Binance founder Changpeng Zhao (CZ) has revealed that his Google account was recently targeted by attackers believed to be backed by a government, with suspicions centered on North Korea’s notorious Lazarus Group. The incident highlights the growing risks faced by major crypto industry figures from sophisticated, state-sponsored cyber threats.
Key Takeaways
-
Changpeng Zhao (CZ) received a Google alert about a possible government-backed hacking attempt on his account.
-
North Korea’s Lazarus Group, responsible for multi-billion-dollar cryptocurrency heists, is the main suspect.
-
State-backed cyberattacks on the crypto industry are on the rise, increasingly targeting individuals, not just exchanges.
Google Security Warning Raises Alarm for Crypto Executives
CZ shared a screenshot of Google's warning on his social media, noting it wasn't the first time he’d received such alerts. These Google notifications are typically reserved for high-profile individuals considered at elevated risk for state-sponsored hacking attempts. In CZ’s case, the alert pointed to an attempt to steal his Google password, though there is no evidence his account was compromised.
Security experts suggest the warning is consistent with tactics used by the Lazarus Group, which has targeted the crypto sector extensively in recent years. The group is infamous for employing phishing, malware, and social engineering strategies to gain unauthorized access to sensitive accounts.
Lazarus Group’s Growing Impact on the Crypto Sector
The Lazarus Group, linked to North Korea, has become the crypto industry’s most prolific state-backed hacker organization. Reports in 2025 indicate they have stolen over $2 billion in digital assets this year alone, with a cumulative total reportedly exceeding $6 billion since their campaign began. Their largest single heist, the $1.4 billion Bybit exchange hack, occurred in February 2025 and remains the biggest crypto theft on record.
A notable shift in 2024 and 2025 has been Lazarus targeting not only company infrastructure but also individual executives, such as CZ and other senior figures. The group's methods now often include posing as job candidates for developer, security, or finance positions, seeking insider access to critical systems.
Crypto Industry Responds to Attack Threats
In response to the rising tide of advanced hacks, CZ and other leaders have emphasized the need for robust account security. Recommendations include enabling two-factor authentication, regularly updating passwords, and monitoring for suspicious login activity. High-profile individuals are encouraged to treat all unexpected security alerts with utmost seriousness and review account settings promptly.
The incident serves as a reminder to firms and employees in the digital asset sector that the threat from state-backed cybercriminals is persistent and evolving. Increased vigilance and proactive security measures are essential to defend against these sophisticated adversaries.
Sources
-
Zhao's Google Account Attacked By 'Government-Backed' Hackers, Cointelegraph.
-
Hackers Target CZ’s Google Account, ForkLog.
-
Binance founder CZ receives alert from Google about possible government-backed attacks, Crypto Briefing.
-
CZ Gets Google Warning of State-Actor Hack – Lazarus Now Targeting Crypto Execs?, CryptoRank.
-
Binance Founder CZ Alerts Followers About Possible State, CoinCentral.
This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.