Lazarus – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sun, 22 Jun 2025 05:26:16 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Lazarus – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 BitoPro exchange links Lazarus hackers to $11 million crypto heist https://earlybirdsinvest.com/bitopro-exchange-links-lazarus-hackers-to-11-million-crypto-heist/ https://earlybirdsinvest.com/bitopro-exchange-links-lazarus-hackers-to-11-million-crypto-heist/#respond Sun, 22 Jun 2025 05:26:15 +0000 https://earlybirdsinvest.com/bitopro-exchange-links-lazarus-hackers-to-11-million-crypto-heist/

Hackers counting crypto

The Taiwanese cryptocurrency exchange BitoPro claims the North Korean hacking group Lazarus is behind a cyberattack that led to the theft of $11,000,000 worth of cryptocurrency on May 8, 2025.

The company has attributed the attack to Lazarus based on the evidence recovered from its internal investigations. It notes that the attack patterns and methodology closely resemble those used in past cyberattacks.

“The attack methodology bears resemblance to patterns observed in multiple past international major incidents, including illicit transfers from global bank SWIFT systems and asset theft incidents from major international cryptocurrency exchanges,” reads the announcement.

“These attacks are attributed to the North Korean hacking organization Lazarus Group.”

Tweet

BitoPro is a cryptocurrency exchange that caters primarily to Taiwanese users, supporting fiat deposits and withdrawals in TWD and a selection of crypto assets.

It has over 800,000 registered users and a daily trading volume of roughly $30 million.

On May 8, 2025, during a hot wallet system update, hackers performed unauthorized withdrawals from an old hot wallet across multiple blockchains, including Ethereum, Tron, Solana, and Polygon.

After the theft, stolen funds were laundered through DEXs and mixers like Tornado Cash, ThorChain, and Wasabi Wallet.

BitoPro was slow in admitting the incident, only confirming it publicly on June 2, noting that all operations were unaffected and impacted hot wallets were replenished by available reserves.

The investigation into the hack now confirmed that there was no internal involvement, even though the attackers launched a social engineering attack and implanted malware on the device of an employee managing cloud operations.

Through this infection, the attackers hijacked AWS session tokens to bypass multi-factor authentication (MFA) and gain control over BitPro’s cloud infrastructure.

Next, the command-and-control (C2) server delivered commands to the implant that injected scripts into the hot wallet host as the attack was being prepared.

When the wallet was upgraded and assets transferred, the attackers stole crypto while simulating normal operational behavior to evade immediate detection.

Once BitoPro detected the compromise, they shut down the hot wallet system and rotated the cryptographic keys. However, roughly $11 million worth of cryptocurrency had already been stolen.

The company informed the applicable authorities and engaged with an external cybersecurity expert to investigate the incident, a process completed on June 11.

The North Korean Lazarus group is notorious for targeting cryptocurrency and decentralized finance entities. The hacking group is believed to be responsible for record-breaking digital asset heists, most recently, the $1.5 billion theft from Bybit.

Tines Needle

Patching used to mean complex scripts, long hours, and endless fire drills. Not anymore.

In this new guide, Tines breaks down how modern IT orgs are leveling up with automation. Patch faster, reduce overhead, and focus on strategic work — no complex scripts required.

]]>
https://earlybirdsinvest.com/bitopro-exchange-links-lazarus-hackers-to-11-million-crypto-heist/feed/ 0 43411
Lazarus hacker forgets VPN, gets exposed https://earlybirdsinvest.com/lazarus-hacker-forgets-vpn-gets-exposed/ https://earlybirdsinvest.com/lazarus-hacker-forgets-vpn-gets-exposed/#respond Mon, 02 Jun 2025 19:51:52 +0000 https://earlybirdsinvest.com/lazarus-hacker-forgets-vpn-gets-exposed/

If you know anything about a crypto hack, you’ve probably heard of the Lazarus Group.

