Binance Square
#lazarusgroup

lazarusgroup

1.4M views
357 Discussing
WISE PUMPS
·
--
😱 #MetaMask Parent Company Accidentally Hired a North Korean Hacker! Consensys, the company behind MetaMask, reportedly hired a developer under the alias "Tyler Knapp" through a third-party recruiting firm. 🇰🇵 About a month later, the company discovered the developer was allegedly linked to North Korea's #LazarusGroup . During that time, he contributed code to a feature related to #crypto -to-fiat conversion. Even more concerning, the same individual had previously worked at Ankr, Blueberry Protocol, DEPO, Pickle Finance, and Harmony—projects that were all later exploited, although that alone does not prove a connection to those hacks. 🛡 The incident highlights how sophisticated state-sponsored infiltration has become. If a major player like Consensys can be targeted, smaller crypto companies with fewer security resources may face an even greater challenge. #BurnhamToBecomeUKPrimeMinister @wisegbevecryptonews9
😱 #MetaMask Parent Company Accidentally Hired a North Korean Hacker!

Consensys, the company behind MetaMask, reportedly hired a developer under the alias "Tyler Knapp" through a third-party recruiting firm.

🇰🇵 About a month later, the company discovered the developer was allegedly linked to North Korea's #LazarusGroup . During that time, he contributed code to a feature related to #crypto -to-fiat conversion.

Even more concerning, the same individual had previously worked at Ankr, Blueberry Protocol, DEPO, Pickle Finance, and Harmony—projects that were all later exploited, although that alone does not prove a connection to those hacks.

🛡 The incident highlights how sophisticated state-sponsored infiltration has become. If a major player like Consensys can be targeted, smaller crypto companies with fewer security resources may face an even greater challenge.
#BurnhamToBecomeUKPrimeMinister @WISE PUMPS
ETH: 🚀 Arbitrum just froze $70M worth of ETH in response to the KelpDAO hack ✅ The attacker moved over $176M across multiple chains, with Bitcoin becoming their new playground. 💾 By intervening early, Arbitrum prevented roughly 29% of the stolen funds from entering the laundering pipeline 🔄 A race against time ensued as investigators tracked the thief's rapid moves through THORChain and other decentralized protocols 🔮 Lazarus Group is suspected to be behind this brazen move, using complex tactics to obscure their tracks. 🔍 Is the remaining $176M still in play? Let's watch closely! 💬 Will these funds find a safe haven or will they slip through our fingers? 🛑 Are we overthinking this situation or is there real risk here? 👇 #ETH #KelpDAO #LazarusGroup
ETH: 🚀 Arbitrum just froze $70M worth of ETH in response to the KelpDAO hack ✅

The attacker moved over $176M across multiple chains, with Bitcoin becoming their new playground. 💾

By intervening early, Arbitrum prevented roughly 29% of the stolen funds from entering the laundering pipeline 🔄

A race against time ensued as investigators tracked the thief's rapid moves through THORChain and other decentralized protocols 🔮

Lazarus Group is suspected to be behind this brazen move, using complex tactics to obscure their tracks. 🔍

Is the remaining $176M still in play? Let's watch closely! 💬

Will these funds find a safe haven or will they slip through our fingers? 🛑

Are we overthinking this situation or is there real risk here? 👇

#ETH #KelpDAO #LazarusGroup
Arbitrum Seals a Win, but the Hunt Continues 🛡️ Arbitrum has frozen 30,766 ETH worth over $70 million linked to the KelpDAO exploit, preventing roughly 29% of stolen funds from entering the laundering pipeline. However, the attacker is still moving assets across multiple chains and protocols, including Bitcoin. This high-level operational discipline hints at a sophisticated threat actor behind the scenes. The Lazarus Group has been linked to previous crypto thefts using similar tactics. With over $176 million already laundered through various decentralized bridges, the race against time continues for blockchain investigators and law enforcement agencies. Is the Lazarus Group involved in this operation? Share your thoughts below! 💬 #Arbitrum #KelpDAO #LazarusGroup
Arbitrum Seals a Win, but the Hunt Continues 🛡️

Arbitrum has frozen 30,766 ETH worth over $70 million linked to the KelpDAO exploit, preventing roughly 29% of stolen funds from entering the laundering pipeline. However, the attacker is still moving assets across multiple chains and protocols, including Bitcoin. This high-level operational discipline hints at a sophisticated threat actor behind the scenes.

The Lazarus Group has been linked to previous crypto thefts using similar tactics. With over $176 million already laundered through various decentralized bridges, the race against time continues for blockchain investigators and law enforcement agencies.

Is the Lazarus Group involved in this operation? Share your thoughts below! 💬

#Arbitrum #KelpDAO #LazarusGroup
🔴 $BTC LAZARUS GROUP JUST DUMPED 121.5 BTC – WHAT HAPPENS NEXT? 💣 📉 Over $7.7M in stolen BTC hit the market an hour ago, and this isn’t just a whale—it’s the Lazarus Group. 🦈 When hackers move coins, they don’t hold. They sell, they swap, they shake retail out. This chunk alone could trigger a local liquidity hunt. 🔍 Historical patterns show these transfers often precede short-term selling pressure on spot order books. Bid walls below current price will be tested. Smart money will wait for the reaction—either absorb the sell-off or let it sweep lower liquidity before bouncing. 📊 💬 Are you expecting a dip-buy opportunity or a deeper cascade? 👇 ⚠️ Not financial advice. Always manage your risk. 🛡️ 🏷️ #BTC #LazarusGroup #Bitcoin #CryptoAlert #WhaleWatch 💣 🦈
🔴 $BTC LAZARUS GROUP JUST DUMPED 121.5 BTC – WHAT HAPPENS NEXT? 💣

📉 Over $7.7M in stolen BTC hit the market an hour ago, and this isn’t just a whale—it’s the Lazarus Group. 🦈 When hackers move coins, they don’t hold. They sell, they swap, they shake retail out. This chunk alone could trigger a local liquidity hunt.

