Japan-based Crypto Businesses Warned of Possible Cyberattack Threat

Crypto companies in Japan asked to defend against hacks from North Korea’s Lazarus group

article-image

Tokyo, Japan; Source: Shutterstock

share
  • Lazarus is most likely targeting Japanese crypto operators through cyberattacks, authorities say
  • Crypto businesses urged to caution against phishing attacks and social engineering

North Korean hacking group Lazarus plotting phishing and social engineering attacks against crypto businesses, authorities in Japan have warned.

Local police, Japan’s financial regulator and the National Center of Incident Readiness and Strategy warned local crypto businesses in a recent advisory statement about further hacking attempts. They also laid out preventive measures to monitor breaches.

Since Lazarus is state-sponsored, it is believed proceeds from the hacks may go toward North Korea’s nuclear weapons program. The group has also been associated with using crypto mixer Tornado Cash, recently sanctioned by the US Treasury, to conceal the origin of stolen funds.

The authorities didn’t mention which crypto businesses were targeted by Lazarus, but warned that security measures such as improved private key management are warranted.

They asked both individuals and companies to implement countermeasures such as ensuring the origin of downloaded files is a trusted source, interfaces to web applications are legitimate and private keys are stored offline, such as on a hardware wallet.

Lazarus is believed to have stolen more than $1.75 billion worth of cryptoassets since its formation in 2009, Chainalysis found last year. The group has been behind several crypto exchange hacks, including the theft of $49 million worth of crypto from Upbit in 2019.

After several companies had their internal systems hacked and crypto stolen, police reportedly launched an investigation within a special investigation unit. They eventually found Lazarus to be the culprit.

A local report by Japan News states it isn’t usual to name a suspected attacker before a more substantial action like an arrest, but that publicly naming the group is also viewed as an effective move to preempt attacks, as it could prompt people to take action and remain vigilant.


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Old Billingsgate

Mon - Wed, October 13 - 15, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Research Report Templates.jpg

Research

Figure, founded by former SoFi CEO Mike Cagney, has emerged as a leader in onchain RWAs, with ~$17.5B publicly tokenized. The platform’s ecosystem volume is growing ~40% YoY as it expands beyond HELOCs into student loans, DSCR loans, unsecured loans, bankruptcy claims, and more. Operationally, Figure cuts average loan production cost by ~93% and compresses median funding time from ~42 days to ~10, creating a durable speed-and-cost advantage.

article-image

Former White House crypto official Bo Hines is expected to be the CEO of the new project

article-image

In bonds, stablecoins and billionaires, a reminder of what makes crypto special

article-image

21Shares exec says CPI and PPI data supports a Fed rate cut, with market leaning toward a 25bps decrease

article-image

The Ethereum co-founder suggested LINEA holders would be eligible for other airdrops in cryptic tweet

article-image

The layer-2’s biggest release yet brings benefits — but a post-upgrade outage caused a chain reorg

article-image

Crypto is shifting into risk-on mode — pump.fun dominates meme activity, while Lido leans on treasury maneuvers