COMING SOON: A New Way to Earn Passive Income with DeFi in 2025 LEARN MORE

Lazarus starts laundering the 400,000 Ether it stole from Bybit

In this post:

  • Lazarus just started laundering 5,000 ETH from the Bybit hack, using eXch (a mixer) and Chainflip to bridge funds to Bitcoin.
  • ZachXBT exposed the laundering path, but later deleted his Telegram post. He also linked the Bybit hack to Phemex using an overlap address.
  • Bybit saw $4 billion in inflows in 12 hours, mostly from cold wallets to hot wallets for withdrawals and external bridge loans.

North Korean hacking group Lazarus just started laundering 5,000 ETH from the Bybit $1.5 billion hack, kicking off their typical complex operation to clean the money.

Blockchain investigator ZachXBT exposed the movement, sharing wallet addresses and timestamps in a Telegram update, but it was shortly after confirmed with Bybit CEO Ben Zhou via an X post, though less than an hour later, Zach deleted the post.

The stolen crypto first landed in a new Ethereum address, then got routed through eXch, a centralized mixer, before being bridged to Bitcoin via Chainflip.

Bybit sees massive inflows as funds move

Meanwhile, Bybit is seeing massive inflows amid the disaster. Data from SoSoValue and TenArmor shows that in the past 12 hours, the exchange received over $4 billion in deposits, with 63,168.08 ETH, $3.15 billion in USDT, $173 million in USDC, and $525 million in CUSD.

Lazarus starts laundering the 400,000 Ether it stole from Bybit

Most of this comes from Bybit cold wallets to hot wallets, fueling withdrawals and bridge loans from external liquidity providers.

Minutes after deleting the Telegram post, Zach made a post on X, connecting the Bybit hack to the Phemex hack, exposing an overlap in stolen funds. “Lazarus Group just connected the Bybit hack to the Phemex hack directly on-chain, commingling funds from the initial theft address for both incidents,” Zach said in his post.

See also  Hamster Kombat tries its market luck one more time - Season 2 gameplay

A shared address—0x33d057af74779925c4b2e720a820387cb89f8f65—links the two attacks, according to Zach. Bybit’s Ben Zhou confirmed that withdrawals are now back to full speed.

Lazarus starts laundering the 400,000 Ether it stole from Bybit.

“12 hours from the worst hack in history. ALL withdrawals have been processed. Our withdrawal system is fully back to normal pace. You can withdraw any amount and experience no delays,” he said.

Zhou also promised a full incident report and new security measures in the coming days. “Bybit will come out with a full incident report as well as security measures in the next few days. I will personally keep you all posted.”

Meanwhile, Elliptic, Chainalysis and Arkham Intelligence tracked the stolen ETH across 39 different addresses as it was quickly shuffled and offloaded, then Arkham announced a $36K bounty for the hacker’s identity and Zach won by exposing Lazarus shortly after.

According to records kept by Elliptic, the Bybit hack is now the largest crypto theft in history, overtaking the $611 million stolen from Poly Network (2021), and $570 million drained from Binance (2022).

Lazarus starts laundering the 400,000 Ether it stole from Bybit.

Lazarus has a history of draining crypto platforms to fund North Korea’s regime. The group first hit South Korean exchanges in 2017, stealing $200 million in Bitcoin. Since then, they’ve perfected advanced crypto laundering methods, hiding funds through mixers, bridges, and obscure DeFi protocols.

See also  THORChain hits unwanted $3B volume milestone as Bybit hackers revive activity on the struggling network

Elliptic’s Tom Robinson confirmed Friday that all stolen wallet addresses have been flagged to prevent laundering through major exchanges.

“The more difficult we make it to benefit from crimes such as this, the less frequently they will take place,” Robinson wrote in a post.

Cryptopolitan Academy: Tired of market swings? Learn how DeFi can help you build steady passive income. Register Now

Share link:

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Most read

Loading Most Read articles...

Stay on top of crypto news, get daily updates in your inbox

Editor's choice

Loading Editor's Choice articles...
Subscribe to CryptoPolitan