Good day everyone,
I hope you are all having a good day, welcome to CryptoGod-1's blog on all things crypto. In this post I will be looking at how BitMEX noticed a security flaw in the North Korean hackers the Lazarus Group
Lazarus Group Hackers Security Flaws
A group of researchers at BitMEX have uncovered a number of technical missteps in the working of the North Korean hacker group The Lazarus Group. This revelation has helped them to identify parts of the organisations infrastructure which exposed significant operational weaknesses. The North Korean hacker group are a state-sponsored cybercrime network which are responsible for a number of high-profile crypto hacks.
The recent counter-operations probe by the security researchers at BitMEX noted a number of discoveries, which included an exposed IP addresses, an accessible database, and tracking algorithms used by the group in its campaigns. These would be considered amateur-level operational security lapses within the hacker group and the exchange noted there is a strong likelihood that at least one of the hackers accidentally revealed their true IP address. This revealed their true location which happened to be in Jiaxing, China.
Researchers also gained access to a Supabase database instance used by the attackers. This is a platform used to easily deploy databases with simple interfaces for applications and is commonly used by the hacking group. It highlights the evolving operational tools being used by The Lazarus Group.

https://x.com/Reuters/status/1490991293224435714
The report by BitMet also noted a growing divide in the group’s internal structure. The analysis highlighted the asymmetry between the group's low-skill social engineering teams designed to funnel unsuspecting victims into downloading malicious software and interacting with sophisticated code exploits developed by high-tech hackers. This fragmentation suggests that Lazarus has splintered into sub-groups with varying capabilities.
Some of these sub-groups rely on basic social engineering while others focus on deploying complex technical attacks targeting the blockchain and tech sectors. Global law enforcement agencies have been continually investigating the group's activities as a surge in DPRK-linked cyber activity has hit the globe.
Back in September 2024 federal law enforcement agencies and governments worldwide, including the FBI, gave a warning regarding phishing scams using fake job offers to lure crypto users. Japan, South Korea, and U.S. officials echoed this warning in January 2025. They cited that Lazarus a threat to financial stability due to the number of common scam strategies employed by the hackers.
It has been reported by Bloomberg that world leaders could be gearing themselves to address the threat posed by the Lazarus Group at the next G7 Summit. This will take place in Canada and it is believed they will explore coordinated strategies to mitigate damage from the group’s activities. Pyongyang’s cyber operations will not be the only topic of discussion, but its use of hacking crypto for funding its weapons programs is a top issue of debate.
The Lazarus Group, North Korea’s most infamous hacking collective, is believed to be behind a series of major crypto thefts, including the record $1.4 billion heist from Bybit in February. Back in 2024 a report from Chainalysis claimed that North Korean-linked actors stole over $1.3 billion across 47 separate incidents.
Their ploy of planting rogue IT workers to infiltrate crypto firms from within was also a tactic flagged in a joint warning from the U.S., Japan, and South Korea. These ever evolving strategies mean the crypto space should remain on high alert against any threat from North Korea, as shown in the 'X' video below where Kraken recently thwarted an infiltration attempt by a suspected North Korean posing as a job candidate.

https://x.com/pete_rizzo_/status/1917986249224159572
Have a great day.
Peace. CryptoGod-1.
Referral Links and Follow Me: