Elliptic: North Korea-backed hacking group Lazarus could be behind Harmony's ~$100M altcoin theft; the hack bore similarities to the $600M Ronin bridge attack
Margi Murphy / Bloomberg : Source: Elliptic Connect .
Context & Ripple Effects
Elliptic's assessment placed Harmony's breach in the same investigative arc as the Treasury-linked Ronin theft, suggesting a recurring Lazarus playbook rather than an isolated platform failure. That initial attribution was later reinforced when the FBI named Lazarus and APT38 in the Harmony theft.
The case also foreshadowed a broader Lazarus campaign: later Elliptic coverage described the group expanding its targets from decentralized services toward centralized ones.
First-order effects
- Harmony's theft becomes part of the Lazarus attribution trail, giving investigators and asset-tracing firms a concrete comparison point in the Ronin attack.
- Lazarus is tied in public analysis to a second major bridge theft, increasing the significance of transaction flows associated with the stolen Harmony assets.
Second-order effects
- The Ronin precedent makes bridge operators and their counterparties more likely to treat similar attack patterns as a shared threat rather than as separate incidents.
- Exchanges become consequential choke points after a bridge theft: later freezes of assets linked to the Harmony hack show how attribution can turn tracing into an operational response.
Third-order effects
- Repeated Lazarus-linked thefts point to crypto infrastructure security becoming inseparable from sanctions-enforcement risk, not solely a product-security issue.
- As the group shifts activity across decentralized and centralized targets, the industry faces a persistent adversary that can exploit weak points across the crypto transaction chain.
The trend: North Korea-linked crypto theft is evolving from isolated exploits into a cross-platform financial-security and sanctions-enforcement challenge.