North Korean hackers who stole $600M from Axie Infinity are still laundering their haul, recently moving $4.5M of ETH, after the US tried to freeze those assets
Despite U.S. law enforcement identifying the Lazarus Group as the thieves, the hackers have laundered 17 percent of their $600 million haul
Context & Ripple Effects
The Treasury publicly tied the Ronin bridge theft to the Lazarus Group back in April 2022 within days of the heist, and by September the US government had clawed back roughly $30M with Chainalysis' help in its first such recovery from the Axie hackers. This report shows the limits of that playbook: attribution and freezes have not stopped the group from washing 17% of the $600M, including a recent $4.5M ETH move.
The pattern is not isolated to Axie. When Lazarus moved ~$63.5M in ETH stolen from the Harmony bridge, Binance and Huobi froze 124 BTC linked to the group in January 2023 — evidence that exchange-side freezes, not government action alone, are where stolen North Korean funds actually get caught.
First-order effects
- Lazarus Group can keep converting stolen ETH into spendable funds at a steady clip despite the US freeze attempt, meaning most of the $600M remains recoverable only on paper.
- Any exchange or service touching the hackers' wallets now faces direct sanctions exposure, since the Treasury has formally attributed the theft to a North Korea-backed entity.
Second-order effects
- Exchanges are being pushed into de facto enforcement roles — the Binance and Huobi freezes after the Harmony hack show wallet screening and asset freezes becoming standard practice for venues that touch Lazarus-linked funds.
- Blockchain analytics firms like Chainalysis gain leverage and revenue as the indispensable intermediaries between law enforcement and on-chain assets, effectively privatizing part of sanctions enforcement.
Third-order effects
- If state-sponsored groups keep outpacing freeze-and-recover efforts, the structural answer shifts toward pre-emptive controls: mandatory wallet screening at exchanges and hardened bridge design, rather than post-hoc asset seizures.
- North Korean crypto theft is consolidating as a durable state-funding channel, which raises the odds that crypto-specific sanctions regimes harden into permanent infrastructure much like traditional financial sanctions.
The trend: State-sponsored North Korean crypto theft is scaling faster than law enforcement's freeze-and-recover playbook, pushing exchanges and analytics firms into the front line of sanctions enforcement.