Binance Square
#lazarus

lazarus

444,189 views
88 Discussing
Crypto earn110
·
--
💥 Lazarus Group is Cooking Crypto in 2026 ⚠️ North Korean hackers just dropped some of the biggest exploits this year: Drift Protocol → $285M Kelp DAO → $292M Their Dirty Tactics: Fake job offers & deepfake calls 😈 Malware on dev laptops to steal keys Bridge exploits & fake collateral plays They plan attacks for months... super patient & dangerous. Stay Safe Kings: Hardware wallet only Never share seed/private keys Double-check every link & file Projects need better security ASAP! You teaming up against Lazarus or still clicking random links? 😂👇 #Lazarus #cryptohacks #CryptoSecurity #BinanceSquare
💥 Lazarus Group is Cooking Crypto in 2026 ⚠️
North Korean hackers just dropped some of the biggest exploits this year:
Drift Protocol → $285M
Kelp DAO → $292M
Their Dirty Tactics:
Fake job offers & deepfake calls 😈
Malware on dev laptops to steal keys
Bridge exploits & fake collateral plays
They plan attacks for months... super patient & dangerous.
Stay Safe Kings:
Hardware wallet only
Never share seed/private keys
Double-check every link & file
Projects need better security ASAP!
You teaming up against Lazarus or still clicking random links? 😂👇

#Lazarus #cryptohacks #CryptoSecurity #BinanceSquare
It was a routine transfer. February 20, 2025. A Bybit employee opens his screen, checks the transaction details, and signs. Everything looks normal. Minutes later, $1.5 billion $USDT in Ethereum had vanished. But the most terrifying part isn’t the amount. The most terrifying part is how they did it. The elite North Korean government hackers of the Lazarus Group didn’t attack the blockchain. They didn’t break any private keys. They didn’t need any of that. They simply… falsified what the employee saw on the screen. Months earlier, they infiltrated the system of a Safe Wallet developer—the platform Bybit used to sign transactions. They injected a malicious code that slept quietly, waiting. When the employee opened his wallet that day, the code activated. The screen showed a legitimate transfer. In reality, the funds were going to Pyongyang. The employee signed. His coworkers signed. Nobody saw anything unusual. Two minutes after the theft, the malicious code deleted itself. No trace. It took the FBI days to confirm what everyone already suspected: it was North Korea, using stolen Ethereum to fund its nuclear weapons program. The lesson nobody wants to hear: the weakest link isn’t the code. It’s you. Do you trust the screen you see when you sign a transaction? Fran Berlin | Blockchain Institute #Lazarus #ETH #InstitutoBlockchain #FranBerlin #BTC {spot}(ETHUSDT) {spot}(USDCUSDT)
It was a routine transfer.

February 20, 2025. A Bybit employee opens his screen, checks the transaction details, and signs.

Everything looks normal.

Minutes later, $1.5 billion $USDT in Ethereum had vanished.

But the most terrifying part isn’t the amount.

The most terrifying part is how they did it.

The elite North Korean government hackers of the Lazarus Group didn’t attack the blockchain. They didn’t break any private keys. They didn’t need any of that.

They simply… falsified what the employee saw on the screen.

Months earlier, they infiltrated the system of a Safe Wallet developer—the platform Bybit used to sign transactions. They injected a malicious code that slept quietly, waiting.

When the employee opened his wallet that day, the code activated. The screen showed a legitimate transfer. In reality, the funds were going to Pyongyang.

The employee signed. His coworkers signed. Nobody saw anything unusual.

Two minutes after the theft, the malicious code deleted itself. No trace.

It took the FBI days to confirm what everyone already suspected: it was North Korea, using stolen Ethereum to fund its nuclear weapons program.

The lesson nobody wants to hear: the weakest link isn’t the code. It’s you.

Do you trust the screen you see when you sign a transaction?

