Escalation of Web3 Attacks
-

Since 2021, the Lazarus Group's activities in the Web3 space intensified, stealing billions from DeFi projects. Some high-profile thefts include a $625 million Axie Infinity Ronin Network Hack in March 2022 and Poly Network in August 2021. In 2023, the concentration of this group on the CeFi targets could be noted mainly in the third quarter, when this group managed to steal $208.6 million, or 30% of all losses in the quarter, to the crypto ecosystem. Further hacks during the period included CoinEx, Alphapo, Stake, and Coinspaid, where a total of $308.6 million was disclosed as being lost between June and September 2023.In 2024 and 2025, the group's attacks shifted focus towards centralized exchanges. In June 2023, they breached Atomic Wallet, stealing over $100 million from users. By February 2025, they carried out their largest crypto heist yet, infiltrating Bybit's multi-signature wallet solution called Safe{Wallet}, and making off with $1.5 billion in Ethereum. These incidents underscore the group's evolving tactics and their focus on high-value targets, exploiting both CeFi and DeFi vulnerabilities.