🔍 Historical patterns show these transfers often precede short-term selling pressure on spot order books. Bid walls below current price will be tested. Smart money will wait for the reaction—either absorb the sell-off or let it sweep lower liquidity before bouncing. 📊

💬 Are you expecting a dip-buy opportunity or a deeper cascade? 👇

⚠️ Not financial advice. Always manage your risk. 🛡️

🏷️ #BTC #LazarusGroup #Bitcoin #CryptoAlert #WhaleWatch

💣 🦈
🚨 $UPBIT FACES REGULATORY SHOCK — THE LIQUIDITY WALL COMING DOWN? 💥 The Financial Supervisory Service just dropped the first formal sanction step on Dunamu, Upbit’s operator, after the $30M Lazarus-linked hack in November 2025. Upbit covered $26M from its own reserves, but the legal void is now screaming louder. 📊 🔍 South Korea’s crypto market is the deepest onramp for retail liquidity. When the regulator starts squeezing the biggest exchange, expect order book depth to thin — whales will front-run the uncertainty. The proposed Digital Asset Basic Act could reshape how cybersecurity failures are penalized, shaking the very floor Korean traders stand on. 💬 Is this the start of a structural liquidity crunch in Asia’s largest crypto hub, or just another headline fizzling out? 👇 ⚠️ Not financial advice. Always manage your risk. 🛡️ 🏷️ #Upbit #SouthKorea #CryptoRegulation #LazarusGroup #Bitcoin 🎯 🦈
🚨 $UPBIT FACES REGULATORY SHOCK — THE LIQUIDITY WALL COMING DOWN? 💥

The Financial Supervisory Service just dropped the first formal sanction step on Dunamu, Upbit’s operator, after the $30M Lazarus-linked hack in November 2025. Upbit covered $26M from its own reserves, but the legal void is now screaming louder. 📊

🔍 South Korea’s crypto market is the deepest onramp for retail liquidity. When the regulator starts squeezing the biggest exchange, expect order book depth to thin — whales will front-run the uncertainty. The proposed Digital Asset Basic Act could reshape how cybersecurity failures are penalized, shaking the very floor Korean traders stand on.

💬 Is this the start of a structural liquidity crunch in Asia’s largest crypto hub, or just another headline fizzling out? 👇

⚠️ Not financial advice. Always manage your risk. 🛡️

🏷️ #Upbit #SouthKorea #CryptoRegulation #LazarusGroup #Bitcoin

🎯 🦈
​🚨 Security Alert: Record increase in cyber attacks on DeFi platforms ​A big shock for the crypto world! According to reports, operators linked to North Korea have stolen more than $500 million from DeFi platforms in less than three weeks. Their total crypto hacking has now reached an estimated $6.75 billion. ⚠️💸 ​Recent major hacks (Exploits): ​KelpDAO (April 18): Loss of about $290 million. According to forensic analysis, the Lazarus Group's 'TraderTraitor' group is behind it. ​Drift Protocol (April 1): Loss of about $286 million. According to Elliptic reports, the patterns of this hack are exactly the same as previous attacks by the DPRK (North Korea). ​Horrifying revelation: The 'Ketman Project' has revealed that nearly 100 North Korean operators are working inside various blockchain companies to carry out secret hacking. ​Important advice for investors: ​Keep your wallets safe: Use only reputable and audited DeFi protocols. ​Unusual activity: If you are investing in a project, be sure to check its security team and recent audit reports. ​Large holdings: Don't keep all your digital wealth on a single DeFi platform. ​This news is a reminder that security should be the top priority in the blockchain world. What do you think about these attacks? Should DeFi platforms adopt more stringent security protocols? Let us know your thoughts in the comments! 👇 ​Follow me for more market alerts and security updates! $BSB $ON $UAI ​#DeFi #CryptoSecurity #LazarusGroup BlockchainNews CryptoMarket DigitalAssets #cyberattack
​🚨 Security Alert: Record increase in cyber attacks on DeFi platforms

​A big shock for the crypto world! According to reports, operators linked to North Korea have stolen more than $500 million from DeFi platforms in less than three weeks. Their total crypto hacking has now reached an estimated $6.75 billion. ⚠️💸

​Recent major hacks (Exploits):

​KelpDAO (April 18): Loss of about $290 million. According to forensic analysis, the Lazarus Group's 'TraderTraitor' group is behind it.

​Drift Protocol (April 1): Loss of about $286 million. According to Elliptic reports, the patterns of this hack are exactly the same as previous attacks by the DPRK (North Korea).

​Horrifying revelation:

The 'Ketman Project' has revealed that nearly 100 North Korean operators are working inside various blockchain companies to carry out secret hacking.

​Important advice for investors:

​Keep your wallets safe: Use only reputable and audited DeFi protocols.

​Unusual activity: If you are investing in a project, be sure to check its security team and recent audit reports.

​Large holdings: Don't keep all your digital wealth on a single DeFi platform.

​This news is a reminder that security should be the top priority in the blockchain world. What do you think about these attacks? Should DeFi platforms adopt more stringent security protocols? Let us know your thoughts in the comments! 👇

​Follow me for more market alerts and security updates!

$BSB $ON $UAI

#DeFi #CryptoSecurity #LazarusGroup BlockchainNews CryptoMarket DigitalAssets #cyberattack
Article
Getting to Know Lazarus Group, the 'Cyber Military' Behind the World's Biggest Crypto HeistHey, Binance Square folks! Continuing our report on the staggering 1,140% surge in cyber attacks in April 2026, one name keeps dominating the headlines: Lazarus Group. But who are they really? Why are they so obsessed with DeFi? And who do they work for? Let's thoroughly dissect the profile of this hacking group that is now responsible for 76% of global cyber losses this year. 1. Who is the Lazarus Group? Lazarus Group (also known as APT38) is not some bunch of amateur hackers operating from a basement. They are an elite cyber unit that is highly organized and has military-level training.

Getting to Know Lazarus Group, the 'Cyber Military' Behind the World's Biggest Crypto Heist

Hey, Binance Square folks!
Continuing our report on the staggering 1,140% surge in cyber attacks in April 2026, one name keeps dominating the headlines: Lazarus Group.
But who are they really? Why are they so obsessed with DeFi? And who do they work for? Let's thoroughly dissect the profile of this hacking group that is now responsible for 76% of global cyber losses this year.
1. Who is the Lazarus Group?
Lazarus Group (also known as APT38) is not some bunch of amateur hackers operating from a basement. They are an elite cyber unit that is highly organized and has military-level training.
Article
🛡️ DeFi Apocalypse of April 2026: Why $800 million in losses is just the tip of the iceberg?April 2026 officially became the "bloodiest" month for the crypto industry. Total losses since the start of the year have already surpassed $800 million, and nearly all of that volume has occurred in the last 30 days. We're witnessing not just a series of hacks but a systemic crisis in the security of infrastructure and communications.

🛡️ DeFi Apocalypse of April 2026: Why $800 million in losses is just the tip of the iceberg?

April 2026 officially became the "bloodiest" month for the crypto industry. Total losses since the start of the year have already surpassed $800 million, and nearly all of that volume has occurred in the last 30 days.
We're witnessing not just a series of hacks but a systemic crisis in the security of infrastructure and communications.
Arkham Intelligence published a report examining Lazarus Group’s crypto laundering network and operational tactics between 2017 and 2026. According to the research, Lazarus-linked actors were tied to more than $6 billion in stolen cryptocurrency across exchange breaches, ransomware campaigns, bridge exploits, and decentralized finance attacks. Arkham said North Korean-linked actors accounted for more than 70% of crypto exploit losses recorded so far in 2026. The report described how Lazarus allegedly moves stolen assets through cross-chain bridges, mixers, centralized exchanges, OTC brokers, and fragmented wallet activity to complicate blockchain tracing efforts. THORChain was identified as a frequently used bridge for converting stolen assets into Bitcoin. Arkham also referenced mixers including Sinbad.io and YoMix, along with Russian exchanges and Chinese OTC brokers involved in cash-out activity. The research examined the April 2026 Drift Protocol ($DRIFT ) exploit, where attackers allegedly spent months building trust with employees through conferences, deposits exceeding $1 million, and fake partnership activity. Arkham said Lazarus later used pre-authorized Solana transactions to drain about $285 million from the protocol. The report also covered the February 2026 KelpDAO exploit. According to Arkham, attackers compromised LayerZero RPC nodes and forged cross-chain messages, allowing the withdrawal of 116,500 $rsETH valued at about $292 million. Arkham concluded that Lazarus continues adapting its laundering methods and attack strategies as blockchain tracing systems become more advanced. #arkham #DRIFT #KelpDAO #LazarusGroup #Lazarus
Arkham Intelligence published a report examining Lazarus Group’s crypto laundering network and operational tactics between 2017 and 2026.
According to the research, Lazarus-linked actors were tied to more than $6 billion in stolen cryptocurrency across exchange breaches, ransomware campaigns, bridge exploits, and decentralized finance attacks.
Arkham said North Korean-linked actors accounted for more than 70% of crypto exploit losses recorded so far in 2026.
The report described how Lazarus allegedly moves stolen assets through cross-chain bridges, mixers, centralized exchanges, OTC brokers, and fragmented wallet activity to complicate blockchain tracing efforts.
THORChain was identified as a frequently used bridge for converting stolen assets into Bitcoin. Arkham also referenced mixers including Sinbad.io and YoMix, along with Russian exchanges and Chinese OTC brokers involved in cash-out activity.
The research examined the April 2026 Drift Protocol ($DRIFT ) exploit, where attackers allegedly spent months building trust with employees through conferences, deposits exceeding $1 million, and fake partnership activity. Arkham said Lazarus later used pre-authorized Solana transactions to drain about $285 million from the protocol.
The report also covered the February 2026 KelpDAO exploit. According to Arkham, attackers compromised LayerZero RPC nodes and forged cross-chain messages, allowing the withdrawal of 116,500 $rsETH valued at about $292 million.
Arkham concluded that Lazarus continues adapting its laundering methods and attack strategies as blockchain tracing systems become more advanced.

#arkham #DRIFT #KelpDAO #LazarusGroup #Lazarus
🚨 DEFI EMERGENCY: The $292M Kelp DAO Exploit Explained! The Attack: A massive breach allowed hackers to mint 116,500 rsETH out of thin air. The Culprit: Initial reports link the attack to the Lazarus Group (North Korea). Contagion: Over 15 protocols (including Ethena and TRON DAO) have frozen their bridges to stop the bleeding. Stay Safe: If you hold rsETH, check your wallet immediately. Aave has already frozen these markets to protect users. 👉 Do follow for the latest DeFi security patches and safety tips! #KelpDAOFacesAttack #DeFiExploit #Web3Security #ETH #LazarusGroup $
🚨 DEFI EMERGENCY: The $292M Kelp DAO Exploit Explained!

The Attack: A massive breach allowed hackers to mint 116,500 rsETH out of thin air.

The Culprit: Initial reports link the attack to the Lazarus Group (North Korea).

Contagion: Over 15 protocols (including Ethena and TRON DAO) have frozen their bridges to stop the bleeding.

Stay Safe: If you hold rsETH, check your wallet immediately. Aave has already frozen these markets to protect users.

👉 Do follow for the latest DeFi security patches and safety tips!

#KelpDAOFacesAttack #DeFiExploit #Web3Security #ETH #LazarusGroup $
MicroStrategy has ultimately surpassed BlackRock, firmly securing the top position in global holdings; at the same time, the $175 million stolen funds from KelpDAO have started to move, pointing directly to the northern neighbor. Saylor's move is truly tough, overshadowing the world's largest asset management giant on a scale, indicating that the narrative of corporate reserve assets has outperformed the ETF channel. From a macro perspective, chips are further concentrating towards top-level will, and the long-term logic remains robust. However, the movement of this $175 million dirty money is like an emotional fly; although the actual selling pressure has limited impact on the overall market, the phrase "northern hacker" always tightens short-term liquidity. On one side is top-level compliant transparent holdings increase, and on the other side is top-level black industry discreetly cashing out, this flavor is just right, truly a magical realism of the cryptocurrency circle. How long do you think Saylor can lead this wave? #MicroStrategy #BlackRock #KelpDAO #LazarusGroup $BTC $MSTR {future}(MSTRUSDT) {future}(BTCUSDT)
MicroStrategy has ultimately surpassed BlackRock, firmly securing the top position in global holdings; at the same time, the $175 million stolen funds from KelpDAO have started to move, pointing directly to the northern neighbor.
Saylor's move is truly tough, overshadowing the world's largest asset management giant on a scale, indicating that the narrative of corporate reserve assets has outperformed the ETF channel. From a macro perspective, chips are further concentrating towards top-level will, and the long-term logic remains robust. However, the movement of this $175 million dirty money is like an emotional fly; although the actual selling pressure has limited impact on the overall market, the phrase "northern hacker" always tightens short-term liquidity. On one side is top-level compliant transparent holdings increase, and on the other side is top-level black industry discreetly cashing out, this flavor is just right, truly a magical realism of the cryptocurrency circle. How long do you think Saylor can lead this wave? #MicroStrategy #BlackRock #KelpDAO #LazarusGroup $BTC $MSTR
·
--
Security Alert: The Lazarus Group Strikes Again with a $290M Heist The crypto ecosystem is facing its biggest challenge so far in 2026. The infamous North Korean hacker group, Lazarus, is the prime suspect behind the massive attack that hit the investment platform KelpDAO this past weekend. Here are the key details of what went down: The Haul: Approximately $290 million in Ethereum-linked tokens. The Method: Two servers hosted through the LayerZero app were compromised, allowing for asset extraction on April 18th. The Impact: This solidifies itself as the largest recorded cryptocurrency cyberattack in 2026 to date. 🛡️ Why does it matter? Experts like Henri Arslanian from Nine Blocks Capital Management point out that the sophistication of the attack hints at state capabilities. According to UN reports, the stolen funds have a critical and alarming goal: to finance North Korea's nuclear weapons development program. Since 2017, this group is estimated to have stolen over $3 billion in digital assets. Fortunately, LayerZero has communicated that there is no contagion to other assets or applications on their network, but the incident reignites the debate on security in interoperability protocols and storage. Keep your assets safe and always verify the protocols where you trade. 🔒 #LazarusGroup #CryptoSecurity2025 #KelpDAO #Ethereum #SeguridadCripto $ETH $BTC $BNB {future}(ETHUSDT) {future}(BTCUSDT) {future}(BNBUSDT)
Security Alert: The Lazarus Group Strikes Again with a $290M Heist

The crypto ecosystem is facing its biggest challenge so far in 2026. The infamous North Korean hacker group, Lazarus, is the prime suspect behind the massive attack that hit the investment platform KelpDAO this past weekend.