They’re pretty much the final boss of crypto cybercrime – a North Korean state-backed hacking group responsible for some of the biggest thefts in the industry, including the Bybit hack earlier this year.

They’ve always carried this boogeyman of blockchain, mysterious vibe. But a new BitMEX report pulled back the curtain a bit.

And turns out… they’re not as flawless as some might think.

Tea

Over time, Lazarus seems to have split into smaller teams, and not all of them are equally skilled. Some are pros. Others – not so much.

Case in point: a BitMEX employee got a message on LinkedIn about joining a crypto project.

If you’ve followed Lazarus’ past scams, you know this is something they’ve done before – so the employee flagged it to the security team.

They were sent a GitHub repo with a Next.js/React project that – surprise – contained malware.

The attacker wanted them to run the code locally, which would’ve let malicious scripts execute on the employee’s computer.

Now, here’s what BitMEX found in the code:

  • It used JavaScript’s eval() function, which takes a piece of text and treats it like code. So if it says “delete everything,” your computer will actually try to run that command – and that opens the door for attackers to sneak in harmful code;

  • The malware tried to connect to suspicious URLs to download even more code – the kind of infrastructure Lazarus has used before in past attacks;

  • It collected data like usernames, IP addresses, operating systems, and uploaded all of it to… wait for it… a public Supabase database 😀👍

Yes. Public.

This is like using Google Sheets to store stolen data… and then leaving the spreadsheet unlocked.

Think smart

The BitMEX team took a look and found nearly 900 logs from infected machines.

And in one of them, they caught a big oopsie: a hacker forgot to turn on their VPN and exposed their real location in Jiaxing, China.

Instead of treating this oopsie as a one-off discovery, BitMEX saw an opportunity here – they built a tool to keep checking the database.

This lets BitMEX:

  • Track new infections as they happen;

  • Figure out who’s being targeted – devs, exchange workers, or random users;

  • Watch for repeat mistakes by the hackers (like more IP leaks);

  • Potentially map out patterns – like locations, time zones, or organizational targets.

Lazarus is still dangerous – no doubt about it.

But the more we learn about their tricks (and their mistakes), the easier it becomes to protect people from falling for them.

]]>
https://earlybirdsinvest.com/lazarus-hacker-forgets-vpn-gets-exposed/feed/ 0 39759
Fake NFT Job Offer? BitMEX Stops Lazarus Group Hack in Its Tracks https://earlybirdsinvest.com/fake-nft-job-offer-bitmex-stops-lazarus-group-hack-in-its-tracks/ https://earlybirdsinvest.com/fake-nft-job-offer-bitmex-stops-lazarus-group-hack-in-its-tracks/#respond Mon, 02 Jun 2025 15:28:51 +0000 https://earlybirdsinvest.com/fake-nft-job-offer-bitmex-stops-lazarus-group-hack-in-its-tracks/

BitMEX



$30.38K

has blocked a phishing attempt linked to the Lazarus Group
, a hacking operation with ties to North Korea.

The exchange said in a May 30 blog post that the attackers used a fake job opportunity on LinkedIn to try and trick one of its employees.

The offer involved a supposed collaboration on a Web3 non-fungible token (NFT) project.

What is Monero? XMR Animated Explainer

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

The attackers then encouraged the employee to download and run a GitHub file. That file included hidden code meant to harm the computer. BitMEX’s security team caught the attempt and traced the source of the file to servers previously connected to the Lazarus Group activity.

During their investigation, the team also found that one of the IP addresses linked to the attack was based in Jiaxing, China. This discovery pointed to a possible mistake by the group, which helped confirm the link to North Korean operations.

BitMEX explained that the Lazarus Group often starts its attacks with simple methods like phishing, using emails or messages to trick people into opening harmful files. These are usually carried out by teams with basic skills.

More complex actions, such as moving through company networks or stealing large amounts of data, are likely handled by other teams with more experience.

