A North Korea crypto check screens a wallet against addresses tied to OFAC-sanctioned DPRK groups like Lazarus; Plastron flags this exposure free using weekly-updated sanctions data across seven EVM chains.
North Korea Crypto Exposure Check
North Korea's Lazarus Group has stolen over $3 billion in crypto since 2017. OFAC-designated DPRK addresses create strict sanctions obligations.
North Korea's state-sponsored hacking group, Lazarus Group, is estimated to have stolen over $3 billion in cryptocurrency between 2017 and 2024, making DPRK the single largest state-level threat to blockchain ecosystem security. Their operations include the $625 million Ronin Bridge hack (2022), the $1.5 billion Bybit hack (2025), and dozens of smaller but significant exchange and DeFi protocol breaches. OFAC has designated Lazarus Group, the Blueberry Protocol addresses, and numerous associated wallet addresses on the SDN list, meaning any transaction involving these addresses by a US person or on a US-nexus platform is a sanctions violation — not merely an AML concern. After each hack, Lazarus rapidly moves stolen funds through multiple intermediary wallets, DEX swaps, and mixing services in an effort to obscure the origin before cashing out. This distribution process means that stolen DPRK-linked funds filter into the broader DeFi ecosystem within weeks of a hack, reaching wallets that had no connection to the original attack. Major exchanges apply heightened scrutiny to wallets with any DPRK exposure given both the sanctions obligations and the scale of DPRK theft activity. South Korean VASP regulations specifically mandate DPRK screening for all registered exchanges. Screening your wallet for Lazarus Group exposure is particularly important if you have been active in DeFi in the weeks following any major hack.
How Plastron Helps
OFAC-Designated DPRK Address Screening
Plastron's OFAC database — updated weekly from the US Treasury SDN XML feed — includes all designated Lazarus Group and DPRK-associated cryptocurrency addresses. Direct counterparty matches flag at Critical severity with a sanctions classification. We show the specific SDN designation, the associated hack operation, and your transaction history with the flagged address.
Post-Hack Exposure Detection
DPRK funds move through DeFi rapidly after each hack. Plastron analyzes your transactions covering the periods following major Lazarus hacks and flags any counterparties that match known distribution wallet patterns. If your wallet received ETH or tokens through a path that traces to Lazarus fund movement — even through multiple hops — the scan will surface the connection.
Stolen Funds and Sanctions Combined Report
DPRK exposure sits at the intersection of stolen funds and OFAC sanctions — the two highest-severity risk categories in Plastron's scoring framework. Your report shows both classifications where applicable, with separate category scores so you can understand the full compliance profile of any DPRK-linked exposure.
Risk Categories We Screen
See It in Action
Real public wallets relevant to this topic. Click any to run a live scan.
Frequently Asked Questions
Related Screening Tools
Screen Your Wallet Now
Connect your wallet and get a full risk report in under 30 seconds. Free, non-custodial, and completely private.