Lazarus strikes again: massive crypto heist rocks ethereum ecosystem

The notorious North Korean hacking group Lazarus has struck again, pulling off a massive cryptocurrency heist that has sent shockwaves through the Ethereum ecosystem.

Lazarus

Lazarus' latest exploit: a $250m+ crypto raid

According to reports, the cybercriminals targeted a popular online investment platform, making off with over 250 million euros in the process. This brazen attack echoes previous exploits by the group, which has been linked to the North Korean government and has a history of orchestrating massive crypto heists.

Experts point to Lazarus' signature modus operandi as a key indicator of their involvement, noting that the attack bears striking similarities to previous raids on WazirX and DMM Bitcoin in 2024. The stolen cryptocurrency, a token representing staked Ethereum (ETH) on the EigenLayer protocol, was valued at approximately 116,500 units, equivalent to around 124,600 ETH or 3,730 BTC.

LayerZero, the company whose servers were compromised in the attack, confirmed the incident, with preliminary indicators suggesting the involvement of a highly sophisticated state-backed actor, likely Lazarus. The group's notorious exploits have been linked to funding the North Korean regime's weapons program, with a 2024 US report estimating that Pyongyang had stolen over $3,000 million in cryptocurrencies since 2017, and an additional $2,800 million between 2024 and 2025.

While the exact methods used by Lazarus remain unclear, the group is known for its ability to exploit vulnerabilities in cryptocurrency platforms and protocols. In this case, they allegedly leveraged a collateral-based money laundering scheme, depositing the stolen funds into lending protocols like Aave v3 and requesting other assets, such as Wrapped Ether (WETH), in return, effectively generating a massive debt across affected platforms.

As the cryptocurrency world reels from this latest attack, experts warn of the ongoing threat posed by Lazarus and other sophisticated hacking groups. The incident serves as a stark reminder of the urgent need for enhanced security measures to protect the integrity of the cryptocurrency ecosystem.