BitMEX also pointed out that the term “Lazarus Group” covers several hacking teams believed to be under the control of the North Korean government. These teams have been blamed for stealing large sums of money through different kinds of cyberattacks.

On May 1, Kraken uncovered an attempt by a North Korean hacker to slip inside the company. How? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/fake-nft-job-offer-bitmex-stops-lazarus-group-hack-in-its-tracks/feed/ 0 39717
Huione Group Faces US Ban for Alleged Ties to North Korea's Lazarus Group https://earlybirdsinvest.com/huione-group-faces-us-ban-for-alleged-ties-to-north-koreas-lazarus-group/ https://earlybirdsinvest.com/huione-group-faces-us-ban-for-alleged-ties-to-north-koreas-lazarus-group/#respond Sun, 04 May 2025 07:36:25 +0000 https://earlybirdsinvest.com/huione-group-faces-us-ban-for-alleged-ties-to-north-koreas-lazarus-group/

The US Treasury Department has announced plans to stop Cambodia’s Huione Group from accessing the US banking system.

Officials believe the company has played a role in helping North Korea’s Lazarus Group hide stolen cryptocurrency.

On May 1, the Treasury’s Financial Crimes Enforcement Network (FinCEN) proposed a new rule. It would prevent US banks from opening or keeping accounts connected to Huione Group. The plan also includes stopping foreign banks from moving money through US accounts on Huione’s behalf.

What is a Crypto Mining Rig? Is it Worth it? (EASILY Explained)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Treasury Secretary Scott Bessent said the group has become a “marketplace of choice” for hackers like Lazarus, who have taken billions of dollars from US citizens. He added that cutting off Huione’s access to banking would make it harder for criminals to hide illegal funds.

Though Huione Group does not have direct accounts with American banks, it works with foreign banks that do. This indirect link still allows it to move funds connected to illegal activities.

According to FinCEN, between August 2021 and January 2025, Huione helped move at least $4 billion in illegal funds. Over $36 million of this came from so-called “pig butchering” scams, where victims are tricked into fake online investments. Another $37 million was linked to hacking groups connected to North Korea.

The Treasury said that Haowang Guarantee has turned Huione Group into a central place for criminals to exchange stolen cryptocurrency for cash.

The proposed rule will be open for public comment for 30 days before it can be put into effect.

Recently, the Australian Transaction Reports and Analysis Centre (AUSTRAC) issued a warning to inactive cryptocurrency exchanges. What did the warning say? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/huione-group-faces-us-ban-for-alleged-ties-to-north-koreas-lazarus-group/feed/ 0 34313
North Korean's Lazarus Group Targets Devs with Bogus Crypto Companies https://earlybirdsinvest.com/north-koreans-lazarus-group-targets-devs-with-bogus-crypto-companies/ https://earlybirdsinvest.com/north-koreans-lazarus-group-targets-devs-with-bogus-crypto-companies/#respond Sat, 26 Apr 2025 15:15:37 +0000 https://earlybirdsinvest.com/north-koreans-lazarus-group-targets-devs-with-bogus-crypto-companies/

North Korean hackers have set up fake crypto consulting firms to trick developers into downloading malware, according to a report published on April 24 by Silent Push Threat Analysts.

The group behind the scheme, called Contagious Interview, is part of the Lazarus network. They created three front companies—BlockNovas, Angeloper Agency, and SoftGlide—with two officially registered in the United States.

The hackers use these fake companies to post job listings on platforms like GitHub, freelancer websites, and recruitment boards.

What is Blockchain? (Animated Examples + Explanation)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Interested applicants are asked to record a video introduction as part of the interview process. When they try to do so, they receive an error message along with instructions to quickly fix it. If they follow the instructions, they unknowingly download malware onto their devices.

Silent Push identified three types of malware being used: BeaverTail, InvisibleFerret, and OtterCookie. BeaverTail is mainly used to steal system information and open a path for more malware. InvisibleFerret and OtterCookie focus on stealing sensitive data such as crypto wallet keys and clipboard contents.