Here are the key details of what went down:

The Haul: Approximately $290 million in Ethereum-linked tokens.

The Method: Two servers hosted through the LayerZero app were compromised, allowing for asset extraction on April 18th.

The Impact: This solidifies itself as the largest recorded cryptocurrency cyberattack in 2026 to date.

🛡️ Why does it matter?

Experts like Henri Arslanian from Nine Blocks Capital Management point out that the sophistication of the attack hints at state capabilities. According to UN reports, the stolen funds have a critical and alarming goal: to finance North Korea's nuclear weapons development program.

Since 2017, this group is estimated to have stolen over $3 billion in digital assets.

Fortunately, LayerZero has communicated that there is no contagion to other assets or applications on their network, but the incident reignites the debate on security in interoperability protocols and storage.

Keep your assets safe and always verify the protocols where you trade. 🔒

#LazarusGroup #CryptoSecurity2025 #KelpDAO #Ethereum #SeguridadCripto

$ETH $BTC $BNB
·
--
Article
$606 Million Stolen in 18 Days. April 2026 Is Already the Worst Month for Crypto Hacks Since Bybit.While markets were watching $79,000 and the Iran ceasefire, something else happened in April that deserves serious attention.Crypto protocols lost over $606 million to hacks in just 18 days of April 2026, making it the worst month since February 2025's Bybit breach. The entire first quarter of 2026 saw $165.5 million in losses across a relatively quiet stretch. April's $606 million total arrived in under three weeks, making the month 3.7 times larger than Q1 combined and pushing 2026's year-to-date theft total to approximately $771.8 million across 47 separate incidents. Two exploits account for nearly all of it. The $285 million Drift Protocol attack on April 1, later attributed to North Korea's Lazarus Group, and the $292 million KelpDAO breach on April 18, also linked to Lazarus, together represent roughly 95% of the month's losses and approximately 75% of everything stolen in crypto in 2026 so far. The same state-sponsored hacking group behind both attacks. Different protocols. Different chains. Different vulnerability types. Same attacker.Beyond the dollar totals, the pace of attacks is accelerating in a way that concerns security researchers as much as the individual incident sizes. DeFi recorded 47 separate incidents in the first four and a half months of 2026, compared with 28 over the same period in 2025, a 68% year-over-year increase in attack frequency. The diversification of attack vectors means that technical audits and code reviews alone are no longer sufficient protection for protocols with significant TVL. This is the part that most coverage misses. It's not just the dollar amounts. It's the shift in how protocols are being attacked. April's exploits cut across smart contract vulnerabilities, infrastructure attacks, and social engineering campaigns, including AI-driven attacks on wallets like Zerion. As crypto's cumulative hack losses have crossed $17 billion over the past decade, attackers are increasingly pivoting away from smart contract bugs toward private keys, signing infrastructure, and human-layer social engineering. AI-driven social engineering attacks. That's new and it's serious. As protocols hardened their smart contract code through multiple audits, sophisticated attackers evolved to target the humans operating the infrastructure — developers with admin keys, bridge operators, multisig signers.Jefferies has warned the string of marquee hacks could temporarily slow Wall Street's appetite for DeFi tokenization projects. PowerDrillThis is where the institutional story intersects with the security story. BlackRock, Morgan Stanley, Stripe — they're all building infrastructure on or adjacent to DeFi rails. If $600M+ can be stolen in 18 days from protocols that were considered secure, institutional risk departments need new frameworks before they commit more capital."DeFi remains a niche market until risk can be properly priced," one analyst wrote. That's the honest state of things. The technology is powerful. The security model isn't mature enough for the capital it's trying to hold. Both things are true simultaneously. #CryptoHacks #DeFiSecurity #LazarusGroup #KelpDAO #CryptoSecurity

$606 Million Stolen in 18 Days. April 2026 Is Already the Worst Month for Crypto Hacks Since Bybit.

While markets were watching $79,000 and the Iran ceasefire, something else happened in April that deserves serious attention.Crypto protocols lost over $606 million to hacks in just 18 days of April 2026, making it the worst month since February 2025's Bybit breach. The entire first quarter of 2026 saw $165.5 million in losses across a relatively quiet stretch. April's $606 million total arrived in under three weeks, making the month 3.7 times larger than Q1 combined and pushing 2026's year-to-date theft total to approximately $771.8 million across 47 separate incidents.
Two exploits account for nearly all of it. The $285 million Drift Protocol attack on April 1, later attributed to North Korea's Lazarus Group, and the $292 million KelpDAO breach on April 18, also linked to Lazarus, together represent roughly 95% of the month's losses and approximately 75% of everything stolen in crypto in 2026 so far.
The same state-sponsored hacking group behind both attacks. Different protocols. Different chains. Different vulnerability types. Same attacker.Beyond the dollar totals, the pace of attacks is accelerating in a way that concerns security researchers as much as the individual incident sizes. DeFi recorded 47 separate incidents in the first four and a half months of 2026, compared with 28 over the same period in 2025, a 68% year-over-year increase in attack frequency. The diversification of attack vectors means that technical audits and code reviews alone are no longer sufficient protection for protocols with significant TVL.
This is the part that most coverage misses. It's not just the dollar amounts. It's the shift in how protocols are being attacked. April's exploits cut across smart contract vulnerabilities, infrastructure attacks, and social engineering campaigns, including AI-driven attacks on wallets like Zerion. As crypto's cumulative hack losses have crossed $17 billion over the past decade, attackers are increasingly pivoting away from smart contract bugs toward private keys, signing infrastructure, and human-layer social engineering.
AI-driven social engineering attacks. That's new and it's serious. As protocols hardened their smart contract code through multiple audits, sophisticated attackers evolved to target the humans operating the infrastructure — developers with admin keys, bridge operators, multisig signers.Jefferies has warned the string of marquee hacks could temporarily slow Wall Street's appetite for DeFi tokenization projects. PowerDrillThis is where the institutional story intersects with the security story. BlackRock, Morgan Stanley, Stripe — they're all building infrastructure on or adjacent to DeFi rails. If $600M+ can be stolen in 18 days from protocols that were considered secure, institutional risk departments need new frameworks before they commit more capital."DeFi remains a niche market until risk can be properly priced," one analyst wrote.
That's the honest state of things. The technology is powerful. The security model isn't mature enough for the capital it's trying to hold. Both things are true simultaneously.
#CryptoHacks #DeFiSecurity #LazarusGroup #KelpDAO #CryptoSecurity
🚨 Major Legal Precedent for DAOs 🚨 A New York federal court has ordered Arbitrum DAO to freeze $71M in ETH seized from the recent Kelp DAO hack. The twist? The money isn't going back to the hack victims yet. Instead, victims of North Korean state terrorism are claiming it to settle a massive 2015 judgment against Pyongyang. ⚖️ Key Takeaways: 🔹 Lazarus Group Link: The funds are tied to North Korean hackers, making them a target for legal garnishment. 🔹 DAO as a "Partnership": The court is treating Arbitrum DAO as a liable entity, warning that Security Council members could face personal liability if they move the ETH. 🔹 Compensation Clash: Plans by Aave & Kelp DAO to refund exploit victims are now stalled by this US court order. This case marks a major shift in how US courts interact with "decentralized" governance. Is "Code is Law" officially meeting its match in federal court? #Arbitrum #KelpDAO #DeFi #CryptoNews #LazarusGroup #Ethereum $BTC {future}(BTCUSDT) $ETH {future}(ETHUSDT) $BNB {future}(BNBUSDT)
🚨 Major Legal Precedent for DAOs 🚨
A New York federal court has ordered Arbitrum DAO to freeze $71M in ETH seized from the recent Kelp DAO hack.
The twist? The money isn't going back to the hack victims yet. Instead, victims of North Korean state terrorism are claiming it to settle a massive 2015 judgment against Pyongyang. ⚖️
Key Takeaways:
🔹 Lazarus Group Link: The funds are tied to North Korean hackers, making them a target for legal garnishment.
🔹 DAO as a "Partnership": The court is treating Arbitrum DAO as a liable entity, warning that Security Council members could face personal liability if they move the ETH.
🔹 Compensation Clash: Plans by Aave & Kelp DAO to refund exploit victims are now stalled by this US court order.
This case marks a major shift in how US courts interact with "decentralized" governance. Is "Code is Law" officially meeting its match in federal court?
#Arbitrum #KelpDAO #DeFi #CryptoNews #LazarusGroup #Ethereum
$BTC
$ETH
$BNB
Article
Warning! Crypto Cyber Attacks Surge 1,140% in April 2026: Real Threat from the Lazarus GroupHello, Binance Square folks! April 2026 is recorded as one of the darkest months in the history of digital asset security. The latest data shows a concerning surge in exploits, serving as a strong warning to all of us that the crypto ecosystem remains a highly active cyber battlefield. Scary Stats: 1,140% Surge Last April logged a grim record with a total of 40 major exploits hitting various protocols. The total loss reached a jaw-dropping figure: US$646.89 million.

