The notorious hackers behind the Bybit exchange breach have intensified their money laundering efforts, moving an additional 62,200 Ether (ETH) valued at approximately $138 million. This activity comes in the wake of ongoing attempts by U.S. authorities to halt transactions associated with the exploiters, specifically the Lazarus Group from North Korea.
Key Takeaways
-
The hackers have now laundered 343,000 ETH, which is about 68.7% of the total stolen funds.
-
Only 156,500 ETH remains to be moved from the original 499,000 ETH stolen in the Bybit hack.
-
The laundering activities had previously slowed due to increased scrutiny from the FBI and blockchain analytics firms.
Overview Of The Bybit Hack
On February 21, 2025, Bybit suffered a massive security breach, resulting in the theft of $1.4 billion worth of cryptocurrency. The incident marked one of the largest hacks in the history of the crypto industry, surpassing the infamous $650 million Ronin bridge hack in 2022. The hackers, identified as North Korea's Lazarus Group, have been systematically moving the stolen funds through various channels.
Recent Laundering Activities
As of March 1, 2025, the hackers successfully laundered another 62,200 ETH. According to a pseudonymous crypto analyst known as EmberCN, this brings the total amount of laundered Ether to 343,000 ETH, leaving only 156,500 ETH still to be moved. The analyst predicts that the remaining funds will likely be cleared within the next three days.
Law Enforcement Response
In response to the ongoing laundering activities, the FBI has taken significant steps to block transactions linked to the Bybit hackers. They have shared a list of 51 Ethereum addresses associated with the hackers and flagged over 11,000 crypto wallet addresses that may be connected to the illicit activities. This proactive approach aims to disrupt the flow of stolen funds and hold the perpetrators accountable.
Methods Used For Laundering
The hackers have employed various methods to convert portions of the stolen Ether into other cryptocurrencies, including Bitcoin (BTC) and the Dai (DAI) stablecoin. They have utilized decentralized exchanges, cross-chain bridges, and instant swap services that do not require Know Your Customer (KYC) protocols, making it easier for them to obscure their tracks.
One notable platform involved in these transactions is THORChain, which has faced criticism for facilitating a significant share of the transfers made by the North Korean hackers. Following a controversial vote to revert a decision blocking transactions linked to the hackers, one of THORChain’s developers announced they would no longer contribute to the protocol.
Conclusion
The Bybit hack and the subsequent laundering activities highlight the ongoing challenges faced by law enforcement and the cryptocurrency industry in combating cybercrime. As the situation develops, it remains crucial for exchanges and blockchain platforms to enhance their security measures and collaborate with authorities to prevent similar incidents in the future.
Sources
-
Bybit hackers resume laundering activities, moving another 62,200 ETH, Cointelegraph.
-
Bybit hackers resume laundering activities, moving another 62,200 ETH, StartupNews.fyi.