The fake companies also use convincing websites and employee profiles to seem real. Some of these profiles are made with artificial intelligence (AI) generated images, while others are altered versions of real people’s photos.

Zach Edwards, a senior analyst at Silent Push, explained that the hackers would slightly modify real images to make them harder to trace.

On April 11, Jake Gallen, CEO of Emblem Vault, warned the crypto community about a scam that cost him over $100,000 in digital assets. How does the scam work? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/north-koreans-lazarus-group-targets-devs-with-bogus-crypto-companies/feed/ 0 32941
Lazarus Group Evolves Tactics to Target CeFi Job Seekers with ‘ClickFix’ Malware https://earlybirdsinvest.com/lazarus-group-evolves-tactics-to-target-cefi-job-seekers-with-clickfix-malware/ https://earlybirdsinvest.com/lazarus-group-evolves-tactics-to-target-cefi-job-seekers-with-clickfix-malware/#respond Sun, 06 Apr 2025 02:51:56 +0000 https://earlybirdsinvest.com/lazarus-group-evolves-tactics-to-target-cefi-job-seekers-with-clickfix-malware/

A recent cybersecurity report by Sekoia revealed an evolving threat posed by the Lazarus Group, the notorious North Korea-linked hacking group. It is now leveraging a tactic known as “ClickFix” to target job seekers in the cryptocurrency sector, particularly within centralized finance (CeFi).

This approach marks an adaptation of the group’s earlier “Contagious Interview” campaign, which was previously aimed at developers and engineers in artificial intelligence and crypto-related roles.

Lazarus Exploits Crypto Hiring

In the newly observed campaign, Lazarus has shifted its focus to non-technical professionals, such as marketing and business development personnel, by impersonating major crypto firms like Coinbase, KuCoin, Kraken, and even stablecoin issuer Tether.

The attackers build fraudulent websites mimicking job application portals and lure candidates with fake interview invitations. These sites often include realistic application forms and even requests for video introductions, fostering a sense of legitimacy.

However, when a user attempts to record a video, they are shown a fabricated error message, which typically suggests a webcam or driver malfunction. The page then prompts the user to run PowerShell commands under the guise of troubleshooting, thereby triggering the malware download.

This ClickFix method, though relatively new, is becoming more prevalent due to its psychological simplicity – since users believe they are resolving a technical issue, and not executing malicious code. According to Sekoia, the campaign draws on materials from 184 fake interview invitations, referencing at least 14 prominent companies to bolster credibility.

As such, the latest tactic demonstrates Lazarus’s growing sophistication in social engineering and its ability to exploit the professional aspirations of individuals in the competitive crypto job market. Interestingly, this shift also suggests that the group is expanding its targeting criteria by aiming not just at those with access to code or infrastructure but also at those who might handle sensitive internal data or be in a position to facilitate breaches inadvertently.

Despite the emergence of ClickFix, Sekoia reported that the original Contagious Interview campaign remains active. This parallel deployment of strategies suggests that North Korea’s state-sponsored collective may be testing their relative effectiveness or tailoring tactics to different target demographics. In both cases, the campaigns share a consistent goal – delivering info-stealing malware through trusted channels and manipulating victims into self-infection.

Lazarus Behind Bybit Hack

The Federal Bureau of Investigation (FBI) officially attributed the $1.5 billion attack on Bybit to the Lazarus Group. Hackers targeting the crypto exchange employed fake job offers to trick staff into installing tainted trading software known as “TraderTraitor.”

