N. Korea-linked Lazarus Group stole ~$240M in crypto in the past 104 days, as it ramps up hacks and shifts focus from decentralized services to centralized ones
The elite North Korean hacking group Lazarus appears to have recently ramped up its operations, conducting a confirmed four attacks against crypto entities since June 3rd.
Context & Ripple Effects
This report fits a long-running pattern of Lazarus-linked crypto theft: a 2018 Group-IB account alleged the group was responsible for a large share of exchange losses, while later reporting connected it to the suspected Harmony theft.
The reported move toward centralized services follows the U.S. Treasury's attribution of the Ronin bridge theft to Lazarus, showing that the group’s targets have spanned different parts of the crypto stack.
First-order effects
- Centralized crypto-service operators become the group’s stated near-term focus, raising the urgency of incident response and security review for platforms holding or moving customer assets.
- The four confirmed attacks translate into immediate losses for the affected crypto entities and reinforce Lazarus’s operational tempo as a material threat actor.
Second-order effects
- Other centralized platforms are likely to prioritize controls around custody, access, and transaction operations as attackers concentrate on fewer, higher-value service providers.
- The shift narrows the distinction between decentralized-protocol risk and exchange or custodian risk: users and business partners must assess the security posture of the intermediaries they rely on.
Third-order effects
- If this targeting pattern persists, crypto’s security burden will increasingly concentrate at centralized custody and service chokepoints, rather than solely in smart contracts and bridges.
- Repeated major thefts tied to the same actor strengthen the broader crypto legitimacy gap, making resilience and credible security practices more central to institutional trust.
The trend: Crypto crime is evolving from opportunistic protocol exploits toward sustained campaigns against the centralized operators that aggregate assets and access.