A wallet cluster associated with North Korea’s Lazarus Group transferred 121.5 Bitcoins, worth around $7.74 million, roughly an hour before the blockchain tracker Lookonchain identified the transaction on Thursday. The amount is significant, given that transactions from wallets tied to Lazarus Group generally do not go unnoticed.
The importance lies more in what this kind of movement could imply than its actual value. By April of 2026, North Korea-related hackers made up 76% of all hacking-related cryptocurrency thefts. Even small transactions could be evidence that stolen funds are being laundered once again.
Lazarus wallets stir again
According to Lookonchain, wallets associated with the Lazarus Group moved 121.5 BTC, estimated to be about $7.74 million. However, the company did not reveal the whereabouts of the funds and did not tie it to a specific previous theft.
By itself, the transaction holds little meaning in a market with daily trading volume of tens of billions of dollars. What makes it significant, however, is the wallet in question. Lazarus addresses attract significant scrutiny because each transaction has the potential to move stolen cryptocurrencies closer to conversion into usable money.
The Lazarus Group hackers moved 121.5 $BTC ($7.74M) an hour ago.https://t.co/kpMHWnl7iQ pic.twitter.com/5qrmlvxMGd
— Lookonchain (@lookonchain) July 30, 2026
TRM Labs estimated that North Korean hackers stole about $577 million in cryptocurrency through April 2026. Nearly all of it came from two attacks: a $285 million exploit of Drift Protocol on April 1 and a $292 million attack on a KelpDAO bridge on April 18. Although the incidents represented just 3% of recorded hacks, they accounted for 76% of the year’s stolen value.
The trend has gotten stronger over the years. The experts at TRM believe that North Korea’s contribution to the global volume of cryptocurrency theft increased from below 10% in 2020 and 2021 to 22% in 2022, 37% in 2023, 39% in 2024, 64% in 2025, leading to a new record in the current year. Since 2017, North Korean hackers have stolen over $6 billion worth of digital currencies, securing the status of the biggest state-sponsored cyber threat in the world.
Bitcoin, THORChain, and the flood-the-zone playbook
The recent activities resemble the money laundering pattern reported by TRM following the Bybit hack in February 2025, when the North Koreans stole around $1.5 billion worth of Ether, the largest theft of cryptocurrency to date. The investigation revealed that the criminals promptly sent the funds through THORChain to convert them into Bitcoin and thereafter sent a part of the stolen funds through coin mixers such as Wasabi Wallet and CryptoMixer.
The attack highlighted the shortcomings of blockchain transparency. The Center for Strategic and International Studies (CSIS) noted in its study of the Bybit case that although the investigation managed to detect many of the wallets in a matter of days, the speed of transfers through decentralized exchanges, bridges, and countries allowed much of the illegally obtained cryptocurrency to continue to circulate before law enforcement took action.
Investors’ confidence would likely be bolstered more by establishing strong cybersecurity standards and implementing uniform regulations than by relying primarily on post-theft enforcement.
TRM’s Nick Carlsen, an ex-FBI analyst, refers to the Lazarus group’s strategy as “flood the zone,” which aims to confuse investigators by triggering numerous transactions across various platforms within a brief period. Frequently, the group does not do anything with the converted Bitcoin for some time and later on moves the funds into cash-out channels.
As a result, the transfer of a mere 121.5 BTC is noteworthy. Rather than attempting to liquidate stolen assets in one large transaction, North Korean criminal outfits usually prefer to move smaller amounts over time. However, if it turns out that yet another distribution cycle is at play, exchanges, OTC traders, and blockchain investigators could see more scrutiny coming their way in the upcoming months.
Sanctioned wallets the whole market must screen
The Lazarus Group is still subject to U.S. Treasury sanctions as part of the DPRK3 program by the Office of Foreign Assets Control, which involves cryptocurrency addresses connected to the organization. Managing the money of these addresses puts companies at risk of sanctions, which means that funds labeled as being from the Lazarus Group must be treated as an immediate compliance concern.
The FBI has assigned the theft of cryptocurrencies to the group several times. Among the thefts it attributed to the group are the $100 million Harmony Horizon Bridge hack of 2022 and also the Bybit hack, which was connected to North Korea with the codename “TraderTraitor” in February 2025.
The recent transfer of 121.5 BTC is less important for its volume than for the meaning it carries. A case in point is that the hacked assets recovered by North Korean hackers may continue to reappear months or years after the theft. Even an insignificant transaction can indicate the start of a big laundering operation as long as such wallets are still operating.
The smartest crypto minds already read our newsletter. Want in? Join them.
免责声明:本文提供的信息不是交易建议。BlockWeeks.com不对根据本文提供的信息所做的任何投资承担责任。我们强烈建议在做出任何投资决策之前进行独立研究或咨询合格的专业人士。