Security News > 2022 > April > US Treasury links largest crypto hack to Lazarus state hackers

The Treasury Department's Office of Foreign Assets Control has updated its Specially Designated Nationals list with new information linking the North Korean-backed Lazarus Group APT to the largest cryptocurrency hack in history.
Blockchain data platform Chainalysis first spotted that a new ETH address added by OFAC to the SDN list as part of the Lazarus Group entry was also used in March to collect the ETH and USDC tokens stolen during the Axie Infinity's Ronin bridge hack.
"Updates to OFAC's SDN designation for Lazarus Group confirm that the North Korean cybercriminal group was behind the March hack of Ronin Bridge, in which over $600 million worth of ETH and USDC was stolen," blockchain data platform Chainalysis revealed in a Twitter thread on Thursday.
This attack is the largest crypto hack ever, with the previous most significant theft of cryptocurrency being the $611 million Poly Network hack from August 2021.
The Lazarus Group is a North Korean military hacking group active for more than a decade, since at least 2009.
The US Treasury sanctioned three DPRK-sponsored hacking groups in September 2019.
News URL
Related news
- Hackers pose as employers to steal crypto, login credentials (source)
- Chinese hackers use custom malware to spy on US telecom networks (source)
- Week in review: PostgreSQL 0-day exploited in US Treasury hack, top OSINT books to learn from (source)
- North Korean hackers linked to $1.5 billion ByBit crypto heist (source)
- Bybit Hack Traced to Safe{Wallet} Supply Chain Attack Exploited by North Korean Hackers (source)
- FBI confirms Lazarus hackers were behind $1.5B Bybit crypto heist (source)
- $1.5B Bybit Hack is Linked to North Korea, FBI Says, in Potentially the Largest Crypto Heist Ever (source)
- US charges Chinese hackers linked to critical infrastructure breaches (source)
- US seizes domain of Garantex crypto exchange used by ransomware gangs (source)
- US seizes $23 million in crypto linked to LastPass breaches (source)