Lazarus and North Korea’s crypto theft network has now been tied to nearly $7.8 billion
The September 2026 Bitget hack has pushed North Korea-linked cyber activity back to the center of the crypto security debate. Bitget first disclosed losses of about $351.6 million, then revised the confirmed amount of transferred assets to $387.5 million. TRM Labs said parts of the laundering trail overlapped with earlier North Korea-linked attacks including Bybit and AFX Bridge, while Elliptic assessed a North Korea connection as “highly likely.”
That latest case sits inside a much longer record. Over the past decade, investigators, law enforcement agencies, and security firms have used names such as Lazarus Group, BlueNoroff, APT38, TraderTraitor, Citrine Sleet, Andariel, and Famous Chollima to describe overlapping North Korean cyber units tied to the Reconnaissance General Bureau, or RGB. The naming varies by firm, but the operational pattern is consistent: financial theft, crypto-focused intrusions, malware campaigns, supply-chain compromises, espionage, and covert workforce infiltration.
Publicly attributed crypto thefts linked by governments and law enforcement to North Korean actors exceed $3.1 billion based on major named cases alone, including Ronin Bridge, Harmony Horizon Bridge, Atomic Wallet, Stake, DMM Bitcoin, and Bybit. Broader blockchain-tracing estimates are much higher. Chainalysis put the cumulative total at no less than $6.75 billion by the end of 2025, and with the still-unresolved Bitget case added to the picture, the running total cited in the source article approaches $7.8 billion as of September 2026.