Fran Berlin | Blockchain Institute

#Lazarus #ETH #InstitutoBlockchain #FranBerlin #BTC

·
--
Article
The $620 Million Fake Job Offer: Inside Crypto’s Largest Social Engineering Heist 🚨In March 2022, the decentralized finance (DeFi) space was rocked by an unprecedented disaster. Ronin Network, an Ethereum-linked sidechain built specifically for the blockchain gaming phenomenon Axie Infinity (owned by Sky Mavis), suffered a devastating breach. A total of 173,600 Ethereum (ETH) and 25.5 million USDC were systematically drained. The total damage? A staggering $620 million, securing its place as one of the largest cryptocurrency heists in history. However, the real shockwave wasn't just the astronomical number; it was the chilling psychological warfare and "Social Engineering" tactics used by the North Korean state-backed Lazarus Group to breach the network. The Bait: Hunting a Senior Developer on LinkedIn 🧳 The heist did not begin with complex zero-day exploits or breaking cryptographic codes. Instead, it started with a simple interaction on the professional networking platform LinkedIn. Lazarus Group operatives crafted highly sophisticated, premium fake profiles posing as recruiters from prestigious global tech firms and venture capital funds. They meticulously scanned the employees of Sky Mavis and locked onto their target: a Senior Software Engineer with extensive access privileges within the network. The fake recruiters approached the developer with a "dream job opportunity," boasting a massive salary package and benefits too good to turn down. To sell the illusion, they put the developer through multiple rounds of rigorous technical interviews over several weeks. The engineer had absolutely no reason to suspect that the professional on the other side of the screen was an elite state-sponsored cyber operative. The Payload: The Malicious "Offer Letter" After clearing the final round of interviews, the developer was told they had officially secured the role. The "recruiters" sent over the official job offer package wrapped inside a standard PDF document. But it was a Trojan horse. The document contained highly advanced, tailored spyware. The moment the developer downloaded and opened the file on their official company laptop, the malware infected the machine and quietly bypassed traditional endpoint security, giving the hackers deep access to the inner architecture of Sky Mavis. Exposing the Critical Vulnerability: Subverting the Nodes To secure transactions and asset bridges, the Ronin Network utilized a Proof of Authority (PoA) consensus mechanism relying on 9 Validator Nodes. For any withdrawal to be authorized, it required cryptographic signatures from at least 5 out of the 9 nodes (a 5/9 majority). Once inside the developer's laptop, the Lazarus hackers successfully extracted the private keys of four validator nodes managed directly by Sky Mavis. However, they still needed a fifth signature to authorize the multi-million dollar theft. To get it, they exploited a lingering oversight in the infrastructure. Months prior, Sky Mavis had granted an unrevoked permission to a community group called the Axie DAO to sign off on transactions to mitigate heavy network traffic. The hackers used their access to exploit this loophole, pulling the fifth signature from the Axie DAO bridge. With a 5/9 majority secured, the hackers forged withdrawal orders and drained $620 million into their own wallets within minutes. The Twist: A 6-Day Delayed Realization What makes this historical heist incredibly bizarre is that the funds were drained on March 23, 2022, but Sky Mavis did not realize they had been hacked until March 29-six full days later! The breach was only discovered when a legitimate user tried to withdraw 5,000 ETH, and the transaction failed because the liquidity pools had already been completely emptied. The Aftermath and Recovery The FBI and the U.S. Treasury Department quickly took over the investigation, officially tying the hacker addresses directly to the Lazarus Group. The stolen funds were funneled through the popular privacy mixer Tornado Cash, which ultimately led to heavy sanctions against the protocol by the U.S. government. Despite the devastating loss, Sky Mavis successfully raised $150 million in a funding round led by Binance and other prominent investors to fully reimburse the affected users. They completely overhauled their security protocol, expanding their validator node count to over 20 to ensure such a bottleneck could never happen again. The Golden Takeaway: You can spend millions of dollars building un-hackable cryptographic code, but the human element remains the ultimate security threshold. A single click on a malicious file can bring down an entire financial fortress. #RoninNetwork #Lazarus #OnChain #DeFi #ETH

The $620 Million Fake Job Offer: Inside Crypto’s Largest Social Engineering Heist 🚨

In March 2022, the decentralized finance (DeFi) space was rocked by an unprecedented disaster. Ronin Network, an Ethereum-linked sidechain built specifically for the blockchain gaming phenomenon Axie Infinity (owned by Sky Mavis), suffered a devastating breach.
A total of 173,600 Ethereum (ETH) and 25.5 million USDC were systematically drained. The total damage? A staggering $620 million, securing its place as one of the largest cryptocurrency heists in history.
However, the real shockwave wasn't just the astronomical number; it was the chilling psychological warfare and "Social Engineering" tactics used by the North Korean state-backed Lazarus Group to breach the network.
The Bait: Hunting a Senior Developer on LinkedIn 🧳
The heist did not begin with complex zero-day exploits or breaking cryptographic codes. Instead, it started with a simple interaction on the professional networking platform LinkedIn.
Lazarus Group operatives crafted highly sophisticated, premium fake profiles posing as recruiters from prestigious global tech firms and venture capital funds. They meticulously scanned the employees of Sky Mavis and locked onto their target: a Senior Software Engineer with extensive access privileges within the network.
The fake recruiters approached the developer with a "dream job opportunity," boasting a massive salary package and benefits too good to turn down. To sell the illusion, they put the developer through multiple rounds of rigorous technical interviews over several weeks. The engineer had absolutely no reason to suspect that the professional on the other side of the screen was an elite state-sponsored cyber operative.
The Payload: The Malicious "Offer Letter"
After clearing the final round of interviews, the developer was told they had officially secured the role. The "recruiters" sent over the official job offer package wrapped inside a standard PDF document.
But it was a Trojan horse. The document contained highly advanced, tailored spyware. The moment the developer downloaded and opened the file on their official company laptop, the malware infected the machine and quietly bypassed traditional endpoint security, giving the hackers deep access to the inner architecture of Sky Mavis.
Exposing the Critical Vulnerability: Subverting the Nodes
To secure transactions and asset bridges, the Ronin Network utilized a Proof of Authority (PoA) consensus mechanism relying on 9 Validator Nodes. For any withdrawal to be authorized, it required cryptographic signatures from at least 5 out of the 9 nodes (a 5/9 majority).
Once inside the developer's laptop, the Lazarus hackers successfully extracted the private keys of four validator nodes managed directly by Sky Mavis.
However, they still needed a fifth signature to authorize the multi-million dollar theft. To get it, they exploited a lingering oversight in the infrastructure. Months prior, Sky Mavis had granted an unrevoked permission to a community group called the Axie DAO to sign off on transactions to mitigate heavy network traffic. The hackers used their access to exploit this loophole, pulling the fifth signature from the Axie DAO bridge.
With a 5/9 majority secured, the hackers forged withdrawal orders and drained $620 million into their own wallets within minutes.
The Twist: A 6-Day Delayed Realization
What makes this historical heist incredibly bizarre is that the funds were drained on March 23, 2022, but Sky Mavis did not realize they had been hacked until March 29-six full days later! The breach was only discovered when a legitimate user tried to withdraw 5,000 ETH, and the transaction failed because the liquidity pools had already been completely emptied.
The Aftermath and Recovery
The FBI and the U.S. Treasury Department quickly took over the investigation, officially tying the hacker addresses directly to the Lazarus Group. The stolen funds were funneled through the popular privacy mixer Tornado Cash, which ultimately led to heavy sanctions against the protocol by the U.S. government.
Despite the devastating loss, Sky Mavis successfully raised $150 million in a funding round led by Binance and other prominent investors to fully reimburse the affected users. They completely overhauled their security protocol, expanding their validator node count to over 20 to ensure such a bottleneck could never happen again.
The Golden Takeaway: You can spend millions of dollars building un-hackable cryptographic code, but the human element remains the ultimate security threshold. A single click on a malicious file can bring down an entire financial fortress.
#RoninNetwork #Lazarus
#OnChain #DeFi #ETH
TWO MAJOR $ETH HACKS TRACED TO LAZARUS GROUP 🔥 ZachXBT just connected the dots: funds from the Kelp DAO $292M exploit and the Humanity Protocol $32M theft are converging on the same address. This isn't coincidence — it's a signature move from the Lazarus Group. The timing is what bothers me. April 18th and June 9th, two separate attacks, same destination. That means North Korea's top hacking crew is actively expanding their DeFi campaign. If you're in a new project without a proper audit, the risk just went up. What's your move — pull liquidity from unaudited protocols or hold through? Not financial advice. Always manage your risk. #ETH #Lazarus #DeFiSecurity #HackAlert #CryptoNews 🔥
TWO MAJOR $ETH HACKS TRACED TO LAZARUS GROUP 🔥

ZachXBT just connected the dots: funds from the Kelp DAO $292M exploit and the Humanity Protocol $32M theft are converging on the same address. This isn't coincidence — it's a signature move from the Lazarus Group.

The timing is what bothers me. April 18th and June 9th, two separate attacks, same destination. That means North Korea's top hacking crew is actively expanding their DeFi campaign. If you're in a new project without a proper audit, the risk just went up.

What's your move — pull liquidity from unaudited protocols or hold through?

Not financial advice. Always manage your risk.

#ETH #Lazarus #DeFiSecurity #HackAlert #CryptoNews

🔥
Article
Crypto's Security Crisis: $755 Million Stolen in Q2 2026 Alone — And the Attacks Are Getting SmarterHackers didn't just break into crypto this quarter — they engineered the most sophisticated assault in blockchain history. ◆ Record-Breaking Quarter: Q2 2026 has become the most-hacked quarter on record by incident count, with 83 exploits targeting cryptocurrency protocols — resulting in $755.3 million in total losses, according to DefiLlama data. (Cointelegraph) ◆ Two Attacks, Half a Billion Gone: KelpDAO's $293 million hack and Drift Protocol's $280 million exploit were the two largest incidents of the quarter — together accounting for over 73% of all Q2 losses. (Cointelegraph) ◆ Bridges Are the Weakest Link: Cross-chain bridge exploits emerged as the biggest attack vector, with $351 million stolen from bridges alone — representing nearly half of all Q2 losses. The LayerZero OFT bridge exploit, which triggered the KelpDAO hack, accounted for more than 38% of the quarter's total stolen value. (Cointelegraph) ◆ North Korea Is the Biggest Threat: North Korean state-linked hackers connected to the Lazarus Group are believed to have accounted for approximately 76% of crypto-related hack losses globally in 2026 — including the Drift and KelpDAO heists. The group had previously been linked to the $1.4 billion Bybit hack in February 2025. (Finextra) ◆ Social Engineering Now Beats Code Attacks: The Drift Protocol breach was not a code exploit — it was a six-month social engineering operation targeting the people who controlled admin keys. Smart contract audits protect against code bugs, but they do not protect against a developer getting phished by a state-backed team with months of patience. (Phemex) ◆ Latest Victim — June 24: SecondFi, a project in the Cardano ecosystem, was hit by a major exploit linked to a flaw in its proprietary wallet generation software. SlowMist analysts estimate losses at over $20 million, involving more than 129 million ADA and additional tokens. (Bitcoin Foundation) ◆ AI Is Now a Hacker's Tool: Immunefi CEO Mitchell Amador warned that advances in artificial intelligence could be exacerbating these trends, describing the rise of AI-enabled hacking as a "vulnerability apocalypse" — with attackers leveraging machine learning to exploit weaknesses at unprecedented scale. (Blockchain News) ◆ DeFi TVL Shrinking Under Attack Pressure: Total value locked in DeFi has fallen from $164 billion before the October 10 liquidation event to approximately $73 billion — a collapse that reflects both market conditions and eroding confidence in protocol security. (Cointelegraph) ◆ All-Time Damage Crosses $16.5 Billion: Since DeFi entered the crypto space, cumulative exploit-related losses have surpassed $16.5 billion all-time, with bridge exploits alone accounting for $2.9 billion of that total. (Finextra) The message from 2026's security data is clear: the code is getting harder to crack, so attackers have moved to the human layer — employees, developers, and infrastructure operators. No audit can fix a six-month social engineering campaign funded by a nation state. If the biggest threat to crypto is now human error and nation-state hackers — not flawed code — what should protocols prioritize first: better audits, better employee security training, or decentralized key management? #CryptoSecurity #DeFiHacks #BlockchainSecurity #CryptoNews #Lazarus

Crypto's Security Crisis: $755 Million Stolen in Q2 2026 Alone — And the Attacks Are Getting Smarter

Hackers didn't just break into crypto this quarter — they engineered the most sophisticated assault in blockchain history.
◆ Record-Breaking Quarter: Q2 2026 has become the most-hacked quarter on record by incident count, with 83 exploits targeting cryptocurrency protocols — resulting in $755.3 million in total losses, according to DefiLlama data. (Cointelegraph)
◆ Two Attacks, Half a Billion Gone: KelpDAO's $293 million hack and Drift Protocol's $280 million exploit were the two largest incidents of the quarter — together accounting for over 73% of all Q2 losses. (Cointelegraph)
◆ Bridges Are the Weakest Link: Cross-chain bridge exploits emerged as the biggest attack vector, with $351 million stolen from bridges alone — representing nearly half of all Q2 losses. The LayerZero OFT bridge exploit, which triggered the KelpDAO hack, accounted for more than 38% of the quarter's total stolen value. (Cointelegraph)
◆ North Korea Is the Biggest Threat: North Korean state-linked hackers connected to the Lazarus Group are believed to have accounted for approximately 76% of crypto-related hack losses globally in 2026 — including the Drift and KelpDAO heists. The group had previously been linked to the $1.4 billion Bybit hack in February 2025. (Finextra)
◆ Social Engineering Now Beats Code Attacks: The Drift Protocol breach was not a code exploit — it was a six-month social engineering operation targeting the people who controlled admin keys. Smart contract audits protect against code bugs, but they do not protect against a developer getting phished by a state-backed team with months of patience. (Phemex)
◆ Latest Victim — June 24: SecondFi, a project in the Cardano ecosystem, was hit by a major exploit linked to a flaw in its proprietary wallet generation software. SlowMist analysts estimate losses at over $20 million, involving more than 129 million ADA and additional tokens. (Bitcoin Foundation)
◆ AI Is Now a Hacker's Tool: Immunefi CEO Mitchell Amador warned that advances in artificial intelligence could be exacerbating these trends, describing the rise of AI-enabled hacking as a "vulnerability apocalypse" — with attackers leveraging machine learning to exploit weaknesses at unprecedented scale. (Blockchain News)
◆ DeFi TVL Shrinking Under Attack Pressure: Total value locked in DeFi has fallen from $164 billion before the October 10 liquidation event to approximately $73 billion — a collapse that reflects both market conditions and eroding confidence in protocol security. (Cointelegraph)
◆ All-Time Damage Crosses $16.5 Billion: Since DeFi entered the crypto space, cumulative exploit-related losses have surpassed $16.5 billion all-time, with bridge exploits alone accounting for $2.9 billion of that total. (Finextra)
The message from 2026's security data is clear: the code is getting harder to crack, so attackers have moved to the human layer — employees, developers, and infrastructure operators. No audit can fix a six-month social engineering campaign funded by a nation state.
If the biggest threat to crypto is now human error and nation-state hackers — not flawed code — what should protocols prioritize first: better audits, better employee security training, or decentralized key management?
#CryptoSecurity #DeFiHacks #BlockchainSecurity #CryptoNews #Lazarus
Article
Arbitrum Freezes Hacker ETHRecently, Arbitrum's operation to 'freeze hacker ETH' has indeed caused a stir in the crypto world. As players focused on Layer 2 and on-chain governance, we need to discuss this thoroughly. The main character in this incident is 30,766 ETH (approximately 70 million to 100 million dollars at current market price), which originally belonged to KelpDAO that was hacked a few days ago. Just today (April 21, 2026), the Arbitrum Security Council exercised its 'emergency powers' and directly transferred this amount to a frozen wallet. 1. The ins and outs of the matter A brief recap: On April 18, KelpDAO's cross-chain bridge was hacked, losing nearly 300 million dollars. The hacker (reportedly the Lazarus group again) initially wanted to launder the money, but the Arbitrum Security Council reacted extremely quickly this time. Out of 12 members, 9 voted in favor, using emergency multi-signature authority to intercept the funds precisely before the hacker could transfer the money to the mainnet or mix it.

