Disclaimer: Information found on CryptoreNews is those of writers quoted. It does not represent the opinions of CryptoreNews on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoreNews covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.
Lazarus Hackers Transfer $19.4 Million in Bitcoin

The North Korean hacker group Lazarus transferred 244.148 Bitcoin, worth approximately $19.4 million, analytics platform Lookonchain reported.
The recipient address is unknown, so it is unclear whether the Bitcoin was sent to an exchange, a crypto mixer, or another address controlled by the hackers or North Korean authorities. Without identifying the recipient address, the movement of Bitcoin does not necessarily indicate that the coins are being prepared for sale.
The Lazarus Group hackers are active again, transferring 244.148 $BTC ($19.42M) an hour ago.https://t.co/kpMHWnl7iQ pic.twitter.com/OaJehtXnNa
— Lookonchain (@lookonchain) August 28, 2026
This is already the second major transfer of funds by North Korean hackers in a month. On August 12, Lazarus transferred 262.2 BTC, worth $16.6 million, from an address identified by Lookonchain to a new crypto address. Last March, 44.07 BTC, then worth $3.76 million, were sent from crypto wallet addresses belonging to Lazarus to five unknown addresses. The transactions were tracked by Arkham Intelligence analysts.
In early August, Dubai-based crypto exchange Bybit filed a lawsuit against North Korea and the Lazarus Group in the U.S. District Court for the District of Columbia, seeking to compel the defendants to return $1.5 billion in crypto assets stolen in the February 2025 hack. The lawsuit also names the Reconnaissance General Bureau of North Korea. A federal judge issued an order prohibiting the defendants from transferring or selling assets related to this case.
The U.S. Federal Bureau of Investigation (FBI) attributed the attack on Bybit to North Korean hackers from the TraderTraitor unit. According to the agency, they converted part of the stolen funds into Bitcoin and distributed them across thousands of addresses on various blockchains. The FBI anticipated the subsequent movement of assets and their exchange for fiat currency, prompting it to contact exchanges, bridges, decentralized finance (DeFi) services, analytics companies, and node operators to request the blocking of transactions associated with identified addresses.
Last year, SlowMist warned about new malware called OtterCookie, which Lazarus hackers are targeting at crypto industry workers. Previously, Silent Push warned about fake companies created by Lazarus hackers to steal cryptocurrency from developers.