Paradigm’s Samczsun warns there’s ‘more to the DPRK than just the Lazarus Group’

Both samczsun and ZachXBT have issued warnings after the Bybit hack last month

article-image

Artwork by Crystal Le

share

This is a segment from the Empire newsletter. To read full editions, subscribe.


There’s no denying that North Korea’s Lazarus Group is a threat, especially as crypto works overtime to be seen as a safe and acceptable industry (sorry degens, there are still corners for you). 

Paradigm’s samczsun highlighted the good, the bad, and the ugly, a month after the Lazarus Group pulled off the biggest digital heist in history. Oof, that hurt to write. 

The upside is that only one bad actor (which, I guess on the downside, is North Korea) has been so successful in stealing funds. 

But “there’s more to the DPRK than just the Lazarus Group,” he warned.

Unfortunately, the team would later find out that the group had managed to compromise SafeWallet’s own infrastructure, deploying “a malicious payload specifically targeting Bybit. This was a level of sophistication that no one had considered or been prepared for, and it was a major update to many of our threat models.”

But there are ways to stay safe, samczsun noted. He urges caution across the board for individual folks like us. And organizations should “install Mobile Device Management (MDM) and Endpoint Detection and Response (EDR) software” on work devices for security prior to any hack and to ensure visibility afterwards. 

Samczsun’s tune was slightly more optimistic than Paradigm advisor ZachXBT, who earlier this month said the effort to try to freeze funds tracked to the Bybit attack had been an “eye-opening” experience. 

From ZachXBT’s Telegram group.

“The industry is unbelievably cooked when it comes to exploits/hacks,” he wrote. 

Samczsun’s holding out hope that the FBI’s unit dedicated to both tracking and preventing DPRK attacks is strong, an encouraging sign given his recent work with them.

Whether or not the FBI paired with super sleuths such as ZachXBT and samczsun — alongside members of Seal 911 — remains to be seen.


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Javits Center North | 445 11th Ave

Tues - Thurs, March 24 - 26, 2026

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Flashnote Template.png

Research

Fuse Energy operates as a vertically integrated energy company spanning renewable generation, wholesale trading, retail supply, and distributed energy coordination. Founded in 2022 by ex-Revolut executives Alan Chang and Charles Orr, the company applies fintech scaling principles to energy infrastructure, targeting 10% cost savings versus incumbent utilities through operational efficiency and in-house control across the value chain.

article-image

BTC finished the week up 1.6%, while L2s, RWAs and the treasury trade continued to grind lower

article-image

DTCC moves DTC-custodied Treasuries onchain via Canton, while Lighter’s LIT launches trading at a fees multiple in Hyperliquid territory

article-image

In the 90s, rapt audiences worldwide watched a coffee pot — will that fascination ever turn to crypto?

article-image

Some systems improve by failing — and crypto has no choice

article-image

Yield Basis introduces an IL-free AMM design that already dominates BTC DEX liquidity

article-image

Maybe tokenholders don’t need the rights that corporate shareholders have come to expect

Newsletter

The Breakdown

Decoding crypto and the markets. Daily, with Byron Gilliam.

Blockworks Research

Unlock crypto's most powerful research platform.

Our research packs a punch and gives you actionable takeaways for each topic.

SubscribeGet in touch

Blockworks Inc.

133 W 19th St., New York, NY 10011

Blockworks Network

NewsPodcastsNewslettersEventsRoundtablesAnalytics