The FBI says North Korea-backed hacking groups Lazarus and APT38 are behind the June 2022 theft of ~$100M in ETH, USDT, and wBTC from Harmony's Horizon bridge
Lazarus Group and APT38, both associated with North Korea, are responsible for the attack in June, the agency concluded.
The case had already moved from attribution to asset tracing: Binance and Huobi froze bitcoin tied to Lazarus after funds from the Horizon theft were moved, according to the January exchange freeze. The FBI finding strengthens that enforcement narrative around Harmony's loss.
First-order effects
Harmony's roughly $100 million Horizon bridge loss is now formally attributed by the FBI to Lazarus Group and APT38, rather than remaining an analyst-led suspicion.
The FBI's identification gives exchanges and investigators a defined actor and transaction trail to use when screening assets associated with the theft.
Second-order effects
Binance, Huobi, and other crypto intermediaries face stronger grounds to maintain or expand controls on funds traced from the Horizon theft after their earlier freeze of Lazarus-linked bitcoin.
Bridge operators must treat the Horizon incident as part of a repeated Lazarus-linked attack pattern that also includes Ronin, rather than as an isolated Harmony breach.
Third-order effects
If official attributions continue to connect major bridge thefts to the same state-backed groups, cross-chain infrastructure will face a persistent legitimacy challenge driven as much by illicit-finance controls as by technical security.
The pattern points toward bridge security and exchange tracing becoming increasingly interdependent: vulnerabilities create the losses, while centralized intermediaries become key points for constraining their movement.
The trend: Cross-chain bridges are becoming a focal point where state-linked crypto theft, blockchain tracing, and exchange enforcement converge.
Looks like this was sparked by the group's effort 10 days ago to launder $63.5 million of the stolen funds. From the report: -RAILGUN protocol (https://t.co/...) used for launder ops (expect sanctions 😅) -Job offers as entry lures -TraderTraitor for malware delivery https://twitt…
FBI saying it recovered a portion of stolen crypto (always some, not all) from a big brazen heist becoming more and more routine https://twitter.com/...
The FBI has formally linked the Harmony crypto-heist ($100mil) to Lazarus/APT38 Hack took place in June 2022. Elliptic linked it to Lazarus a few weeks later, but this marks the first official attribution https://www.fbi.gov/... https://twitter.com/...
supports my theory that the DOJ cut a deal with CZ to have Binance act as a sink for illicit assets that they could eventually control https://twitter.com/...
Update: Final graph of the recent exchange outflows of $38m (1656 BTC) by Lazarus Group for the Harmony Bridge hack. Includes chain-hopping, depositing to bitcoin mixers, and sending to exchanges. https://twitter.com/...
the blockchain is a public ledger of every transaction that anyone sends including hackers including to cex's including from cex's if you aren't watching @zachxbt yet, you should be. dude seriously knows how to follow the money. https://twitter.com/... https://twitter.com/...
FBI Confirms Lazarus Group, APT38 Cyber Actors Responsible for Harmony's Horizon Bridge Currency Theft: The FBI continues to combat malicious cyber activity, including the threat posed by the Democratic People's Republic of Korea (DPRK) to the U.S. and ... https://www.fbi.gov/...
#CertiKSkynetAlert 🚨 @FBI Confirms that the Lazarus Group is responsible for the @harmonyprotocol bridge exploit that resulted in the loss of ~100m in user funds on 23 June, 2022. Read more 👇 https://www.fbi.gov/...