NEAR Intents (NEAR ecosystem cross-chain protocol) had the stolen funds first sent to KuCoin (KuCoin), and then bridged into BTC. The attacker’s address also interacted with an address marked as belonging to the Lazarus Group (North Korean hacking organization): 0x098B7...E2f96.

These are the only confirmed details. The amounts haven’t been disclosed, and it’s still unknown whether KuCoin blocked anything or where the BTC ended up.

A single interaction at most shows that two addresses had contact; you can’t directly conclude that Lazarus was the one carrying out the operation.

Next, monitor two things: whether that Lazarus-labeled address will continue to receive same-source funds, and whether the BTC corresponding to KuCoin’s deposit address will continue to be withdrawn.