Although crafted to look authentic through cross-platform JavaScript and Node.js development, the applications embedded malware designed to steal private keys and execute illicit transactions on the blockchain.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

]]>
https://earlybirdsinvest.com/lazarus-group-evolves-tactics-to-target-cefi-job-seekers-with-clickfix-malware/feed/ 0 29255
Lazarus Group Becomes $1B Bitcoin Whale After Converting: Arkham https://earlybirdsinvest.com/lazarus-group-becomes-1b-bitcoin-whale-after-converting-arkham/ https://earlybirdsinvest.com/lazarus-group-becomes-1b-bitcoin-whale-after-converting-arkham/#respond Mon, 17 Mar 2025 07:22:40 +0000 https://earlybirdsinvest.com/lazarus-group-becomes-1b-bitcoin-whale-after-converting-arkham/

The Lazarus Group, which was responsible for the recent $1.5 billion Bybit hack, now holds 13,518 BTC worth $1.13 billion, according to Arkham Intelligence.

This could make North Korea the fifth-largest nation-state to hold the asset behind the United States, China, the United Kingdom, and Ukraine, according to BitBO.

It would also make the cybercrime group’s holdings larger than those of Bhutan and El Salvador, which hold 13,029 BTC and 6,089 BTC, respectively.

Lazarus recently converted some of its stolen ETH into BTC, according to Arkham.

Lazarus The Bitcoin Whale

Arkham also reports that Lazarus-linked wallets hold 13,702 ETH worth around $26 million, 5,022 BNB worth $3 million, $2.2 million in DAI, and several stablecoins and wrapped crypto assets.

“We grind and HODL just so that a hacker group can steal over $1B in crypto. It’s time for us to take the market back,” commented crypto investor Kyle Chassé.

North Korea-linked actors have stolen over $6 billion in crypto assets since 2017, with the proceeds reportedly spent on the country’s ballistic missile program, reported Elliptic earlier this month.

On March 13, it deposited 400 ETH (ETH) worth around $750,000 at the time into the Tornado Cash mixing service, according to blockchain security firm CertiK, which stated, “The funds trace to the Lazarus group’s activity on the Bitcoin network,” it noted.

Lazarus Group has also deployed six new malware packages to infiltrate developer environments, steal credentials, extract cryptocurrency data and install backdoors, according to research from cybersecurity firm Socket released last week.

The malware dubbed “BeaverTail” is embedded in packages that mimic legitimate JavaScript libraries and targets cryptocurrency wallets, specifically Solana and Exodus.

The researchers said that “the tactics, techniques, and procedures observed in this npm attack closely align with Lazarus’s known operations.”

OKX Suspends DEX

In related news, crypto exchange OKX suspended its Web3 decentralized exchange aggregator on March 17 following the detection of “a coordinated effort by Lazarus group to misuse our DeFi services.”

Following the Bybit hack, OKX rolled out a hacker address detection system for its Web3 DEX aggregator and a system to track the attacker’s latest addresses and block them in the CEX system in real-time.

Last week, Bloomberg reported that the OKX DEX aggregator was used to launder $100 million in crypto linked to Lazarus and the hack.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

]]>
https://earlybirdsinvest.com/lazarus-group-becomes-1b-bitcoin-whale-after-converting-arkham/feed/ 0 25608
North Korean Lazarus hackers infect hundreds via npm packages https://earlybirdsinvest.com/north-korean-lazarus-hackers-infect-hundreds-via-npm-packages/ https://earlybirdsinvest.com/north-korean-lazarus-hackers-infect-hundreds-via-npm-packages/#respond Wed, 12 Mar 2025 03:11:40 +0000 https://earlybirdsinvest.com/north-korean-lazarus-hackers-infect-hundreds-via-npm-packages/

NPM

Six malicious packages have been identified on npm (Node package manager) linked to the notorious North Korean hacking group Lazarus.

The packages, which have been downloaded 330 times, are designed to steal account credentials, deploy backdoors on compromised systems, and extract sensitive cryptocurrency information.

The Socket Research Team discovered the campaign, which linked it to previously known Lazarus supply chain operations.

The threat group is known for pushing malicious packages into software registries like npm, which is used by millions of JavaScript developers, and compromising systems passively.

Similar campaigns attributed to the same threat actors have been spotted on GitHub and the Python Package Index (PyPI).

