North Korea Lazarus Group Crypto Hacks: 2026 Timeline
The North Korea Lazarus Group crypto exchange hacks 2026 timeline includes confirmed FBI attributions for Ronin (2022), DMM Bitcoin (2024), and Bybit (2025), a forensics-based link to KuCoin (2020), and a reported but unconfirmed pattern match in Bitget's 2026 incident. Mt. Gox, Coincheck, and Bitfinex carry no such attribution.
North Korea Lazarus Group crypto exchange hacks 2026 timeline refers to the chronological pattern of exchange breaches that US and international investigators have formally or informally linked to North Korean state-sponsored hacking units, chiefly the group known as Lazarus and tracked under related names like APT38 and TraderTraitor. Not every major exchange hack carries this attribution. Some of the industry’s largest losses, including Mt. Gox and Coincheck, have never been tied to North Korea by any credible investigation.
I’ve been trading perps across a couple dozen exchanges since 2019, and one pattern has become impossible to ignore: the hacks that get a formal nation-state attribution almost always target the same piece of infrastructure, the systems that authorize and move funds out of cold storage. This piece isn’t a dollar-amount ranking (we already have that at our biggest crypto exchange hacks ranking). It’s a walk through which incidents actually carry a Lazarus attribution, from whom, and how solid that attribution is.
What Is the Lazarus Group and Why Does It Target Exchanges?
Lazarus Group is the name most commonly used for a hacking apparatus that US and UN reporting has linked to North Korea’s government. The US Treasury’s Office of Foreign Assets Control has sanctioned wallet addresses tied to the group on multiple occasions, and the FBI has issued public statements naming Lazarus, or its sub-cluster TraderTraitor, in specific exchange breach investigations. The stated motive across UN Panel of Experts reporting is straightforward: stolen crypto functions as a funding stream, reportedly tied to weapons programs, that’s harder to interdict than traditional sanctions-busting trade.
Exchanges are targeted specifically, rather than random wallets, because that’s where large pooled balances and privileged withdrawal permissions concentrate in one place. A single compromised signer or a manipulated multisig approval can move far more value than phishing individual retail wallets ever could.
The Confirmed Attribution Cases: Ronin, DMM Bitcoin, and Bybit
Three incidents in this timeline carry formal, named government attribution rather than just researcher speculation.
The Ronin Network bridge hack in March 2022 (roughly $625 million, per blockchain analytics estimates cited at the time) was formally attributed to Lazarus Group by the FBI within weeks, with OFAC sanctioning the associated wallet address soon after. It remains one of the clearest, fastest official attributions on record for a crypto hack.
DMM Bitcoin’s May 2024 breach, investigated jointly by Japanese authorities and the FBI, received a similar formal attribution to North Korean actors operating under the TraderTraitor label.
Bybit’s February 2025 cold wallet breach, the largest single crypto exchange hack by dollar value to date according to the ranking linked above, was likewise attributed by the FBI to North Korean state-linked hackers. Bybit’s public response and subsequent legal action against North Korea are covered in depth elsewhere on this site; what matters for this timeline is that the FBI attribution came with the same formal weight as Ronin’s.
KuCoin 2020: Forensics-Led Attribution, Not a Government Statement
KuCoin’s September 2020 hack (around $281 million at the time, most of it later recovered or frozen through exchange coordination) sits in a slightly different category. Blockchain forensics firms, notably Chainalysis and Elliptic, traced the stolen funds through wallet clusters and mixing patterns previously associated with Lazarus-linked addresses, and that analysis has been widely cited since. It’s a strong circumstantial case built on fund-flow tracing rather than a direct government-issued statement naming North Korea, which is a meaningfully different standard of proof than the Ronin or Bybit cases. KuCoin itself has not issued a formal attribution statement of its own beyond acknowledging the researcher findings.
Bitget 2026: A Suspected Pattern Still Awaiting Formal Confirmation
Reporting on Bitget’s 2026 incident has pointed to similarities with prior Lazarus-attributed breaches, such as the routing of funds through mixing services and targeting of withdrawal authorization flows. That’s worth stating plainly as suspicion, not fact: no government agency has issued a formal attribution naming North Korea in connection with the Bitget incident as of this writing. If that changes, this timeline entry will need updating, and readers evaluating Bitget as a platform should check the exchange’s own incident disclosures directly rather than relying on pattern-matching alone.
Which Exchange Hacks Have No North Korea Attribution?
This is the part that tends to get glossed over in pattern pieces, so I’ll say it directly: several of the industry’s biggest exchange hacks have no North Korea attribution at all, confirmed or suspected.
- Mt. Gox (2014) — widely linked to insider mismanagement and early, gradual theft; no nation-state attribution from any investigation.