Warning! Crypto Cyber Attacks Surge 1,140% in April 2026: Real Threat from the Lazarus Group

Hello, Binance Square folks!
April 2026 is recorded as one of the darkest months in the history of digital asset security. The latest data shows a concerning surge in exploits, serving as a strong warning to all of us that the crypto ecosystem remains a highly active cyber battlefield.
Scary Stats: 1,140% Surge
Last April logged a grim record with a total of 40 major exploits hitting various protocols. The total loss reached a jaw-dropping figure: US$646.89 million.
🚨 Kelp DAO: The $292M Shadow Attack Unveiled! 📉⚔️ The full post-mortem on the Kelp DAO ($rs$ETH ) exploit is in, and it’s being called the most sophisticated "infrastructure poisoning" in DeFi history. On April 18, 2026, the Lazarus Group (TraderTraitor sub-group) successfully bypassed on-chain security by attacking the "plumbing" of the network. 📊 The "Heist" Final Count Total Drain: 116,500 rsETH (~$292 Million) released in a single block. Intercepted: 40,000 rsETH (~$95 Million) second attempt BLOCKED by Kelp’s emergency pause. Recovered: ~30,766 ETH (~$71 Million) frozen by the Arbitrum Security Council. Market Shock: Aave TVL plummeted $8 Billion as utilization hit 100% during the panic. 🔍 The "Invisible" Hack: The 1-of-1 Trap: Kelp relied on a single LayerZero verifier. Lazarus didn't hack the code; they isolated the verifier in a "data echo chamber." RPC Poisoning: The attackers compromised two internal RPC nodes and launched a massive DDoS attack on all external backups. The Phantom Burn: The verifier was fed fake data showing rsETH had been burned on a source chain. It "verified" a lie, and the Ethereum contract released the funds perfectly legally. Self-Destructing Malware: The malicious code wiped all logs and binaries from the infected nodes the moment the drain was complete. 📈 Current Market Recovery: $rsETH Peg: The token is under-collateralized on 20+ chains. Kelp is working on a recovery contract to buy back and burn supply using recovered and treasury funds. Institutional Shift: This hack is the "smoking gun" for the CLARITY Act in the Senate, with Coinbase and others reaching deals to mandate multi-verifier security standards. The "Lazarus" Loop: The attacker deposited stolen funds into Aave as collateral to borrow $195M in WETH, creating a massive debt scenario that the community is now unwinding. #KelpDAO #rsETH #LazarusGroup #DeFiSecurity #Aave #Arbitrum #BinanceSquare #CryptoNews2026 {future}(ETHUSDT)
🚨 Kelp DAO: The $292M Shadow Attack Unveiled! 📉⚔️

The full post-mortem on the Kelp DAO ($rs$ETH ) exploit is in, and it’s being called the most sophisticated "infrastructure poisoning" in DeFi history. On April 18, 2026, the Lazarus Group (TraderTraitor sub-group) successfully bypassed on-chain security by attacking the "plumbing" of the network.

📊 The "Heist" Final Count

Total Drain: 116,500 rsETH (~$292 Million) released in a single block.

Intercepted: 40,000 rsETH (~$95 Million) second attempt BLOCKED by Kelp’s emergency pause.

Recovered: ~30,766 ETH (~$71 Million) frozen by the Arbitrum Security Council.

Market Shock: Aave TVL plummeted $8 Billion as utilization hit 100% during the panic.

🔍 The "Invisible" Hack:

The 1-of-1 Trap: Kelp relied on a single LayerZero verifier. Lazarus didn't hack the code; they isolated the verifier in a "data echo chamber."

RPC Poisoning: The attackers compromised two internal RPC nodes and launched a massive DDoS attack on all external backups.

The Phantom Burn: The verifier was fed fake data showing rsETH had been burned on a source chain. It "verified" a lie, and the Ethereum contract released the funds perfectly legally.

Self-Destructing Malware: The malicious code wiped all logs and binaries from the infected nodes the moment the drain was complete.

📈 Current Market Recovery:

$rsETH Peg: The token is under-collateralized on 20+ chains. Kelp is working on a recovery contract to buy back and burn supply using recovered and treasury funds.

Institutional Shift: This hack is the "smoking gun" for the CLARITY Act in the Senate, with Coinbase and others reaching deals to mandate multi-verifier security standards.

The "Lazarus" Loop: The attacker deposited stolen funds into Aave as collateral to borrow $195M in WETH, creating a massive debt scenario that the community is now unwinding.

