Lazarus Group

Analysis

North Korean IT Workers Have Been Building DeFi Protocols Since 2020. The $285M Drift Hack Shows Why That Matters.

A researcher says over 40 DeFi platforms have employed DPRK state-linked developers. Their seven years of blockchain experience is, as she notes, not a lie. The Drift Protocol exploit was not a code bug. It was a six-month intelligence operation conducted by a North Korean state-affiliated group that attended conferences, deposited real capital, and waited.

By Ramy Morton
News

Prosecutors Reject Tornado Cash Co-founder's Copyright Defense. The Retrial Is Still Coming.

SDNY US Attorney Jay Clayton has pushed back against Roman Storm's attempt to use a 2026 Supreme Court copyright ruling as a defense against the two charges a jury deadlocked on last year. The case is a live contradiction: the same DOJ that issued a memo ending 'regulation by prosecution' on crypto platforms is now pursuing a retrial that could send a developer to prison for 40 years for writing open-source code.

By Ramy Morton

Lazarus Group Overview

Lazarus Group is the North Korean state-sponsored hacking operation responsible for the largest crypto thefts in history, from Ronin to Bybit. This tag tracks its exchange and bridge exploits, its laundering through mixers and cross-chain hops, the sanctions and investigations targeting it, and its role funding the DPRK regime. Coinliva covers the hacks, the traced funds, and the security lessons for exchanges and protocols.