This tactic often allows them to gain initial access to valuable networks and conduct massive record-breaking attacks, like the recent $1.5 billion crypto heist from the Bybit exchange.

The six Lazarus packages discovered in npm all employ typosquatting tactics to trick developers into accidental installations:

  1. is-buffer-validator – Malicious package mimicking the popular is-buffer library to steal credentials.
  2. yoojae-validator – Fake validation library used to extract sensitive data from infected systems.
  3. event-handle-package – Disguised as an event-handling tool but deploys a backdoor for remote access.
  4. array-empty-validator – Fraudulent package designed to collect system and browser credentials.
  5. react-event-dependency – Poses as a React utility but executes malware to compromise developer environments.
  6. auth-validator – Mimics authentication validation tools to steal login credentials and API keys.

The packages contain malicious code designed to steal sensitive information, such as cryptocurrency wallets and browser data that contains stored passwords, cookies, and browsing history.

They also load the BeaverTail malware and the InvisibleFerret backdoor, which North Koreans previously deployed in fake job offers that led to the installation of malware.

Code snippet that downloads malware payloads
Code snippet that downloads malware payloads
Source: Socket

“The code is designed to collect system environment details, including the hostname, operating system, and system directories,” explains the Socket report.

“It systematically iterates through browser profiles to locate and extract sensitive files such as Login Data from Chrome, Brave, and Firefox, as well as keychain archives on macOS.”

“Notably, the malware also targets cryptocurrency wallets, specifically extracting id.json from Solana and exodus.wallet from Exodus.”

All six Lazarus packages are still available on npm and the GitHub repositories, so the threat is still active.

Software developers are advised to double-check the packages they use for their projects and constantly scrutinize code in open-source software to find suspicious signs like obfuscated code and calls to external servers.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/north-korean-lazarus-hackers-infect-hundreds-via-npm-packages/feed/ 0 24627
Bybit Launches Community Effort To Fight North Korean Hackers Lazarus Group After $1,400,000,000 Heist https://earlybirdsinvest.com/bybit-launches-community-effort-to-fight-north-korean-hackers-lazarus-group-after-1400000000-heist/ https://earlybirdsinvest.com/bybit-launches-community-effort-to-fight-north-korean-hackers-lazarus-group-after-1400000000-heist/#respond Thu, 27 Feb 2025 18:05:53 +0000 https://earlybirdsinvest.com/bybit-launches-community-effort-to-fight-north-korean-hackers-lazarus-group-after-1400000000-heist/

The Bybit CEO is launching a new initiative that calls on the crypto community to help retrieve digital assets stolen by a notorious group of North Korean hackers.

Ben Zhou, Bybit’s co-founder and CEO, says on the social media platform X that they have launched a bounty program website to target the Lazarus Group after the cybercriminal outfit is believed to have stolen $1.4 billion in digital assets from their platform last week.

“Join us on war against Lazarus: http://lazarusbounty.com.

Industry first bounty site that shows aggregated full transparency on the sanctioned Lazarus money laundering activities…

Becoming a bounty hunter by connecting your wallet and help tracing the fund, when your submitted bounty leads to freeze, bounty is paid upfront upon instantly at freezing. All freezer gets 5% of the bounty, exchange, mixers and all.”

Zhou also says they have assembled a team dedicated to keep the website current, and may expand it to include other victims of the Lazarus Group’s illicit activities.

“We have assigned a team to dedicate to maintain and update this website, we will not stop until Lazarus or bad actors in the industry is eliminated. In the future we will open it up to other victims of Lazarus as well.”

According to the crypto analysis firm Arkham, the attackers siphoned about $1.4 billion in Ethereum (ETH) and Lido Staked Ether (STETH), making the incident the largest known heist in crypto history.

Lazarus most likely compromised the exchange’s ETH wallet directly through Safe, the crypto wallet that Bybit was using, by accessing its Amazon Web Services (AWS) bucket, according to the Bybit CEO.

