Lazarus Group Moves 41,000 Ethereum Nabbed From Harmony Bridge Hack

Will McCurdy
Will McCurdy January 16, 2023
Updated 2023/01/16 at 4:02 PM
4 Min Read

North Korea-linked cybercrime syndicate Lazarus Group has reportedly transferred $63.4 million in Ethereum from 2022’s mammoth Harmony bridge hack, depositing it on Binance, Huobi, and OKX.

According to on-chain sleuth ZachXBT, the group used the privacy and anonymity system Railgun before consolidating the funds and depositing them on the exchanges.

Railgun is an Ethereum-based smart contract system that lets users obscure the nature of their crypto transactions, removing identifying information.

The sleuth claimed that the transfers, made on January 13, involved 350,000 separate wallet addresses.

Binance CEO Changpeng “CZ” Zhao said that his team, in collaboration with Huobi, had detected the funds’ movements, which they then froze and recovered.

The Binance chief claimed that the total recovery came to 124 Bitcoin, suggesting that the attackers had converted funds from ETH to BTC.

Though Lazarus reportedly originally made the illegitimate transfers in the form ETH, these tokens could have been later swapped for BTC at many points during the mixing and consolidating process.

Harmony hack and Lazarus Group

In June 2022, the Harmony attack saw hackers run off with $100 million after compromising the project’s token bridge. A blockchain bridge that connects different, incompatible blockchains together.

Many, including blockchain analytics company Elliptic, attributed the attack to the North Korean state-sponsored hacking group Lazarus.

The group was said to have used the now-sanctioned cryptocurrency mixer Tornado Cash, a tool not dissimilar to Railgun.

It’s unknown, what if any, steps have been taken by OKX, in response to the alleged criminal transfers.

CZ explained that Binance’s security teams are to an extent collaborative and talk to other exchanges, but added that “not all” other exchanges are collaborative.

The CEO added that he is not in those security chats himself and as a result, doesn’t “know the details.”

Decrypt has contacted Binance, Huobi, and OKX about the transfers and their responses.

Despite the size of Lazarus’s attack on Harmony, the hack is just a small portion of the overall number of funds the cybercrime syndicate has been implicated in stealing.


Lazarus was also implicated, to give just an example, in the March 2022 attack on the Ronin Network, which was estimated at being worth about $622 million. The group was also tied to a scheme that impersonated venture capital companies to spread malware to various crypto-related firms.


Stay on top of crypto news, get daily updates in your inbox.

This article was first published on
Share this Article