Paradigm’s Samczsun warns there’s ‘more to the DPRK than just the Lazarus Group’

Both samczsun and ZachXBT have issued warnings after the Bybit hack last month

article-image

Artwork by Crystal Le

share

This is a segment from the Empire newsletter. To read full editions, subscribe.


There’s no denying that North Korea’s Lazarus Group is a threat, especially as crypto works overtime to be seen as a safe and acceptable industry (sorry degens, there are still corners for you). 

Paradigm’s samczsun highlighted the good, the bad, and the ugly, a month after the Lazarus Group pulled off the biggest digital heist in history. Oof, that hurt to write. 

The upside is that only one bad actor (which, I guess on the downside, is North Korea) has been so successful in stealing funds. 

But “there’s more to the DPRK than just the Lazarus Group,” he warned.

Unfortunately, the team would later find out that the group had managed to compromise SafeWallet’s own infrastructure, deploying “a malicious payload specifically targeting Bybit. This was a level of sophistication that no one had considered or been prepared for, and it was a major update to many of our threat models.”

But there are ways to stay safe, samczsun noted. He urges caution across the board for individual folks like us. And organizations should “install Mobile Device Management (MDM) and Endpoint Detection and Response (EDR) software” on work devices for security prior to any hack and to ensure visibility afterwards. 

Samczsun’s tune was slightly more optimistic than Paradigm advisor ZachXBT, who earlier this month said the effort to try to freeze funds tracked to the Bybit attack had been an “eye-opening” experience. 

From ZachXBT’s Telegram group.

“The industry is unbelievably cooked when it comes to exploits/hacks,” he wrote. 

Samczsun’s holding out hope that the FBI’s unit dedicated to both tracking and preventing DPRK attacks is strong, an encouraging sign given his recent work with them.

Whether or not the FBI paired with super sleuths such as ZachXBT and samczsun — alongside members of Seal 911 — remains to be seen.


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Javits Center North | 445 11th Ave

Tues - Thurs, March 24 - 26, 2026

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

allora-image.png

Research

Decentralized AI coordination networks solve crypto's growing architectural mismatch: applications built on trustless infrastructure shouldn't depend on centralized intelligence providers. By turning model outputs into competitive marketplaces, protocols like Allora are building the permissionless intelligence layer that AI-powered DeFi and autonomous agents require.

article-image

For new growth, crypto may need to shed tired norms like over-raising and the hoarding of investment resources

article-image

Ethereum rolls out Fusaka, setting the stage for a stronger blob fee market and renewed deflationary potential

article-image

Futuristic DeFi is stuck inside the computer. An old idea might be its escape hatch

article-image

Money market indicators are flashing liquidity stress again as crypto underperforms equities

article-image

From passageways to penumbras: a history of private life

article-image

BTC’s Asia-session move and Ethena’s weaker yields reflect a market adjusting to tighter yen funding and softer derivatives carry