Paradigm’s Samczsun warns there’s ‘more to the DPRK than just the Lazarus Group’

Both samczsun and ZachXBT have issued warnings after the Bybit hack last month

article-image

Artwork by Crystal Le

share

This is a segment from the Empire newsletter. To read full editions, subscribe.


There’s no denying that North Korea’s Lazarus Group is a threat, especially as crypto works overtime to be seen as a safe and acceptable industry (sorry degens, there are still corners for you). 

Paradigm’s samczsun highlighted the good, the bad, and the ugly, a month after the Lazarus Group pulled off the biggest digital heist in history. Oof, that hurt to write. 

The upside is that only one bad actor (which, I guess on the downside, is North Korea) has been so successful in stealing funds. 

But “there’s more to the DPRK than just the Lazarus Group,” he warned.

Unfortunately, the team would later find out that the group had managed to compromise SafeWallet’s own infrastructure, deploying “a malicious payload specifically targeting Bybit. This was a level of sophistication that no one had considered or been prepared for, and it was a major update to many of our threat models.”

But there are ways to stay safe, samczsun noted. He urges caution across the board for individual folks like us. And organizations should “install Mobile Device Management (MDM) and Endpoint Detection and Response (EDR) software” on work devices for security prior to any hack and to ensure visibility afterwards. 

Samczsun’s tune was slightly more optimistic than Paradigm advisor ZachXBT, who earlier this month said the effort to try to freeze funds tracked to the Bybit attack had been an “eye-opening” experience. 

From ZachXBT’s Telegram group.

“The industry is unbelievably cooked when it comes to exploits/hacks,” he wrote. 

Samczsun’s holding out hope that the FBI’s unit dedicated to both tracking and preventing DPRK attacks is strong, an encouraging sign given his recent work with them.

Whether or not the FBI paired with super sleuths such as ZachXBT and samczsun — alongside members of Seal 911 — remains to be seen.


Get the news in your inbox. Explore Blockworks newsletters:

  • Blockworks Daily: The newsletter that helps thousands of investors understand crypto and the markets, by Byron Gilliam.
  • Empire: Start your morning with the top news and analysis to inform your day in crypto.
  • Forward Guidance: Reporting and analysis on the growing intersection of crypto and macroeconomics, policy and finance.
  • 0xResearch: Alpha directly in your inbox. Market highlights, data, degen trade ideas, governance updates, token performance and more.
  • Lightspeed: Built for Solana investors, developers and community members. The latest from one of crypto’s hottest networks.
  • The Drop: For crypto collectors and traders, covering apps, games, memes and more.
  • Supply Shock: Tracking Bitcoin’s rise from internet plaything worth less than a penny to global phenomenon disrupting money as we know it.
Tags

Upcoming Events

Industry City | Brooklyn, NY

TUES - THURS, JUNE 24 - 26, 2025

Permissionless IV serves as the definitive gathering for crypto’s technical founders, developers, and builders to come together and create the future.If you’re ready to shape the future of crypto, Permissionless IV is where it happens.

Old Billingsgate

Mon - Wed, October 13 - 15, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Research Report Templates.png

Research

Fluid's hybrid money market & DEX protocol has grown rapidly since launch in December of 2024.

article-image

PitchBook’s Robert Le said crypto projects focused on institutional use cases are the focus

article-image

The decentralized AI firm designed ODS to be owned by the community in an effort to promote more decentralized AI

article-image

The non-profit’s launch and big-name hires aim to grow Solana’s footprint in Washington

article-image

February jobs report shows fewer jobs and layoffs on the rise, with DOGE federal layoffs likely not yet reflected

article-image

Tomorrow’s tariff announcements are likely to impact the market, though they may not bring certainty

article-image

Circle filed a public prospectus with the SEC in one of its first steps to going public