Arbitrum Freezes Hacker ETH

Recently, Arbitrum's operation to 'freeze hacker ETH' has indeed caused a stir in the crypto world. As players focused on Layer 2 and on-chain governance, we need to discuss this thoroughly.
The main character in this incident is 30,766 ETH (approximately 70 million to 100 million dollars at current market price), which originally belonged to KelpDAO that was hacked a few days ago. Just today (April 21, 2026), the Arbitrum Security Council exercised its 'emergency powers' and directly transferred this amount to a frozen wallet.
1. The ins and outs of the matter
A brief recap: On April 18, KelpDAO's cross-chain bridge was hacked, losing nearly 300 million dollars. The hacker (reportedly the Lazarus group again) initially wanted to launder the money, but the Arbitrum Security Council reacted extremely quickly this time. Out of 12 members, 9 voted in favor, using emergency multi-signature authority to intercept the funds precisely before the hacker could transfer the money to the mainnet or mix it.
Arkham Intelligence published a report examining Lazarus Group’s crypto laundering network and operational tactics between 2017 and 2026. According to the research, Lazarus-linked actors were tied to more than $6 billion in stolen cryptocurrency across exchange breaches, ransomware campaigns, bridge exploits, and decentralized finance attacks. Arkham said North Korean-linked actors accounted for more than 70% of crypto exploit losses recorded so far in 2026. The report described how Lazarus allegedly moves stolen assets through cross-chain bridges, mixers, centralized exchanges, OTC brokers, and fragmented wallet activity to complicate blockchain tracing efforts. THORChain was identified as a frequently used bridge for converting stolen assets into Bitcoin. Arkham also referenced mixers including Sinbad.io and YoMix, along with Russian exchanges and Chinese OTC brokers involved in cash-out activity. The research examined the April 2026 Drift Protocol ($DRIFT ) exploit, where attackers allegedly spent months building trust with employees through conferences, deposits exceeding $1 million, and fake partnership activity. Arkham said Lazarus later used pre-authorized Solana transactions to drain about $285 million from the protocol. The report also covered the February 2026 KelpDAO exploit. According to Arkham, attackers compromised LayerZero RPC nodes and forged cross-chain messages, allowing the withdrawal of 116,500 $rsETH valued at about $292 million. Arkham concluded that Lazarus continues adapting its laundering methods and attack strategies as blockchain tracing systems become more advanced. #arkham #DRIFT #KelpDAO #LazarusGroup #Lazarus
Arkham Intelligence published a report examining Lazarus Group’s crypto laundering network and operational tactics between 2017 and 2026.
According to the research, Lazarus-linked actors were tied to more than $6 billion in stolen cryptocurrency across exchange breaches, ransomware campaigns, bridge exploits, and decentralized finance attacks.
Arkham said North Korean-linked actors accounted for more than 70% of crypto exploit losses recorded so far in 2026.
The report described how Lazarus allegedly moves stolen assets through cross-chain bridges, mixers, centralized exchanges, OTC brokers, and fragmented wallet activity to complicate blockchain tracing efforts.
THORChain was identified as a frequently used bridge for converting stolen assets into Bitcoin. Arkham also referenced mixers including Sinbad.io and YoMix, along with Russian exchanges and Chinese OTC brokers involved in cash-out activity.
The research examined the April 2026 Drift Protocol ($DRIFT ) exploit, where attackers allegedly spent months building trust with employees through conferences, deposits exceeding $1 million, and fake partnership activity. Arkham said Lazarus later used pre-authorized Solana transactions to drain about $285 million from the protocol.
The report also covered the February 2026 KelpDAO exploit. According to Arkham, attackers compromised LayerZero RPC nodes and forged cross-chain messages, allowing the withdrawal of 116,500 $rsETH valued at about $292 million.
Arkham concluded that Lazarus continues adapting its laundering methods and attack strategies as blockchain tracing systems become more advanced.

#arkham #DRIFT #KelpDAO #LazarusGroup #Lazarus
North Korea is out here denying the hacker attack accusations, saying it's all just rumors, and that sounds way too familiar. The on-chain money laundering pathways and Lazarus' fingerprints are right there in plain sight, and the funds still chilling in the mixers won't lie. This kind of verbal denial is just for laughs; seasoned traders have seen it all before. Meanwhile, Upbit's banking partner is looking to test Ripple's remittance system, and that's where the real action is. In Korea, the response to such news is usually lightning fast. If they really go for cross-border trials, then Ripple's on-chain liquidity and narrative logic are going to need some serious reshaping. Lately, I've been keeping an eye on large on-chain transfers to see if any big players are paving the way for liquidity pools. #Ripple #Upbit #Lazarus $XRP {future}(XRPUSDT)
North Korea is out here denying the hacker attack accusations, saying it's all just rumors, and that sounds way too familiar. The on-chain money laundering pathways and Lazarus' fingerprints are right there in plain sight, and the funds still chilling in the mixers won't lie. This kind of verbal denial is just for laughs; seasoned traders have seen it all before.
Meanwhile, Upbit's banking partner is looking to test Ripple's remittance system, and that's where the real action is. In Korea, the response to such news is usually lightning fast. If they really go for cross-border trials, then Ripple's on-chain liquidity and narrative logic are going to need some serious reshaping. Lately, I've been keeping an eye on large on-chain transfers to see if any big players are paving the way for liquidity pools. #Ripple #Upbit #Lazarus $XRP
🚫 North Korea Denies All Charges! Despite TRM Labs Report: Stolen Crypto Exceeds $6 Billion 💸 North Korea has officially rejected the accusations, calling them "baseless claims" and denying any involvement in cybercrime 🤨 📊 Where does this data come from? • Reported by blockchain analysis firm TRM Labs. • They estimate that over the years, a total of $6 Billion worth of crypto has been stolen. • The blame points directly to the Lazarus Group, linked to the North Korean state. • These funds are believed to fund their weapons programs and state activities. 💥 Examples of Major Recent Cases: • Drift Protocol (Apr 2026) - Loss ~$285 Million (SOL, ETH, USDC) • KelpDAO (Apr 2026) - Loss ~$292 Million • Bybit (Feb 2025) - Loss ~$1.5 Billion (ETH) This story is far from over! Who is telling the truth? 👀🔒 $ETH $SOL $AAVE #NorthKorea #TRMLabs #Lazarus
🚫 North Korea Denies All Charges! Despite TRM Labs Report: Stolen Crypto Exceeds $6 Billion 💸

