North Korea-tied Lazarus Group stole nearly $240M in crypto in the past 104 days, ramping up hacks and shifting focus from decentralized to centralized services
The elite North Korean hacking group Lazarus appears to have recently ramped up its operations, conducting a confirmed four attacks against crypto entities since June 3rd.
Context & Ripple Effects
The reported campaign extends a documented Lazarus crypto-theft record: U.S. authorities previously tied the group to the Ronin bridge theft, while later reporting connected it to Harmony's Horizon bridge incident.
The meaningful change is target selection. After attacks associated with decentralized infrastructure, Elliptic says the group is now directing more activity toward centralized crypto services.
First-order effects
- Centralized crypto services face an immediate increase in exposure to a group reported to have carried out four confirmed attacks since June 3, requiring heightened monitoring of wallets, access controls, and transaction flows.
- Lazarus's reported haul and tempo reinforce the operational impact of crypto theft on targeted platforms and their users, rather than confining the risk to decentralized protocols.
Second-order effects
- Exchanges and other centralized providers may face stronger pressure to distinguish themselves on security and incident-response practices as attackers shift toward their systems.
- The shift broadens the threat model for firms that had focused heavily on bridge and protocol exploits after the Harmony theft was linked to Lazarus, making cross-platform tracing and controls more consequential.
Third-order effects
- If state-linked attackers continue to move between decentralized and centralized targets, crypto security will be judged increasingly as an ecosystem-wide operational risk rather than a protocol-specific weakness.
- Recurring high-profile thefts could deepen the long-running record of exchange-focused crypto losses, strengthening the case for more mature security, compliance, and asset-recovery capabilities across the sector.
The trend: State-linked crypto theft is evolving from isolated protocol exploits into a persistent, adaptive risk spanning both decentralized infrastructure and centralized service providers.