/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

The FBI says North Korea-backed hacking groups Lazarus and APT38 are behind the June 2022 theft of ~$100M in ETH, USDT, and wBTC from Harmony's Horizon bridge

Lazarus Group and APT38, both associated with North Korea, are responsible for the attack in June, the agency concluded.

CoinDesk Jesse Hamilton

Context & Ripple Effects

The FBI's attribution converts an earlier Elliptic assessment pointing to Lazarus into an official conclusion about the Horizon bridge theft. It also places the incident alongside the Treasury's prior attribution of the Ronin bridge theft to Lazarus, linking two major bridge losses to the same North Korea-backed actor.

The case had already moved from attribution to asset tracing: Binance and Huobi froze bitcoin tied to Lazarus after funds from the Horizon theft were moved, according to the January exchange freeze. The FBI finding strengthens that enforcement narrative around Harmony's loss.

First-order effects

  • Harmony's roughly $100 million Horizon bridge loss is now formally attributed by the FBI to Lazarus Group and APT38, rather than remaining an analyst-led suspicion.
  • The FBI's identification gives exchanges and investigators a defined actor and transaction trail to use when screening assets associated with the theft.

Second-order effects

  • Binance, Huobi, and other crypto intermediaries face stronger grounds to maintain or expand controls on funds traced from the Horizon theft after their earlier freeze of Lazarus-linked bitcoin.
  • Bridge operators must treat the Horizon incident as part of a repeated Lazarus-linked attack pattern that also includes Ronin, rather than as an isolated Harmony breach.

Third-order effects

  • If official attributions continue to connect major bridge thefts to the same state-backed groups, cross-chain infrastructure will face a persistent legitimacy challenge driven as much by illicit-finance controls as by technical security.
  • The pattern points toward bridge security and exchange tracing becoming increasingly interdependent: vulnerabilities create the losses, while centralized intermediaries become key points for constraining their movement.

The trend: Cross-chain bridges are becoming a focal point where state-linked crypto theft, blockchain tracing, and exchange enforcement converge.

Discussion

  • @campuscodi Catalin Cimpanu on x
    Looks like this was sparked by the group's effort 10 days ago to launder $63.5 million of the stolen funds. From the report: -RAILGUN protocol (https://t.co/...) used for launder ops (expect sanctions 😅) -Job offers as entry lures -TraderTraitor for malware delivery https://twitt…
  • @kevincollier Kevin Collier on x
    FBI saying it recovered a portion of stolen crypto (always some, not all) from a big brazen heist becoming more and more routine https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    The FBI has formally linked the Harmony crypto-heist ($100mil) to Lazarus/APT38 Hack took place in June 2022. Elliptic linked it to Lazarus a few weeks later, but this marks the first official attribution https://www.fbi.gov/... https://twitter.com/...
  • @ldrogen Leigh Drogen on x
    supports my theory that the DOJ cut a deal with CZ to have Binance act as a sink for illicit assets that they could eventually control https://twitter.com/...
  • @zachxbt @zachxbt on x
    Update: Final graph of the recent exchange outflows of $38m (1656 BTC) by Lazarus Group for the Harmony Bridge hack. Includes chain-hopping, depositing to bitcoin mixers, and sending to exchanges. https://twitter.com/...
  • @tayvano_ @tayvano_ on x
    the blockchain is a public ledger of every transaction that anyone sends including hackers including to cex's including from cex's if you aren't watching @zachxbt yet, you should be. dude seriously knows how to follow the money. https://twitter.com/... https://twitter.com/...
  • @zachxbt @zachxbt on x
    @tier10k If you're curious where the funds went https://twitter.com/...
  • @780thc @780thc on x
    FBI Confirms Lazarus Group, APT38 Cyber Actors Responsible for Harmony's Horizon Bridge Currency Theft https://www.fbi.gov/... @FBI
  • @fbicharlotte @fbicharlotte on x
    FBI Confirms Lazarus Group, APT38 Cyber Actors Responsible for Harmony's Horizon Bridge Currency Theft: The FBI continues to combat malicious cyber activity, including the threat posed by the Democratic People's Republic of Korea (DPRK) to the U.S. and ... https://www.fbi.gov/...
  • @tier10k @tier10k on x
    [DB] FBI Confirms Lazarus Group Responsible for Harmony Bridge Theft, Froze “Portion” of Funds in Cooperation With Exchanges
  • @certikalert @certikalert on x
    #CertiKSkynetAlert 🚨 @FBI Confirms that the Lazarus Group is responsible for the @harmonyprotocol bridge exploit that resulted in the loss of ~100m in user funds on 23 June, 2022. Read more 👇 https://www.fbi.gov/...