innokenty Isers, Chief Executive Officer...
Apr, 07, 2025
4 min read
by CryptoSlate
Hackers Hammer Android and iPhone Users As Bank Account Attacks Surge 258% in One Year: Kaspersky

Hackers Hammer Android and iPhone Users As Bank Account Attacks Surge 258% in One Year: Kaspersky

The number of Android and iPhone users hit by bank malware is skyrocketing as crimina...
Apr, 06, 2025
2 min read
by The Daily Hodl
MainNewsFBI confirms...

FBI confirms North Korea-backed Lazarus hackers stole $1.5 billion from Bybit


Feb, 27, 2025
2 min read
by Oluwapelumi Adejumo
for CryptoSlate
FBI confirms North Korea-backed Lazarus hackers stole $1.5 billion from Bybit

The Federal Bureau of Investigation (FBI) has confirmed North Korea as the culprit behind the recent $1.5 billion exploit on Bybit.

In a Feb. 26 Public Service Announcement (PSA), the agency attributed the attack to TraderTraitor, a malicious cyber campaign linked to North Korean threat actors.

TraderTraitor refers to a series of malware-infested applications disguised as crypto trading and price prediction tools.

These applications, built using cross-platform JavaScript and the Electron framework, originate from various open-source projects. Cybercriminals behind the campaign use well-designed websites to lure victims, showcasing fake features to build credibility.

Fund laundering

The FBI reported that the stolen funds are already being laundered, with attackers converting portions of the assets into Bitcoin and dispersing them across multiple blockchain networks.

The agency expects the funds to eventually be exchanged for fiat currency through illicit channels.

To counter this, the FBI released a list of flagged blockchain addresses linked to the hackers. It urged virtual asset service providers—including exchanges, DeFi platforms, and blockchain analytics firms—to block transactions associated with these addresses to prevent further money laundering.

This confirms prior reports from blockchain analysis firm SpotOnChain, which revealed that the hackers laundered 100,000 ETH, valued at approximately $250 million, in under four days.

SpotOnChain noted that the laundered funds represent 20% of the stolen 499,000 ETH. According to the firm, the cybercriminals have been splitting the assets across multiple addresses and using THORChain for cross-chain swaps into Bitcoin, DAI, and other cryptocurrencies.

North Korea’s expanding cyber threat

This attack illustrates North Korea’s growing success in using cybercrime to finance state operations. The Lazarus Group, a notorious government-backed hacking unit, has been behind several major digital asset heists.

The FBI noted that Lazarus Group is responsible for several previous attacks on crypto platforms. The group attacked Horizon Bridge in June 2022, attacked Ronin Bridge in March 2022, and has carried out other attacks as well.

Reports indicate that North Korean hackers stole more than $1.3 billion in digital assets in 2024, far surpassing the $660 million taken in 2023.

Analysts believe these stolen funds support the country’s nuclear weapons program, allowing it to bypass international sanctions.

Both Bybit and Safe have further confirmed to CryptoSlate that the North Korean hacking group Lazarus Group was responsible for the attack. A developer machine was compromised, allowing the hackers to trick owners of a multisig cold wallet into signing a malicious transaction. Safe stated,

“The Safe{Wallet} team has fully rebuilt, reconfigured all infrastructure, and rotated all credentials, ensuring the attack vector is fully eliminated.”

ByBit also confirmed that the majority of its assets held with Safe have been withdrawn from vaults to protect against any further vulnerability.

The post FBI confirms North Korea-backed Lazarus hackers stole $1.5 billion from Bybit appeared first on CryptoSlate.

Read the article at CryptoSlate

Read More

Stablecoin bill advances in Senate: Could it strengthen US dollar dominance?

Stablecoin bill advances in Senate: Could it strengthen US dollar dominance?

The following is a guest post and opinion of Innokenty Isers, Chief Executive Officer...
Apr, 07, 2025
4 min read
by CryptoSlate
Hackers Hammer Android and iPhone Users As Bank Account Attacks Surge 258% in One Year: Kaspersky

Hackers Hammer Android and iPhone Users As Bank Account Attacks Surge 258% in One Year: Kaspersky

The number of Android and iPhone users hit by bank malware is skyrocketing as crimina...
Apr, 06, 2025
2 min read
by The Daily Hodl

Privacy & Cookies Statement

Please read and accept our Privacy Policy & Cookies Statement to continue using our Site. This policy governs your provision of your personal data necessary to access our Site and/or particular services.

I have read, understood, and hereby accept the Privacy Policy & Cookies Statement and accept only essential cookies.