Lazarus Group just connected the Bybit hack to the Phemex hack

2025-02-22 Zach XBT

https://archive.is/bM8I9

Thumbnail for Lazarus Group just connected the Bybit hack to the Phemex hack

The archived thread reports on-chain links between the Bybit, Phemex, and BingX theft clusters attributed in the thread to Lazarus Group. It cites commingling between Bybit and Phemex theft addresses, test transactions, connected wallets used before the Bybit exploit, and later movement tying a BingX-linked address into the same cluster. The thread also references ZachXBT’s Arkham bounty submission, which it says provided transaction analysis, wallet links, forensic graphs, and timing evidence for Lazarus attribution. The value of the source is the claimed blockchain clustering rather than new malware or intrusion-chain detail.

Related Actors

Related Reports

« Back