We are currently updating CBG to Version 5.0. During this time, you may experience temporary technical issues. For further information or support, please contact us directly.

Discussion –

0

Discussion –

0

North Korean Hackers Launder Hundreds of Millions from $1.5B ByBit Cyber Heist

North Korean Hackers Launder $300M from Record-Breaking ByBit Crypto Heist

A Sophisticated Operation Unfolds

A hacking group believed to be working under the North Korean regime has successfully cashed out at least $300 million (£232 million) of stolen cryptocurrency. This massive sum is part of a record-breaking $1.5 billion heist that targeted the crypto exchange ByBit two weeks ago.

The attackers, identified as the notorious Lazarus Group, managed to infiltrate ByBit’s systems, initiating an elaborate scheme to siphon off digital assets. Since then, investigators have been working tirelessly to track and block the hackers’ efforts to convert the stolen funds into cash.

A Race Against Time

Experts warn that the Lazarus Group operates with an unmatched level of efficiency, working nearly around the clock to obscure the money trail.

“Every minute matters for the hackers who are trying to confuse the money trail, and they are extremely sophisticated in what they’re doing,” said Dr. Tom Robinson, co-founder of crypto investigative firm Elliptic.

Robinson further explained that among all cybercriminal groups engaged in cryptocurrency-related crimes, North Korea’s Lazarus Group is the most adept at laundering stolen funds.

“I imagine they have an entire room of people doing this using automated tools and years of experience. We can also see from their activity that they only take a few hours’ break each day, possibly working in shifts to get the crypto turned into cash.”

Funds Disappearing Into the Abyss

According to ByBit, approximately 20% of the stolen funds have now “gone dark,” meaning they are unlikely to be recovered.

The United States and its allies have accused North Korea of conducting numerous cyber heists in recent years, allegedly using the stolen assets to finance military and nuclear programs.

The ByBit breach occurred on February 21 when hackers compromised one of ByBit’s suppliers. They covertly altered a digital wallet address, redirecting the transfer of 401,000 Ethereum coins from ByBit’s intended destination to their own wallets.

ByBit’s CEO, Ben Zhou, reassured customers that their personal funds were not affected by the breach. The company has since replenished the stolen assets with loans from investors and has declared its commitment to fighting back against the Lazarus Group.

A Global Effort to Track Stolen Crypto

To counteract the theft, ByBit launched the Lazarus Bounty Program, encouraging the public to assist in tracing the stolen assets and freezing them when possible. Since all cryptocurrency transactions are recorded on a public blockchain, the movement of funds can be monitored in real time.

Crypto firms have the ability to freeze assets if they detect illicit activity. However, North Korean hackers are experts in circumventing such measures.

So far, 20 individuals have collectively earned over $4 million in rewards for identifying and blocking $40 million worth of stolen assets. Nevertheless, experts remain skeptical about the recovery of the remaining funds.

“North Korea is a very closed system and closed economy, so they created a successful industry for hacking and laundering, and they don’t care about the negative impression of cybercrime,” said Dr. Dorit Dor from cybersecurity firm Check Point.

The Role of Exchanges in Crypto Laundering

One major challenge in stopping the hackers is the varying levels of cooperation among crypto exchanges.

ByBit and other industry players have accused a platform known as eXch of enabling the criminals to cash out their funds. More than $90 million has allegedly been funneled through this exchange.

The platform’s owner, Johann Roberts, disputes these allegations. In an email response, Roberts admitted that eXch initially failed to stop the transactions but attributed this to a long-standing dispute with ByBit. He insisted that his team was unsure whether the funds were truly stolen at the time. He now claims to be cooperating with investigators but argues that mainstream exchanges are undermining the principles of privacy and anonymity in cryptocurrency.

North Korea’s Cybercrime Network

Although North Korea has never officially acknowledged its involvement with Lazarus Group, the country remains the only known state actor using hacking operations for financial gain.

Initially targeting banks, the group has, in recent years, shifted its focus to cryptocurrency platforms due to their weaker security measures. Notable attacks linked to North Korea include:

  • 2019: $41 million stolen from UpBit
  • 2020: $275 million theft from KuCoin (most funds later recovered)
  • 2022: $600 million stolen in the Ronin Bridge attack
  • 2023: $100 million siphoned from Atomic Wallet

The Fight Against Cybercrime Continues

In 2020, the United States added members of the Lazarus Group to its Cyber Most Wanted list. However, apprehending these individuals remains a significant challenge, as they are unlikely to leave North Korea.

As the cybersecurity industry grapples with increasingly sophisticated threats, exchanges and regulatory bodies worldwide are working together to mitigate risks and enhance protections. However, as recent events demonstrate, North Korean hackers continue to refine their techniques—posing an ever-growing threat to the cryptocurrency ecosystem.

Author: Din Kumar

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *