{"id":29085,"date":"2025-03-10T06:56:09","date_gmt":"2025-03-10T10:56:09","guid":{"rendered":"https:\/\/worldjusticenews.com\/news\/?p=29085"},"modified":"2025-03-10T07:06:52","modified_gmt":"2025-03-10T11:06:52","slug":"north-korean-hackers-cash-out-hundreds-of-millions-from-1-5bn-bybit-hack","status":"publish","type":"post","link":"https:\/\/worldjusticenews.com\/news\/2025\/03\/10\/north-korean-hackers-cash-out-hundreds-of-millions-from-1-5bn-bybit-hack\/","title":{"rendered":"North Korean hackers cash out hundreds of millions from $1.5bn ByBit hack"},"content":{"rendered":"<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\"><b class=\"ssrcss-1xjjfut-BoldText e5tfeyi3\">Hackers thought to be working for the North Korean regime have successfully converted at least $300m (\u00a3232m) of their record-breaking $1.5bn crypto heist to unrecoverable funds.<\/b><\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The criminals, known as Lazarus Group, swiped the huge haul of digital tokens in a hack on crypto exchange ByBit\u00a0<a class=\"ssrcss-f6h2dj-InlineLink e1kn3p7n0\" href=\"https:\/\/www.bbc.co.uk\/news\/articles\/cx2844nvwx8o\" target=\"_blank\" rel=\"noopener\">two weeks ago<\/a>.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Since then, it&#8217;s been a cat-and-mouse game to track and block the hackers from successfully converting the crypto into usable cash.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Experts say the infamous hacking team is working nearly 24 hours a day &#8211; potentially funnelling the money into the regime&#8217;s military development.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">&#8220;Every minute matters for the hackers who are trying to confuse the money trail and they are extremely sophisticated in what they&#8217;re doing,&#8221; says Dr Tom Robinson, co-founder of crypto investigators Elliptic.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Out of all the criminal actors involved in crypto currency, North Korea is the best at laundering crypto, Dr Robinson says.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">&#8220;I imagine they have an entire room of people doing this using automated tools and years of experience. We can also see from their activity that they only take a few hours break each day, possibly working in shifts to get the crypto turned into cash.&#8221;<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Elliptic&#8217;s analysis tallies with ByBit, which says that 20% of the funds have now &#8220;gone dark&#8221;, meaning it is unlikely to ever be recovered.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The US and allies accuse the North Koreans of carrying out dozens of hacks in recent years to fund the regime&#8217;s military and nuclear development.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">On 21 February the criminals hacked one of ByBit&#8217;s suppliers to secretly alter the digital wallet address that 401,000 Ethereum crypto coins were being sent to.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">ByBit thought it was transferring the funds to its own digital wallet, but instead sent it all to the hackers.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Ben Zhou, the CEO of ByBit, assured customers that none of their funds had been taken.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The firm has since replenished the stolen coins with loans from investors, but is, in Zhou&#8217;s words, &#8220;waging war on Lazarus&#8221;.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">ByBit&#8217;s Lazarus Bounty programme is encouraging members of the public to trace the stolen funds and get them frozen where possible.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">All crypto transactions are displayed on a public blockchain, so it&#8217;s possible to track the money as it&#8217;s moved around by the Lazarus Group.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">If the hackers try to use a mainstream crypto service to attempt to turn the coins into normal money like dollars, the crypto coins can be frozen by the company if they think they are linked to crime.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">So far 20 people have shared more than $4m in rewards for successfully identifying $40m of the stolen money and alerting crypto firms to block transfers.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">But experts are downbeat about the chances of the rest of the funds being recoverable, given the North Korean expertise in hacking and laundering the money.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">&#8220;North Korea is a very closed system and closed economy so they created a successful industry for hacking and laundering and they don&#8217;t care about the negative impression of cyber crime,&#8221; Dr Dorit Dor from cyber security company Check Point said.<\/p>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Another problem is that not all crypto companies are as willing to help as others.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Crypto exchange eXch is being accused by ByBit and others of not stopping the criminals cashing out.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">More than $90m has been successfully funnelled through this exchange.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">But over email the elusive owner of eXch &#8211; Johann Roberts &#8211; disputed that.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">He admits they didn&#8217;t initially stop the funds, as his company is in a long-running dispute with ByBit, and he says his team wasn&#8217;t sure the coins were definitely from the hack.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">He says he is now co-operating, but argues that mainstream companies that identify crypto customers are betraying the private and anonymous benefits of crypto currency.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-1qlkdz0-ComponentWrapper-FullWidthWrapper ep2nwvo1\" data-component=\"image-block\">\n<figure class=\"ssrcss-1vfya96-StyledFigure e34k3c22\">\n<div class=\"ssrcss-ab5fd8-StyledFigureContainer e34k3c21\"><span class=\"ssrcss-1r8ar7-Placeholder etlorgc0\"><picture><source srcset=\"https:\/\/ichef.bbci.co.uk\/ace\/standard\/240\/cpsprodpb\/5f22\/live\/88a18160-fb61-11ef-896e-d7e7fb1719a4.png.webp 240w, https:\/\/ichef.bbci.co.uk\/ace\/standard\/320\/cpsprodpb\/5f22\/live\/88a18160-fb61-11ef-896e-d7e7fb1719a4.png.webp 320w, https:\/\/ichef.bbci.co.uk\/ace\/standard\/480\/cpsprodpb\/5f22\/live\/88a18160-fb61-11ef-896e-d7e7fb1719a4.png.webp 480w, https:\/\/ichef.bbci.co.uk\/ace\/standard\/624\/cpsprodpb\/5f22\/live\/88a18160-fb61-11ef-896e-d7e7fb1719a4.png.webp 624w\" type=\"image\/webp\" \/><img loading=\"lazy\" decoding=\"async\" class=\"ssrcss-11yxrdo-Image edrdn950\" src=\"https:\/\/ichef.bbci.co.uk\/ace\/standard\/798\/cpsprodpb\/5f22\/live\/88a18160-fb61-11ef-896e-d7e7fb1719a4.png\" srcset=\"https:\/\/ichef.bbci.co.uk\/ace\/standard\/240\/cpsprodpb\/5f22\/live\/88a18160-fb61-11ef-896e-d7e7fb1719a4.png 240w, https:\/\/ichef.bbci.co.uk\/ace\/standard\/320\/cpsprodpb\/5f22\/live\/88a18160-fb61-11ef-896e-d7e7fb1719a4.png 320w, https:\/\/ichef.bbci.co.uk\/ace\/standard\/480\/cpsprodpb\/5f22\/live\/88a18160-fb61-11ef-896e-d7e7fb1719a4.png 480w, https:\/\/ichef.bbci.co.uk\/ace\/standard\/624\/cpsprodpb\/5f22\/live\/88a18160-fb61-11ef-896e-d7e7fb1719a4.png 624w\" alt=\"Park Jin Hyok\" width=\"798\" height=\"511\" \/><\/picture><\/span>Park Jin Hyok is one of the alleged Lazarus Group hackers (Image: FBI)<\/div>\n<\/figure>\n<\/div>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p>&nbsp;<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">North Korea has never admitted being behind the Lazarus Group, but is thought to be the only country in the world using its hacking powers for financial gain.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Previously the Lazarus Group hackers targeted banks, but have in the last five years specialised in attacking cryptocurrency companies.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The industry is less well protected with fewer mechanisms in place to stop them laundering the funds.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Recent hacks linked to North Korea include:<\/p>\n<div class=\"ssrcss-1le81vw-ListContainer e5tfeyi0\">\n<ul role=\"list\">\n<li>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The 2019 hack on UpBit for $41m<\/p>\n<\/li>\n<li>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The $275m theft of crypto from exchange KuCoin (most of the funds were recovered)<\/p>\n<\/li>\n<li>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The 2022 Ronin Bridge attack which saw hackers make off with $600m in crypto<\/p>\n<\/li>\n<li>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Approximately $100m in crypto was stolen in an attack on Atomic Wallet in 2023<\/p>\n<\/li>\n<\/ul>\n<\/div>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">In 2020, the US added North Koreans accused of being part of the Lazarus Group to its Cyber Most Wanted list. But the chances of the individuals ever being arrested are extremely slim unless they leave their country.<\/p>\n<p>Source: <a href=\"https:\/\/www.bbc.co.uk\/news\/articles\/c2kgndwwd7lo\" target=\"_blank\" rel=\"noopener\">bbc.co.uk<\/a><\/p>\n<\/div>\n<\/div>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<div class=\"mh-excerpt\">Hackers thought to be working for the North Korean regime have successfully converted at least $300m (\u00a3232m) of their record-breaking $1.5bn crypto heist to unrecoverable funds. The criminals, known as Lazarus Group, swiped the huge <a class=\"mh-excerpt-more\" href=\"https:\/\/worldjusticenews.com\/news\/2025\/03\/10\/north-korean-hackers-cash-out-hundreds-of-millions-from-1-5bn-bybit-hack\/\" title=\"North Korean hackers cash out hundreds of millions from $1.5bn ByBit hack\">[&#8230;]<\/a><\/div>\n","protected":false},"author":1,"featured_media":29086,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"pmpro_default_level":"","footnotes":""},"categories":[109,2,6],"tags":[11092,9077,9638,4686,11094,4835,7120,10361,9795,11093,2936,8469,1786],"class_list":{"0":"post-29085","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-headline","8":"category-news","9":"category-world","10":"tag-bybit","11":"tag-crypto-exchange","12":"tag-crypto-heist","13":"tag-cryptocurrency","14":"tag-cyber-most-wanted","15":"tag-cyber-crime","16":"tag-cyber-security","17":"tag-ethereum","18":"tag-ethereum-coins","19":"tag-exch","20":"tag-hacking","21":"tag-lazarus-group","22":"tag-north-korea","23":"pmpro-has-access"},"_links":{"self":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts\/29085","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/comments?post=29085"}],"version-history":[{"count":2,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts\/29085\/revisions"}],"predecessor-version":[{"id":29088,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts\/29085\/revisions\/29088"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/media\/29086"}],"wp:attachment":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/media?parent=29085"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/categories?post=29085"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/tags?post=29085"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}