- Coincheck (2018) — attackers were never publicly identified as state-linked by Japanese authorities or independent researchers.
- Bitfinex (2016) — the stolen funds were eventually traced to a US-based couple later arrested and prosecuted, with no North Korea connection reported anywhere in that case.
Lumping these in with Lazarus-attributed hacks just because they’re large is sloppy, and it’s exactly the kind of pattern-matching-without-evidence that makes the genuinely confirmed cases harder to take seriously.
Attribution Status at a Glance
| Incident | Year | Attribution Status | Source Type |
|---|---|---|---|
| Ronin Network | 2022 | Confirmed | FBI + OFAC sanctions |
| KuCoin | 2020 | Suspected, strong | Chainalysis / Elliptic forensics |
| DMM Bitcoin | 2024 | Confirmed | FBI + Japanese authorities |
| Bybit | 2025 | Confirmed | FBI |
| Bitget | 2026 | Suspected, unconfirmed | Researcher pattern-matching |
| Mt. Gox | 2014 | None reported | N/A |
| Coincheck | 2018 | None reported | N/A |
| Bitfinex | 2016 | None reported | N/A |
What the Attribution Pattern Means for Traders and Exchanges
Set the confirmed and strongly-suspected cases side by side and a pattern emerges that has nothing to do with exchange size or region: every one of them involved compromising the systems that approve and move funds out of cold or warm storage, not front-end user accounts. That’s a very different threat model than phishing or SIM-swapping, and it’s why exchange security disclosures increasingly emphasize multisig signer separation and hardware-based approval flows rather than just “we use cold storage” as a blanket claim.
For traders, the practical takeaway isn’t paranoia about any single platform, it’s discipline about balances. Keeping only what you need for active positions on an exchange, checking whether a platform publishes proof-of-reserves, and reading incident disclosures rather than headlines are the boring habits that actually matter here. If you’re still shopping around, our rankings of major exchanges and the individual review for Bybit cover how each platform has handled security disclosure post-incident, and the full ranked hacks list has the dollar-amount comparisons this piece deliberately left out.
Frequently asked questions
What is the Lazarus Group?
Lazarus Group is a hacking collective that United States and United Nations investigators have linked to North Korea's government, also tracked under names like APT38 and TraderTraitor. Reporting from the US Treasury and FBI describes the group's crypto theft as a funding mechanism, distinct from ordinary criminal hacking crews chasing quick profit.
Has Bitget confirmed North Korea was behind its 2026 incident?
No. As of this writing, Bitget has not issued a statement confirming North Korean state involvement in its 2026 incident. Security researchers have reported similarities to prior Lazarus-linked patterns, such as mixer routing and cold wallet targeting, but that is a suspected pattern, not a confirmed attribution.
Which crypto exchange hacks are officially attributed to North Korea?
The FBI has formally attributed the 2022 Ronin Network hack, the 2024 DMM Bitcoin hack, and the 2025 Bybit hack to North Korean state-linked actors. KuCoin's 2020 breach carries a strong attribution from blockchain forensics firms, though it lacks the same level of formal government confirmation as the other three.
How much crypto has Lazarus Group stolen from exchanges in total?
Estimates vary widely depending on which incidents a source counts and how recovered funds are treated, so there is no single reliable cumulative figure worth quoting as fact. For exchange-by-exchange dollar amounts, see our full ranked breakdown of the biggest crypto exchange hacks.
Is my crypto safe from North Korean hackers on regulated exchanges?
No exchange, regulated or not, can claim complete immunity, since these attacks have hit large, well-funded platforms with dedicated security teams. What matters more for an individual trader is using platforms with transparent proof-of-reserves practices and not leaving large balances sitting in hot wallets you don't need for active trading.
Did North Korea hack Mt. Gox or Coincheck?
No credible investigation has attributed either the 2014 Mt. Gox collapse or the 2018 Coincheck hack to North Korean state actors. Mt. Gox is widely linked to insider mismanagement and early theft, while Coincheck's attackers were never publicly identified with any nation-state connection.
How does hack attribution actually work? Is it always confirmed by a government?
Attribution happens on a spectrum. At one end, agencies like the FBI issue formal statements naming a state actor, often backed by US Treasury sanctions on specific wallet addresses. At the other end, private blockchain forensics firms trace fund flows and wallet reuse patterns to make a strong but unofficial case, which is where cases like KuCoin 2020 sit.
Is trading on Bitget or Bybit safe after these incidents?
Both exchanges remained operational and continued honoring withdrawals after their respective incidents, and Bybit in particular published a detailed public response to its 2025 breach. That said, any trader evaluating a platform after a security incident should check the exchange's own security and reserves disclosures directly rather than relying on secondhand summaries.