Bitcoins Heist

North Korea steals $1.5B in cryptocurrency

The process

How does a nuclear-armed pariah nation, the 🇰🇵 #DPRK 🇰🇵, steal and launder $1.5B? Thanks to ongoing investigations, we now know the details...
The #Bybit #cryptocurrency heist, by North Korean state-affiliated group UNC4899 (better known as #Lazarus Group), was enabled by a supply chain attack against a company called "Safe{Wallet}", who make cryptocurrency infrastructure for secure multi-signature transactions (and whose name looks suspiciously like a CTF flag!!)

Here's the sequence of events, from a preliminary report and a blockchain analysis:

We do not know when the laundered ETH will be converted to fiat (eg. USD). Let's hope they spend it on food, not nukes.

Lessons learned so far:




Important note: no zero days were burned during the creation of this heist. Author: Yiannakis Papageorgiou 2025