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Follow us on X, Facebook and Telegram

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/bybit-launches-community-effort-to-fight-north-korean-hackers-lazarus-group-after-1400000000-heist/feed/ 0 22247
Bybit unveils bounty platform to tackle crypto crime following massive Lazarus hack https://earlybirdsinvest.com/bybit-unveils-bounty-platform-to-tackle-crypto-crime-following-massive-lazarus-hack/ https://earlybirdsinvest.com/bybit-unveils-bounty-platform-to-tackle-crypto-crime-following-massive-lazarus-hack/#respond Tue, 25 Feb 2025 22:53:20 +0000 https://earlybirdsinvest.com/bybit-unveils-bounty-platform-to-tackle-crypto-crime-following-massive-lazarus-hack/

Bybit announced a bounty platform designed to combat crypto-related crime titled LazarusBounty.com following.

The initiative employs a structured, four-pronged approach to identifying illicit activity, holding hackers accountable, and enhancing crypto security. 

The effort follows a hack perpetrated against Bybit on Feb. 21, which resulted in the loss of nearly $1.5 billion in Ethereum (ETH) and ETH synthetic tokens. According to blockchain security firm Elliptic, this is the largest hack in history.

War against Lazarus

LazarusBounty.com consolidates blockchain security data from leading firms, including Chainalysis, Arkham, and GoPlus, into a unified security repository. This real-time database provides investigators and the broader community with critical insights to detect, analyze, and counteract illicit activities. 

LazarusBounty.com mobilizes blockchain forensic specialists, such as ZachXBT and Yu Xian of SlowMist, to conduct in-depth investigations when significant breaches occur.

These experts have forensic tools and methodologies to trace stolen funds, identify attackers, and coordinate responses with law enforcement and affected platforms. The initiative is a proactive deterrent against cybercrime, strengthening the industry’s ability to respond to security threats.

Bybit CEO Ben Zhou said:

“In today’s blockchain landscape, transparency isn’t just a principle — it’s our most potent weapon against cybercrime. With LazarusBounty.com, we are taking a stand to ensure that every transaction is visible and every hacker is held accountable. Our multifive-pronged offensive is a clear message: if you steal, you will be found, and justice will be swift.”

Moreover, LazarusBounty.com has a bounty leaderboard that tracks and rewards contributions based on the effectiveness of efforts to recover stolen funds. The site catalogs verified intelligence, recognizing security researchers and ethical hackers who help unmask cybercriminals. 

An automated notification system enhances response times by immediately alerting exchanges and platforms to freeze illicitly obtained funds before they can be laundered.

Bybit has also assembled a security advisory board comprising chief security officers from major blockchain networks. This decentralized council collaborates to enhance security protocols, share intelligence, and reinforce protective measures across the crypto ecosystem.

Tracking the funds

According to on-chain data highlighted by Arkham, the funds extracted in the Bybit hack are being swapped for Bitcoin (BTC) and DAI via the multichain protocol Thorchain and the OKX Web3 Swap feature. So far, the hackers swapped $6.2 million to BTC.

Blockchain analytics platform SpotOnChain also noted that roughly $250 million has already been laundered.

Due to the structure of the attack and the subsequent laundering process, analysts suspect that the North Korean Lazarus Group is behind the Bybit hack.

Elliptic highlighted that Lazarus uses various layering tactics, including sending funds through numerous crypto wallets, using cross-chain bridges to transfer assets across blockchains, converting assets via decentralized exchanges or swap services, and leveraging mixers like Tornado Cash.

These techniques are intended to buy time for launderers before attempting to cash out the illicit funds. Lazarus seems to be currently performing the third step, using multichain solutions to layer funds.

Mentioned in this article
Blocscale
]]>
https://earlybirdsinvest.com/bybit-unveils-bounty-platform-to-tackle-crypto-crime-following-massive-lazarus-hack/feed/ 0 21863