North Korea has officially rejected the accusations, calling them "baseless claims" and denying any involvement in cybercrime 🤨

📊 Where does this data come from?
• Reported by blockchain analysis firm TRM Labs.
• They estimate that over the years, a total of $6 Billion worth of crypto has been stolen.
• The blame points directly to the Lazarus Group, linked to the North Korean state.
• These funds are believed to fund their weapons programs and state activities.

💥 Examples of Major Recent Cases:
• Drift Protocol (Apr 2026) - Loss ~$285 Million (SOL, ETH, USDC)
• KelpDAO (Apr 2026) - Loss ~$292 Million
• Bybit (Feb 2025) - Loss ~$1.5 Billion (ETH)

This story is far from over! Who is telling the truth? 👀🔒
$ETH $SOL $AAVE
#NorthKorea #TRMLabs #Lazarus
·
--
Bearish
🚨 DeFi Shockwave: $7B Wiped in 24H 🚨 The DeFi market just took a massive hit, with over $7 billion erased in a single day following a $290M exploit — and LayerZero has flagged it as a likely Lazarus Group-linked attack. 💥 What’s unfolding: • A major exploit drains ~$290M • Panic spreads across protocols • Total DeFi market cap sees a sharp $7B drop • Cross-chain infrastructure once again under scrutiny ⚠️ The bigger concern? This isn’t just another hack — it highlights systemic vulnerabilities in cross-chain messaging and liquidity bridges. When core infrastructure is targeted, the ripple effects hit everything. 🧠 Key takeaways for traders & investors: • Security risk in DeFi is still VERY real • Smart money rotates fast during exploits • Fear-driven selloffs create both traps & opportunities • Always track where liquidity is flowing next 👀 The mention of Lazarus Group is serious — they’ve been behind some of the largest crypto hacks in history, and their return signals state-level sophistication in exploits. 📊 Bottom line: DeFi isn’t dead — but moments like this remind everyone: High yield = high risk. Are you staying defensive… or preparing to buy the fear? #DeFi #CryptoNews #LayerZero #Lazarus #Web3
🚨 DeFi Shockwave: $7B Wiped in 24H 🚨

The DeFi market just took a massive hit, with over $7 billion erased in a single day following a $290M exploit — and LayerZero has flagged it as a likely Lazarus Group-linked attack.

💥 What’s unfolding:
• A major exploit drains ~$290M
• Panic spreads across protocols
• Total DeFi market cap sees a sharp $7B drop
• Cross-chain infrastructure once again under scrutiny

⚠️ The bigger concern?
This isn’t just another hack — it highlights systemic vulnerabilities in cross-chain messaging and liquidity bridges. When core infrastructure is targeted, the ripple effects hit everything.

🧠 Key takeaways for traders & investors:
• Security risk in DeFi is still VERY real
• Smart money rotates fast during exploits
• Fear-driven selloffs create both traps & opportunities
• Always track where liquidity is flowing next

👀 The mention of Lazarus Group is serious — they’ve been behind some of the largest crypto hacks in history, and their return signals state-level sophistication in exploits.

📊 Bottom line:
DeFi isn’t dead — but moments like this remind everyone:
High yield = high risk.

Are you staying defensive… or preparing to buy the fear?

