On February 21, 2025, the cryptocurrency world was rocked by the revelation that North Korea's notorious Lazarus Group is linked to two significant hacks: the $1.4 billion theft from Bybit and the $29 million breach of Phemex. This connection was established through on-chain evidence, highlighting the ongoing threat posed by state-sponsored cybercrime in the crypto space.
"Lazarus Group just linked the Bybit hack to the Phemex hack directly on the blockchain by mixing funds from the original theft address for both incidents" - ZachXBT
Key Takeaways
-
Lazarus Group is suspected of orchestrating both the Bybit and Phemex hacks.
-
The Bybit hack is the largest in crypto history, with over $1.4 billion stolen.
-
The Phemex hack involved the theft of $29 million through over 125 transactions.
-
The stolen funds are being laundered through crypto mixing protocols, complicating recovery efforts.
Overview Of The Hacks
The Bybit hack, which occurred on February 21, 2025, is now recognized as the largest theft in cryptocurrency history. Attackers managed to siphon off more than $1.4 billion in various digital assets, including liquid-staked Ether and other ERC-20 tokens. This incident has raised alarms across the crypto community, as it accounts for more than half of the total $2.3 billion stolen in crypto-related hacks in 2024.
In January, the Phemex exchange was also targeted, resulting in a loss of $29 million. Recent investigations have revealed that the same wallets associated with the Lazarus Group were involved in both hacks, indicating a coordinated effort to consolidate stolen funds.
The Methodology Behind The Hacks
According to blockchain security analysts, the Lazarus Group utilized sophisticated techniques to execute these hacks. The Bybit attack involved a deceptive transaction that tricked signers of the Ethereum multisig cold wallet into approving a malicious smart contract change. This allowed the hackers to gain control of the wallet and transfer all ETH to an unknown address.
The Phemex hack was executed through a series of over 125 transactions across 11 blockchain networks, draining the exchange's hot wallets. The attackers then began converting the stolen assets into Ether using crypto mixing protocols like Tornado Cash, making it increasingly difficult for authorities to trace the funds.
The Broader Implications
The Lazarus Group has been linked to some of the most significant crypto heists in history, including the $600 million Ronin network hack and the $230 million WazirX exchange breach. In 2024 alone, North Korean hackers are reported to have stolen over $1.34 billion across 47 incidents, marking a staggering 102% increase from the previous year.
This surge in cybercrime has prompted a joint warning from the United States, Japan, and South Korea regarding the growing threat posed by North Korean hackers targeting the cryptocurrency industry. The implications of these hacks extend beyond financial losses; they raise concerns about the security and integrity of the entire crypto ecosystem.
Chainalysis
Conclusion
The consolidation of funds from the Bybit and Phemex hacks by the Lazarus Group underscores the persistent threat of state-sponsored cybercrime in the cryptocurrency space. As the industry grapples with these challenges, it becomes increasingly vital for exchanges and users to adopt robust security measures to protect their assets from such sophisticated attacks.
Sources
-
Lazarus Group consolidates Bybit funds into Phemex hacker wallet, Cointelegraph.
-
Lazarus Group consolidates Bybit funds into Phemex hacker wallet, StartupNews.fyi.