US Treasury imposed sanctions against North Korean crypto hackers
The FBI linked the Ronin sidechain hack to the DPRK hacker group Lazarus
15.04.2022 - 11:45
869
2 min
0
What’s new? The US Treasury Department has added to the sanctions list a wallet containing 148 000 ETH from the Ronin Network hack. The Federal Bureau of Investigation (FBI) linked the sidechain attack to the Lazarus hacker group from North Korea, according to the Ronin blog. The FBI conducted the investigation jointly with the US Treasury Department.
Details of the investigation. The Ronin Network hack took place on March 29, 2022, and the hackers managed to withdraw over $625 million in cryptocurrency (173 600 ETH and 25,5 million USDC). The FBI stated that another hacking group, Advance Persistent Threat 38 (APT38), was also involved in the hack and used malware to steal the funds.
Analyst firm Elliptic noted that the attackers had already managed to launder 18% of the stolen assets. The US Treasury Department has warned that any wallets that will interact with the sanctioned address will also be blocked.
What had happened before? Former Ethereum developer Virgil Griffith was sentenced to five years in prison for collaborating with the DPRK. He provided North Korea with information about the use of blockchain and cryptocurrencies to circumvent sanctions.
The US Department of Treasury also imposed sanctions on the Garantex crypto exchange and the Hydra darknet marketplace. The agency stressed that these measures should prevent Russia from evading sanctions by using cryptocurrencies.
Useful material?
Incidents
The company is linking the incident to a compromised private key on a service wallet, rather than a smart contract exploit
May 22, 2026
Incidents
Following the incident, the project temporarily halted trading operations and node activity.
May 15, 2026
Incidents
The user spent weeks unsuccessfully trying to guess the password until Claude helped find an old wallet backup file
May 14, 2026
Crypto regulations
Authorities are introducing mandatory registration for companies handling cross-border crypto transactions
May 8, 2026
Incidents
According to Blockaid, the attack may have been carried out by the same hacker behind the 1inch Fusion V1 exploit.
May 7, 2026
Incidents
The attacker gained administrative access and altered contracts to drain user funds
Apr 30, 2026
Telegram
Twitter