#DeFi #CryptoNews #LayerZero #Lazarus #Web3
🚨 Lazarus "The North Korean Ghost" Strikes DeFi – $577 Million Gone in 18 Days The Lazarus hacking group (North Korea) has confirmed its involvement in both of the biggest attacks in April: Drift Protocol lost $285M on April 1st and KelpDAO lost $292M on April 18th – total damages exceeding $577M in just half a month. The KelpDAO hack exploited a vulnerability in the LayerZero bridge by launching a DDoS attack on 2 RPC nodes, forcing the failover system and tricking the verifier into signing fake cross-chain transactions, withdrawing 116,500 rsETH (~18% of the circulating supply). April 2026 officially became the worst month for DeFi since February 2025, with total damages this year reaching $771.8M – the number of attacks has nearly doubled compared to the same period in 2025. #DeFiHack #Lazarus #KelpDAO
🚨 Lazarus "The North Korean Ghost" Strikes DeFi – $577 Million Gone in 18 Days

The Lazarus hacking group (North Korea) has confirmed its involvement in both of the biggest attacks in April: Drift Protocol lost $285M on April 1st and KelpDAO lost $292M on April 18th – total damages exceeding $577M in just half a month.

The KelpDAO hack exploited a vulnerability in the LayerZero bridge by launching a DDoS attack on 2 RPC nodes, forcing the failover system and tricking the verifier into signing fake cross-chain transactions, withdrawing 116,500 rsETH (~18% of the circulating supply).

April 2026 officially became the worst month for DeFi since February 2025, with total damages this year reaching $771.8M – the number of attacks has nearly doubled compared to the same period in 2025.

#DeFiHack #Lazarus #KelpDAO
Article
Serious Security Alert: The "Lazarus" Group is using fake meetings to infiltrate crypto companies!The infamous North Korean hacking group "Lazarus Group" has launched a new and innovative cyber attack campaign directly targeting executives in the crypto and FinTech sectors. Cybersecurity researchers at "CertiK" revealed this complex operation on Wednesday, dubbing it "Mach-O Man."

Serious Security Alert: The "Lazarus" Group is using fake meetings to infiltrate crypto companies!

The infamous North Korean hacking group "Lazarus Group" has launched a new and innovative cyber attack campaign directly targeting executives in the crypto and FinTech sectors.
Cybersecurity researchers at "CertiK" revealed this complex operation on Wednesday, dubbing it "Mach-O Man."
☠️ ALERT — North Korea just upgraded their attack on crypto and almost nobody is talking about it. Same month. Same group. Three hits: 🔴 $285M — Drift Protocol (April 1) 🔴 $292M — KelpDAO (April 18) 🔴 NEW — "Mach-O Man" malware targeting YOUR Mac right now How does Mach-O Man work? You get a Telegram message: "Urgent Zoom call, fix your connection — paste this command." You paste it. Your entire system is theirs. Done. This isn't random hackers. This is a North Korean state army funding nuclear weapons with YOUR crypto. Lazarus Group stole 59% of ALL crypto stolen globally in 2025. In just 18 days of April 2026 — $577M gone. And now Google says quantum computers could crack Bitcoin's encryption by 2029. Bitcoin's own fix (BIP-361) takes 7 years. Do the math. 👀 🔐 Never paste commands from strangers into your terminal. Ever. RT this to save someone's wallet. 👇 #Lazarus #CryptoSecurity #Bitcoin #BinanceSquare #DeFi
☠️ ALERT — North Korea just upgraded their attack on crypto and almost nobody is talking about it.

Same month. Same group. Three hits:
🔴 $285M — Drift Protocol (April 1)
🔴 $292M — KelpDAO (April 18)
🔴 NEW — "Mach-O Man" malware targeting YOUR Mac right now

How does Mach-O Man work?
You get a Telegram message: "Urgent Zoom call, fix your connection — paste this command."
You paste it. Your entire system is theirs. Done.

This isn't random hackers. This is a North Korean state army funding nuclear weapons with YOUR crypto.

Lazarus Group stole 59% of ALL crypto stolen globally in 2025.
In just 18 days of April 2026 — $577M gone.

And now Google says quantum computers could crack Bitcoin's encryption by 2029. Bitcoin's own fix (BIP-361) takes 7 years. Do the math. 👀

🔐 Never paste commands from strangers into your terminal. Ever.

RT this to save someone's wallet. 👇
#Lazarus #CryptoSecurity #Bitcoin #BinanceSquare #DeFi
Log in to explore more content
Join global crypto users on Binance Square
⚡️ Get latest and useful information about crypto.
💬 Trusted by the world’s largest crypto exchange.
👍 Discover real insights from verified creators.
Email / Phone number