#KelpDAO #rsETH #LazarusGroup #DeFiSecurity #Aave #Arbitrum #BinanceSquare #CryptoNews2026
Article
🚨 BREAKING: NORTH KOREA JUST STOLE $577M FROM DEFI IN 18 DAYS — AND NOBODY IS TALKING ABOUT......April 23, 2026 The numbers are in. They are catastrophic. Crypto protocols have lost over $606 million to hacks and exploits in just the first 18 days of April 2026 making it the single worst month for theft in the industry since the $1.4 billion Bybit breach in February 2025. Two attacks. Two names. Both point to the same culprit. 🔴 WHAT HAPPENED The $285 million Drift Protocol attack on April 1st, and the $292 million KelpDAO breach on April 18th both later attributed to North Korea’s Lazarus Group together represent roughly 95% of April’s losses. This wasn’t random. This was surgical. Following the KelpDAO exploit alone, DeFi’s total value locked fell over 7% in 24 hours. Aave dropped from $26.4 billion to near $17.9 billion. Billions. Gone. Overnight. 🔥 WHY IT MATTERS This isn’t just a bad month. The entire first quarter of 2026 saw just $165.5 million in losses. April’s total arrived in under three weeks making the month 3.7× larger than all of Q1 combined. The pace is accelerating dangerously. DeFi recorded 47 separate incidents in the first 4.5 months of 2026, compared with 28 over the same period in 2025 a 68% year-over-year increase in attack frequency. 📉 MARKET REACTION Panic. Institutional players are not waiting around. Institutional players responded with emergency rate limits and frozen bridge flows, while Jefferies warned the string of hacks could temporarily slow Wall Street’s appetite for DeFi tokenization projects. $BTC is holding. Alts are bleeding. Risk-off mode is fully activated. ⚠️ MOST PEOPLE ARE MISSING THIS DETAIL… Everyone is focused on the dollar amounts. But the real story is HOW they’re getting in. April’s exploits cut across smart contract vulnerabilities, infrastructure attacks, AND social engineering campaigns including AI-driven attacks on wallets. The old playbook of “just get your code audited” is dead. Lazarus Group is now deploying AI to target individuals. Your wallet. Your team. Your infra. As one analyst put it bluntly: “DeFi remains a niche market until risk can be properly priced and right now, we’re far from it.” 🔮 WHAT HAPPENS NEXT If even one more mid-size exploit hits before April 30th, the month’s total could approach $700 million. The Clarity Act which could bring regulatory structure to protect DeFi looks like a lost cause for April, with a potential Senate committee hearing pushed into May at the earliest. Meanwhile, the attackers are not slowing down. The question isn’t whether your protocol will be targeted. It’s whether you’ll still be solvent when it is. 🔒 #defi #KelpDAO #LazarusGroup #CryptoSecurity #BinanceSquare

🚨 BREAKING: NORTH KOREA JUST STOLE $577M FROM DEFI IN 18 DAYS — AND NOBODY IS TALKING ABOUT......

April 23, 2026
The numbers are in. They are catastrophic.
Crypto protocols have lost over $606 million to hacks and exploits in just the first 18 days of April 2026 making it the single worst month for theft in the industry since the $1.4 billion Bybit breach in February 2025.
Two attacks. Two names. Both point to the same culprit.

🔴 WHAT HAPPENED
The $285 million Drift Protocol attack on April 1st, and the $292 million KelpDAO breach on April 18th both later attributed to North Korea’s Lazarus Group together represent roughly 95% of April’s losses.
This wasn’t random. This was surgical.
Following the KelpDAO exploit alone, DeFi’s total value locked fell over 7% in 24 hours. Aave dropped from $26.4 billion to near $17.9 billion. Billions. Gone. Overnight.

🔥 WHY IT MATTERS
This isn’t just a bad month. The entire first quarter of 2026 saw just $165.5 million in losses. April’s total arrived in under three weeks making the month 3.7× larger than all of Q1 combined.
The pace is accelerating dangerously. DeFi recorded 47 separate incidents in the first 4.5 months of 2026, compared with 28 over the same period in 2025 a 68% year-over-year increase in attack frequency.

📉 MARKET REACTION
Panic. Institutional players are not waiting around. Institutional players responded with emergency rate limits and frozen bridge flows, while Jefferies warned the string of hacks could temporarily slow Wall Street’s appetite for DeFi tokenization projects.
$BTC is holding. Alts are bleeding. Risk-off mode is fully activated.

⚠️ MOST PEOPLE ARE MISSING THIS DETAIL…
Everyone is focused on the dollar amounts. But the real story is HOW they’re getting in.
April’s exploits cut across smart contract vulnerabilities, infrastructure attacks, AND social engineering campaigns including AI-driven attacks on wallets. The old playbook of “just get your code audited” is dead.
Lazarus Group is now deploying AI to target individuals. Your wallet. Your team. Your infra.
As one analyst put it bluntly: “DeFi remains a niche market until risk can be properly priced and right now, we’re far from it.”

🔮 WHAT HAPPENS NEXT
If even one more mid-size exploit hits before April 30th, the month’s total could approach $700 million.
The Clarity Act which could bring regulatory structure to protect DeFi looks like a lost cause for April, with a potential Senate committee hearing pushed into May at the earliest.
Meanwhile, the attackers are not slowing down.

