Japan-based Crypto Businesses Warned of Possible Cyberattack Threat

Crypto companies in Japan asked to defend against hacks from North Korea’s Lazarus group

article-image

Tokyo, Japan; Source: Shutterstock

share

key takeaways

  • Lazarus is most likely targeting Japanese crypto operators through cyberattacks, authorities say
  • Crypto businesses urged to caution against phishing attacks and social engineering

North Korean hacking group Lazarus plotting phishing and social engineering attacks against crypto businesses, authorities in Japan have warned.

Local police, Japan’s financial regulator and the National Center of Incident Readiness and Strategy warned local crypto businesses in a recent advisory statement about further hacking attempts. They also laid out preventive measures to monitor breaches.

Since Lazarus is state-sponsored, it is believed proceeds from the hacks may go toward North Korea’s nuclear weapons program. The group has also been associated with using crypto mixer Tornado Cash, recently sanctioned by the US Treasury, to conceal the origin of stolen funds.

The authorities didn’t mention which crypto businesses were targeted by Lazarus, but warned that security measures such as improved private key management are warranted.

They asked both individuals and companies to implement countermeasures such as ensuring the origin of downloaded files is a trusted source, interfaces to web applications are legitimate and private keys are stored offline, such as on a hardware wallet.

Lazarus is believed to have stolen more than $1.75 billion worth of cryptoassets since its formation in 2009, Chainalysis found last year. The group has been behind several crypto exchange hacks, including the theft of $49 million worth of crypto from Upbit in 2019.

After several companies had their internal systems hacked and crypto stolen, police reportedly launched an investigation within a special investigation unit. They eventually found Lazarus to be the culprit.

A local report by Japan News states it isn’t usual to name a suspected attacker before a more substantial action like an arrest, but that publicly naming the group is also viewed as an effective move to preempt attacks, as it could prompt people to take action and remain vigilant.


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Upcoming Events

Brooklyn, NY

SUN - MON, JUN. 22 - 23, 2025

Blockworks and Cracked Labs are teaming up for the third installment of the Permissionless Hackathon, happening June 22–23, 2025 in Brooklyn, NY. This is a 36-hour IRL builder sprint where developers, designers, and creatives ship real projects solving real problems across […]

Industry City | Brooklyn, NY

TUES - THURS, JUNE 24 - 26, 2025

Permissionless IV serves as the definitive gathering for crypto’s technical founders, developers, and builders to come together and create the future.If you’re ready to shape the future of crypto, Permissionless IV is where it happens.

Old Billingsgate

Mon - Wed, October 13 - 15, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Research

article-image

Debate over extra Bitcoin use cases has returned, two years on from Ordinals

article-image

Altcoin season may be on a permanent pause as the market matures and paths grow more selective

article-image

Today’s blockchains are more like nervous systems without a brain — wiring without will

article-image

A number of blockchains make use of the Solana Virtual Machine

article-image

Bloomberg Intelligence analysts pegged the odds of the SEC approving US litecoin and solana ETFs in 2025 at 90%

article-image

Digital Assets Subcommittee Chair Bryan Steil called for a “roundtable” discussion in lieu of a formal hearing