Skip to main content

North Korea pulled huge $600 million crypto heist, feds say

The U.S. Department of the Treasury managed to track down the culprit of the massive Axie Infinity cryptocurrency heist. It turns out that a North Korean hacker group called Lazarus stands behind the theft, which amounted to over $600 million worth of crypto being stolen.

In response to the theft, the group involved had been added to the U.S. international sanctions list.

THREAD: Updates to OFAC’s SDN designation for Lazarus Group confirm that the North Korean cybercriminal group was behind the March hack of Ronin Bridge, in which over $600 million worth of ETH and USDC was stolen.

— Chainalysis (@chainalysis) April 14, 2022

The attack took place in March of this year and it targeted Axie Infinity, a blockchain-based game that involves cryptocurrency transactions. Although the game is based on Ethereum, it utilizes a blockchain called Ronin. This allows the players to perform all the necessary transactions without paying the hefty fees of the standard Ethereum blockchain.

The two chains are connected by a digital bridge. It’s a helpful workaround for day-to-day users, but unfortunately, an exploit in the bridge between Ethereum and Ronin resulted in a massive theft. The hack conducted by the Lazarus Group resulted in 173,600 Ethereum and 25.5 million USDC being stolen. USDC is a so-called stable coin, which means it’s pegged to the U.S. dollar. At the time of the theft, the two currencies pooled together amounted to over $600 million.

Initially, it was unclear whether the Specially Designated Nationals List update referred to the Axie Infinity heist specifically. However, the Department of the Treasury confirmed to PC Gamer that the new entry refers to the hack conducted by Lazarus. The cryptocurrency wallet that collected the stolen funds was discovered by the FBI as part of an ongoing investigation of North Korea.

Lazarus is a state-sponsored group of hackers, and this isn’t the first time we’ve heard about their attacks. According to Chainalysis, the group stole at least $400 million worth of digital assets in 2021. However, this means that the 2022 Axie Infinity hack is a huge escalation, seeing as the group managed to steal over $600 million in one go.

Illustration of a woman putting a bitcoin into a piggy bank.
Taylor Frint/Digital Trends Graphic

The funds obtained through these crypto attacks are most likely used to fund North Korea’s weapon programs. Elliptic, a cryptosecurity firm, estimates that the country has already laundered 18% of the $600 million Lazarus managed to obtain.

An anonymous FBI representative said to PC Gamer: Through our investigation, we were able to confirm Lazarus Group and APT38, cyber actors associated with the Democratic People’s Republic of Korea (DPRK), are responsible for the theft of $620 million in Ethereum reported on March 29th. The FBI, in coordination with Treasury and other U.S. Government partners, will continue to expose and combat the DPRK’s use of illicit activities — including cybercrime and cryptocurrency theft — to generate revenue for the regime.”

This is a huge hit for Axie Infinity, a game that relies on helping users profit rather than just to have fun. Sky Mavis, the developers of Axie Infinity, said that additional security measures are being added to the Ronin Bridge. Hopefully, this time around, the bridge will be secure enough to not be breached.

Editors' Recommendations

Monica J. White
Monica is a UK-based freelance writer and self-proclaimed geek. A firm believer in the "PC building is just like expensive…
How to build a budget gaming PC build for under $500
This gaming PC rig costs less than most smartphones. Here's what we put inside
should you buy a console style gaming pc computer desk

Who says a gaming PC has to be expensive? You can get a lot of gaming PC for under $500 if you spend it carefully. That's where we come in. This guide will round up the best gaming hardware deals available today to give you a great starting point for your own budget gaming PC build for under $500.

If you have a little more to spend, check out our guides on the best gaming PCs of 2024, and also the best gaming PC deals right now.
The build and what it can do
We’ll go into more detail about the hardware we've chosen below, but this is a quick summary of what we've picked if you want to just dive in and buy them right now.

Read more
These 7 announcements stole the show at Computex 2024
A sign for Computex in Taipei.

This year, Computex was absolutely packed with announcements. Even early reveals like the Asus ROG Ally X seem downright puny compared to the wave of new products companies like AMD and Intel showed off at the event.

We spent more than a week on the ground in Taipei for Computex, running to various hotels and scouring the show floor to find the biggest, most exciting new products coming out this year. Here are the seven announcements you need to know about.
Best desktop component: AMD Ryzen 9000

Read more
DuckDuckGo’s new AI service keeps your chatbot conversations private
DuckDuckGo

DuckDuckGo released its new AI Chat service on Thursday, enabling users to anonymously access popular chatbots like GPT-3.5 and Claude 3 Haiku without having to share their personal information as well as preventing the companies from training the AIs on their conversations. AI Chat essentially works by inserting itself between the user and the model, like a high-tech game of telephone.

From the AI Chat home screen, users can select which chat model they want to use -- Meta’s Llama 3 70B model and Mixtral 8x7B are available in addition to GPT-3.5 and Claude -- then begin conversing with it as they normally would. DuckDuckGo will connect to that chat model as an intermediary, substituting the user's IP address with one of their own. "This way it looks like the requests are coming from us and not you," the company wrote in a blog post.

Read more