Worked example · 2026
Bybit $1.5B Hack Laundering Continuation into 2026 — DPRK / Lazarus — 2026
Summary
The Bybit hack (February 21, 2025) resulted in the theft of approximately $1.5B in ETH and staked ETH derivatives from Bybit's cold wallet infrastructure. Lazarus Group (OAK-G01) compromised Bybit's Safe{Wallet} multisig signing infrastructure through a social-engineering supply-chain attack on the Safe{Wallet} frontend, tricking Bybit signers into approving a malicious contract upgrade that redirected funds to Lazarus-controlled addresses.
The laundering operation — converting $1.5B in stolen ETH into clean assets — was the largest laundering campaign in cryptocurrency history. Lazarus Group employed a layered laundering architecture:
THORChain swap laundering (primary rail). THORChain's cross-chain swap protocol allowed Lazarus to convert ETH to BTC without KYC. THORChain's swap volume spiked to multiples of its baseline during the active laundering windows, with Lazarus transactions accounting for a material fraction of total protocol volume. THORChain's decentralised design meant there was no central entity that could freeze or censor the swaps.
DEX and aggregator swaps. Lazarus used DEX aggregators (1inch, CoWSwap, Odos) to swap ETH for USDC, USDT, DAI, and other stablecoins, spreading swaps across multiple pools to minimise per-pool price impact.
CEX deposit layering. Lazarus deposited laundered funds on centralised exchanges with KYC/AML gaps, structuring deposits across multiple accounts, jurisdictions, and time windows to avoid triggering automated AML thresholds.
Mixer / privacy-protocol routing. Remaining ETH proceeds were routed through Tornado Cash analogues, Railgun privacy pools, and DEX-based mixing patterns.
The laundering operation continued through 2026 because the sheer volume of stolen assets ($1.5B) exceeded the throughput capacity of any single laundering rail. Lazarus had to pace the laundering to avoid saturating THORChain's pools (which would cause extreme slippage on large swaps), avoid triggering exchange AML freezes (which would lock funds), and avoid mixer pool exhaustion (which would reduce anonymity-set effectiveness).
By mid-2026, TRM Labs and Chainalysis estimated that approximately $900M–$1.1B of the stolen funds had been laundered, with $400M–$600M remaining in known Lazarus addresses awaiting laundering capacity. The pace of laundering was expected to continue through 2026–2027.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2025-02-21 | Bybit hacked; ~$1.5B in ETH and staked ETH derivatives stolen by Lazarus Group (OAK-G01) | T15 + T11 |
| 2025-02 to 2025-04 | Initial laundering phase: Lazarus converts stolen ETH through THORChain, DEXes, and CEX deposits | T7.001 + T7.002 |
| 2025-04 to 2025-12 | Mid-phase laundering: Lazarus paces laundering across multiple rails; THORChain volume remains elevated | T7.001 + T7.002 + T7.005 |
| 2026-01 to 2026-05 | Continued laundering: ~$900M–$1.1B estimated laundered; ~$400M–$600M remaining in known Lazarus addresses | T7.001 + T7.002 + T7.005 + T8.001 |
| 2026–2027 (projected) | Laundering expected to continue as remaining funds are paced through available rails | T7 (ongoing) |
Public references
- FBI, TRM Labs, Chainalysis, and Elliptic laundering-tracking reports (2025–2026)
- THORChain swap-volume analytics showing Bybit-laundering-window volume spikes
- On-chain forensic analysis of Lazarus laundering address clusters and fund-flow graphs
- See
examples/2025-02-bybit.mdfor the initial hack andexamples/2025-02-bybit-thorchain-laundering.mdfor the initial THORChain laundering phase
Discussion
The Bybit laundering continuation into 2026 anchors the T7 × 2026 matrix cell and provides the canonical "multi-year laundering campaign" example for the OAK taxonomy. The incident demonstrates that laundering is not an instantaneous post-exploit step but a paced operation whose duration is determined by available laundering-rail throughput.
The structural insight for T7 is that laundering capacity is a measurable property of the crypto ecosystem: the aggregate daily throughput of all no-KYC swap protocols (THORChain, Maya, Chainflip), the pool depth of all mixer/privacy protocols (Tornado Cash analogues, Railgun, privacy pools), and the deposit limits of all weak-KYC exchanges collectively define the maximum daily laundering rate for a large-scale theft. A $1.5B theft against a $10M/day laundering-capacity ceiling requires 150+ days of sustained laundering — a constraint that forces the attacker to maintain operational security over an extended window and gives investigators an extended detection opportunity.
The Lazarus Group's laundering tradecraft — pacing, multi-rail distribution, exchange-deposit structuring — is the state-of-the-art reference for T7. Future T7 incident entries should reference the Bybit 2025–2026 laundering timeline as the baseline for large-scale laundering duration and throughput analysis.