Lazarus Group Moves 121.5 BTC ($7.74M) Amid Escalating North Korean Crypto Theft Trend
Key Takeaways
- •A wallet cluster associated with North Korea's Lazarus Group moved 121.5 Bitcoin worth roughly $7.74 million, according to blockchain analytics firm Lookonchain.
- •TRM Labs estimated that North Korean hackers stole approximately $577 million in cryptocurrency through April 2026, with just two incidents responsible for 76% of the total value stolen.
- •Since 2017, North Korean state-sponsored cyber operatives have stolen more than $6 billion in digital assets, making the country the world's largest state-sponsored cyber threat.
- •The Lazarus Group remains subject to U.S. Treasury sanctions under OFAC's DPRK3 program, meaning any entity processing transactions from designated addresses risks sanctions exposure.
- •The FBI has linked the Lazarus Group to multiple major cryptocurrency heists, including the $100 million Harmony Horizon Bridge hack in 2022 and the record-breaking $1.5 billion Bybit hack in February 2025.

A wallet cluster linked to North Korea's Lazarus Group transferred 121.5 Bitcoin (BTC), valued at approximately $7.74 million, roughly one hour before the transaction was flagged by blockchain analytics tracker Lookonchain on Thursday.
While the amount is modest in a market where daily trading volumes routinely reach tens of billions of dollars, the significance lies in the wallet's association with the Lazarus Group. Addresses tied to the organization attract intense scrutiny because each transaction potentially moves stolen cryptocurrencies closer to conversion into spendable funds. The broader stakes are geopolitical: a United Nations Panel of Experts has reported that cryptocurrency theft serves as a significant revenue stream for Pyongyang, helping fund the country's weapons of mass destruction and ballistic missile programs in violation of UN sanctions.
Lazarus Wallets Reactivate
According to Lookonchain, wallets associated with the Lazarus Group moved 121.5 BTC, estimated at roughly $7.74 million. The firm did not disclose the destination of the funds nor link the transfer to a specific prior theft.
The Lazarus Group hackers moved 121.5 $BTC ($7.74M) an hour ago. pic.twitter.com/5qrmlvxMGd — Lookonchain (@lookonchain) July 30, 2026
The Lazarus Group hackers moved 121.5 $BTC ($7.74M) an hour ago. pic.twitter.com/5qrmlvxMGd
North Korea Dominates Crypto Theft in 2026
TRM Labs estimated that North Korean hackers stole approximately $577 million in cryptocurrency through April 2026. Nearly all of that total stemmed from two incidents: a $285 million exploit of Drift Protocol on April 1 and a $292 million attack on a KelpDAO bridge on April 18. Although those two incidents represented just 3% of all recorded hacks, they accounted for 76% of the total value stolen during the period.
The trend has intensified over recent years. TRM analysts note that North Korea's share of global cryptocurrency theft volume rose from below 10% in 2020 and 2021, to 22% in 2022, 37% in 2023, 39% in 2024, and 64% in 2025 — reaching a new record this year. Since 2017, North Korean hackers have stolen more than $6 billion in digital assets, cementing their status as the world's largest state-sponsored cyber threat.
Bitcoin, THORChain, and the Flood-the-Zone Playbook
The latest movement echoes the laundering pattern documented by TRM Labs following the Bybit hack in February 2025, in which North Korean actors stole approximately $1.5 billion worth of Ether — the largest cryptocurrency theft on record. The investigation found that the perpetrators rapidly routed funds through THORChain to convert them into Bitcoin, then directed a portion through coin mixers such as Wasabi Wallet and CryptoMixer.
That attack underscored the limitations of blockchain transparency. The Center for Strategic and International Studies (CSIS) noted in its analysis of the Bybit case that while investigators identified many of the involved wallets within days, the speed of transfers across decentralized exchanges, cross-chain bridges, and jurisdictions allowed a substantial portion of the stolen cryptocurrency to keep circulating before law enforcement could intervene.
TRM's Nick Carlsen, a former FBI analyst, describes the Lazarus Group's methodology as "flood the zone" — a deliberate strategy to overwhelm investigators by generating a high volume of transactions across multiple platforms within a compressed timeframe. The group often holds converted Bitcoin without further activity for extended periods before eventually routing funds into cash-out channels. UN Panel of Experts reports have documented that these cash-out networks frequently rely on over-the-counter brokers operating in China and Southeast Asia who help convert cryptocurrency into fiat currencies.
This context makes the transfer of 121.5 BTC noteworthy. Rather than liquidating stolen assets in a single large transaction, North Korean operators typically move smaller increments over time. If another distribution cycle is underway, exchanges, over-the-counter (OTC) desks, and blockchain investigators may face heightened scrutiny in the coming months.
Sanctioned Wallets Require Market-Wide Screening
The Lazarus Group remains subject to U.S. Treasury sanctions under the Office of Foreign Assets Control's DPRK3 program, which designates cryptocurrency addresses connected to the organization. Any entity processing transactions involving these addresses risks sanctions exposure, meaning funds labeled as originating from Lazarus must be treated as an immediate compliance concern.
The FBI has attributed multiple cryptocurrency thefts to the group, including the $100 million Harmony Horizon Bridge hack of 2022 and the February 2025 Bybit hack, which the bureau linked to North Korea under the codename "TraderTraitor."
The recent 121.5 BTC transfer matters less for its dollar value than for what it signals. Assets stolen by North Korean hackers can resurface months or even years after the initial theft, and even a relatively small transaction from a known Lazarus wallet can mark the beginning of a broader laundering operation — as long as such addresses remain active.