The question isn’t whether your protocol will be targeted.
It’s whether you’ll still be solvent when it is. 🔒
#defi #KelpDAO #LazarusGroup #CryptoSecurity #BinanceSquare
Article
The KelpDAO bridge exploit (April 18–22, 2026)has become a defining case study in systemic DeFi risk. Here is the expanded intelligence on the laundering operation, the Aave liquidity collapse, and the specific security failures involved.  1. The Laundering: A Masterclass in Cross-Chain Speed The exploiter, linked to North Korea’s Lazarus Group, executed a highly efficient exit strategy after minting 116,500 rsETH (approx. $292M) out of thin air via a message-forgery attack.  • THORChain as a Black Box: Within 36 hours of the hack, the attackers routed nearly 75,700 ETH ($175M) through THORChain, swapping it directly into Native Bitcoin. By utilizing THORChain’s permissionless, non-custodial nodes, they successfully bypassed centralized exchange (CEX) freezes and mixed the funds before the Bitcoin rally to $78,400.  • The Arbitrum "Stumble": The only significant recovery occurred on April 21, when the Arbitrum Security Council used emergency intervention powers to freeze 30,766 ETH ($71M) held on the Arbitrum One network. This was a "jurisdictional" win: while the council could "steal back" the funds on their Layer 2, they had no power over the remaining $175M on Ethereum Mainnet.  • Privacy Layer: Small portions of the loot (approx. $78,000) were also detected moving through the Umbra privacy protocol to obscure the digital trail further.  2. Aave's $16B "Ghost" Crisis Aave’s TVL didn't just drop; it underwent a structural liquidity collapse. Although Aave’s core smart contracts remained secure, the protocol’s risk management was weaponized by the hacker.  • Bad Debt Mechanics: The hacker deposited the unbacked rsETH into Aave V3 as collateral to borrow $190M in WETH and other assets. Because the rsETH had no real value, Aave was left with an estimated $196M to $230M in bad debt once the KelpDAO bridge was confirmed compromised.  • The 100% Utilization Trap: As whales and institutions (including Justin Sun) scrambled to withdraw, the WETH and USDT markets hit 100% utilization. This meant many regular depositors were effectively locked in, unable to withdraw their funds because the pools were completely drained by the panic.  • Flight to Quality: Over $1.3B of the withdrawn capital immediately rotated into SparkLend and other "hard" collateral protocols, signaling a massive loss of faith in Liquid Restaking Tokens (LRTs) as viable collateral.  3. Bridge Security: The "1-of-1" Single Point of Failure The post-mortem from Chainalysis and LayerZero Labs revealed that this was not a code bug, but an infrastructure takeover.  • The RPC Compromise: Lazarus Group didn't hack the smart contracts. Instead, they compromised the internal RPC nodes used by the LayerZero Decentralized Verifier Network (DVN). They fed forged data to the verifier while simultaneously launching a DDoS attack on external nodes to prevent them from "correcting" the lie.  • The 1-of-1 Configuration: A major public feud erupted between KelpDAO and LayerZero. LayerZero revealed that KelpDAO had used a 1-of-1 DVN setup—meaning only one verifier needed to be fooled to release the bridge funds.  • Lazarus Sophistication: The malware used on the RPC nodes was engineered to self-destruct and wipe all logs/binaries once the $292M was released, leaving investigators with a "cold" digital crime scene.  The Bottom Line for 2026 This event confirms that while on-chain code is getting safer, off-chain infrastructure (RPCs/Oracles) and cross-chain verifier configurations are now the primary targets. The "Kelp Contagion" has forced a massive industry-wide shift toward Multi-Sig DVNs and lower LTVs for restaked assets. 🛡️🌉📉  #KelpDAO #Aave #LazarusGroup #DefiExploits #BridgeSecurity #Arbitrum #THORChain Complete Laundering Operation The KelpDAO exploiter swapped nearly all 75,700 stolen ETH (worth $175M) into Bitcoin through THORChain in just 36 hours, narrowing recovery to only Arbitrum's frozen portion. DeFi Contagion Spreads Aave TVL collapsed from $45.8B to $29.6B, losing $16.2B in deposits as the exploit created $230M bad debt and triggered panic withdrawals across protocols with no direct exposure. Bridge Security Crisis LayerZero attributed the attack to North Korea's Lazarus Group, highlighting cross-chain bridges remain the weakest link with 2026 exploit losses matching 2025 levels.$ETH {spot}(ETHUSDT)

The KelpDAO bridge exploit (April 18–22, 2026)

has become a defining case study in systemic DeFi risk. Here is the expanded intelligence on the laundering operation, the Aave liquidity collapse, and the specific security failures involved.
1. The Laundering: A Masterclass in Cross-Chain Speed
The exploiter, linked to North Korea’s Lazarus Group, executed a highly efficient exit strategy after minting 116,500 rsETH (approx. $292M) out of thin air via a message-forgery attack.
• THORChain as a Black Box: Within 36 hours of the hack, the attackers routed nearly 75,700 ETH ($175M) through THORChain, swapping it directly into Native Bitcoin. By utilizing THORChain’s permissionless, non-custodial nodes, they successfully bypassed centralized exchange (CEX) freezes and mixed the funds before the Bitcoin rally to $78,400.
• The Arbitrum "Stumble": The only significant recovery occurred on April 21, when the Arbitrum Security Council used emergency intervention powers to freeze 30,766 ETH ($71M) held on the Arbitrum One network. This was a "jurisdictional" win: while the council could "steal back" the funds on their Layer 2, they had no power over the remaining $175M on Ethereum Mainnet.
• Privacy Layer: Small portions of the loot (approx. $78,000) were also detected moving through the Umbra privacy protocol to obscure the digital trail further.
2. Aave's $16B "Ghost" Crisis
Aave’s TVL didn't just drop; it underwent a structural liquidity collapse. Although Aave’s core smart contracts remained secure, the protocol’s risk management was weaponized by the hacker.
• Bad Debt Mechanics: The hacker deposited the unbacked rsETH into Aave V3 as collateral to borrow $190M in WETH and other assets. Because the rsETH had no real value, Aave was left with an estimated $196M to $230M in bad debt once the KelpDAO bridge was confirmed compromised.
• The 100% Utilization Trap: As whales and institutions (including Justin Sun) scrambled to withdraw, the WETH and USDT markets hit 100% utilization. This meant many regular depositors were effectively locked in, unable to withdraw their funds because the pools were completely drained by the panic.
• Flight to Quality: Over $1.3B of the withdrawn capital immediately rotated into SparkLend and other "hard" collateral protocols, signaling a massive loss of faith in Liquid Restaking Tokens (LRTs) as viable collateral.
3. Bridge Security: The "1-of-1" Single Point of Failure
The post-mortem from Chainalysis and LayerZero Labs revealed that this was not a code bug, but an infrastructure takeover.
• The RPC Compromise: Lazarus Group didn't hack the smart contracts. Instead, they compromised the internal RPC nodes used by the LayerZero Decentralized Verifier Network (DVN). They fed forged data to the verifier while simultaneously launching a DDoS attack on external nodes to prevent them from "correcting" the lie.
• The 1-of-1 Configuration: A major public feud erupted between KelpDAO and LayerZero. LayerZero revealed that KelpDAO had used a 1-of-1 DVN setup—meaning only one verifier needed to be fooled to release the bridge funds.
• Lazarus Sophistication: The malware used on the RPC nodes was engineered to self-destruct and wipe all logs/binaries once the $292M was released, leaving investigators with a "cold" digital crime scene.
The Bottom Line for 2026
This event confirms that while on-chain code is getting safer, off-chain infrastructure (RPCs/Oracles) and cross-chain verifier configurations are now the primary targets. The "Kelp Contagion" has forced a massive industry-wide shift toward Multi-Sig DVNs and lower LTVs for restaked assets. 🛡️🌉📉
#KelpDAO #Aave #LazarusGroup #DefiExploits #BridgeSecurity #Arbitrum #THORChain
Complete Laundering Operation
The KelpDAO exploiter swapped nearly all 75,700 stolen ETH (worth $175M) into Bitcoin through THORChain in just 36 hours, narrowing recovery to only Arbitrum's frozen portion.
DeFi Contagion Spreads
Aave TVL collapsed from $45.8B to $29.6B, losing $16.2B in deposits as the exploit created $230M bad debt and triggered panic withdrawals across protocols with no direct exposure.
Bridge Security Crisis
LayerZero attributed the attack to North Korea's Lazarus Group, highlighting cross-chain bridges remain the weakest link with 2026 exploit losses matching 2025 levels.$ETH
$292M GONE: THE DEFI CONTAGION 🚨 The KelpDAO exploit is officially the largest DeFi theft of 2026. Hackers are using THORChain to swap stolen $ETH for $BTC , leaving a massive trail of chaos. Arbitrum froze $75M, but the rest is disappearing into the void. This isn't just one protocol—it’s a systemic failure. Are we witnessing the "Death of Interoperability"? Be careful where you deposit your assets! #KelpDAO #DeFiHack #Security #Alert #LazarusGroup
$292M GONE: THE DEFI CONTAGION 🚨

The KelpDAO exploit is officially the largest DeFi theft of 2026. Hackers are using THORChain to swap stolen $ETH for $BTC , leaving a massive trail of chaos. Arbitrum froze $75M, but the rest is disappearing into the void.

This isn't just one protocol—it’s a systemic failure. Are we witnessing the "Death of Interoperability"? Be careful where you deposit your assets!

#KelpDAO #DeFiHack #Security #Alert #LazarusGroup
·
--
Article
The US Just Seized Nearly $500 Million in Iranian Crypto. North Korea's Lazarus Group Is Behind 76%Two law enforcement actions dropped this week that, combined, reveal something important about where crypto sits in the global geopolitical order. This is no longer a story about financial fraud. This is state-level warfare being conducted through digital assets.The US seized nearly $500 million in Iranian crypto.The US says it seized nearly $500 million in Iranian crypto assets. This is part of the broader financial campaign against Iran running parallel to the Strait of Hormuz conflict. The IRGC and affiliated entities have been using crypto — Bitcoin, USDT, and Ethereum — to route payments outside the SWIFT system, pay for imports under sanctions, and compensate assets in ways that traditional financial monitoring can't easily track. CointelegraphThe seizure happened simultaneously with an FBI-led global operation that arrested 276 suspects in pig butchering schemes — an FBI-led global enforcement effort targeting crypto pig butchering schemes led to the arrest of 276 suspects. Pig butchering is the social engineering scam where targets are cultivated over weeks or months through fake romantic relationships before being manipulated into depositing crypto into fraudulent investment platforms. CointelegraphNorth Korea's Lazarus Group: 76% of all 2026 losses, $6B stolen since 2017.The security intelligence research firm said North Korean state-backed hackers account for 76% of all crypto scam and hack losses in 2026 and have stolen $6 billion since 2017. New reporting this week on the Drift Protocol hack revealed the full scope of how Lazarus operates. The long con: North Korean spies spent months in-person to drain $285 million from Drift — the security intelligence research firm detailed how North Korean state-backed hackers infiltrated Drift through months of preparation, including suspected physical presence of operatives near the company's operations, before executing the exploit on April 1. Months of in-person preparation. This isn't a lone hacker running code from a basement. This is a structured, state-funded operation with the same discipline as any military intelligence unit — because that's exactly what it is. North Korea funds a significant portion of its weapons programs through crypto theft. The $577 million stolen in 2026 is not a side project. It's a strategic revenue source. PowerDrillPowerDrillThe picture this paints of crypto's global status in 2026: Iran uses crypto to evade sanctions. The US uses blockchain forensics to trace and seize those assets. North Korea steals crypto at industrial scale to fund its military. South Korea's FISA is monitoring DeFi protocols for state-linked wallets.Bitcoin was designed to be censorship-resistant and permissionless. What nobody anticipated when Satoshi wrote the whitepaper was that "permissionless" would eventually mean "accessible to every actor on earth" — including the ones building nuclear weapons and circumventing global financial sanctions.This doesn't change the fundamental value of decentralized money. But it changes how we need to think about the security, regulation, and geopolitical context of the ecosystem we're all participating in. #Bitcoin #LazarusGroup #CryptoSecurity #NorthKorea #IranSanctions

The US Just Seized Nearly $500 Million in Iranian Crypto. North Korea's Lazarus Group Is Behind 76%

Two law enforcement actions dropped this week that, combined, reveal something important about where crypto sits in the global geopolitical order. This is no longer a story about financial fraud. This is state-level warfare being conducted through digital assets.The US seized nearly $500 million in Iranian crypto.The US says it seized nearly $500 million in Iranian crypto assets. This is part of the broader financial campaign against Iran running parallel to the Strait of Hormuz conflict. The IRGC and affiliated entities have been using crypto — Bitcoin, USDT, and Ethereum — to route payments outside the SWIFT system, pay for imports under sanctions, and compensate assets in ways that traditional financial monitoring can't easily track. CointelegraphThe seizure happened simultaneously with an FBI-led global operation that arrested 276 suspects in pig butchering schemes — an FBI-led global enforcement effort targeting crypto pig butchering schemes led to the arrest of 276 suspects. Pig butchering is the social engineering scam where targets are cultivated over weeks or months through fake romantic relationships before being manipulated into depositing crypto into fraudulent investment platforms. CointelegraphNorth Korea's Lazarus Group: 76% of all 2026 losses, $6B stolen since 2017.The security intelligence research firm said North Korean state-backed hackers account for 76% of all crypto scam and hack losses in 2026 and have stolen $6 billion since 2017.
New reporting this week on the Drift Protocol hack revealed the full scope of how Lazarus operates. The long con: North Korean spies spent months in-person to drain $285 million from Drift — the security intelligence research firm detailed how North Korean state-backed hackers infiltrated Drift through months of preparation, including suspected physical presence of operatives near the company's operations, before executing the exploit on April 1.
Months of in-person preparation. This isn't a lone hacker running code from a basement. This is a structured, state-funded operation with the same discipline as any military intelligence unit — because that's exactly what it is. North Korea funds a significant portion of its weapons programs through crypto theft. The $577 million stolen in 2026 is not a side project. It's a strategic revenue source. PowerDrillPowerDrillThe picture this paints of crypto's global status in 2026: Iran uses crypto to evade sanctions. The US uses blockchain forensics to trace and seize those assets. North Korea steals crypto at industrial scale to fund its military. South Korea's FISA is monitoring DeFi protocols for state-linked wallets.Bitcoin was designed to be censorship-resistant and permissionless. What nobody anticipated when Satoshi wrote the whitepaper was that "permissionless" would eventually mean "accessible to every actor on earth" — including the ones building nuclear weapons and circumventing global financial sanctions.This doesn't change the fundamental value of decentralized money. But it changes how we need to think about the security, regulation, and geopolitical context of the ecosystem we're all participating in.
#Bitcoin #LazarusGroup #CryptoSecurity #NorthKorea #IranSanctions
Log in to explore more content
Join global crypto users on Binance Square
⚡️ Get latest and useful information about crypto.
💬 Trusted by the world’s largest crypto exchange.
👍 Discover real insights from verified creators.
Email / Phone number