On-chain monitors lit up early on September 15, 2026, when wallets long labelled as belonging to the Lazarus Group offloaded 911 ETH in a tight two-hour window.
The sale fetched roughly $2.28 million at an average price of $2,499 per coin.
Lookonchain first flagged the moves, and Arkham Intelligence quickly confirmed the address cluster.
Traders and investigators immediately began watching the flow, because any visible movement from this particular actor tends to ripple through both price charts and compliance desks.
The speed of the dump stands out. In just 120 minutes, the group converted a sizeable ETH pile into stable value, then stepped back.
Market participants now face the familiar mix of curiosity and caution that follows every confirmed Lazarus transaction.

Who is the Lazarus Group and why are they selling ETH right now?
The Lazarus Group operates as a North Korean state-sponsored cyber unit, often tracked under the names APT38 and TraderTraitor.
Intelligence agencies and blockchain firms attribute more than $6.75 billion in stolen cryptocurrency to the group since 2017.
Their work funds the regime’s weapons programs and keeps hard currency flowing into a sanctioned economy.
In recent months, the same cluster has stayed active. After the massive Bybit theft in early 2025 and the KelpDAO and Drift incidents in 2026, the group continues to cycle older holdings into liquid form.
Selling ETH at current levels simply converts dormant inventory into assets that travel more easily across borders and services.
The timing also lines up with periods when Ethereum liquidity runs deep enough to absorb multi-million-dollar orders without dramatic slippage.

Where did the 911 ETH originally come from — which previous hack?
Exact provenance for this specific 911 ETH batch remains under active tracing. Yet, the address history points to earlier high-value incidents.
Lazarus wallets frequently re-use infrastructure across operations. Funds from the February 2025 Bybit heist—still the largest single crypto theft on record at roughly $1.5 billion—continue to surface in later sales.
Additional slices may trace back to the 2026 KelpDAO bridge exploit or residual Ronin Bridge proceeds from 2022.
Investigators watch for shared transaction patterns, dormancy periods, and common counterparties.
When an address sits quiet for months and then suddenly awakens with clean ETH, the link to prior heists grows stronger.
In this case, the wallet in question had already carried the Lazarus tag on Arkham before the latest sales began.
Will this $2.28M sale put meaningful downward pressure on Ethereum’s price?
A $2.28 million market sell registers as noise against Ethereum’s daily volume, which routinely stretches into the billions.
Spot and derivatives markets absorb orders of this size with minimal lasting impact under normal conditions.
Still, the psychological weight differs from the pure numbers. Every confirmed Lazarus sale reminds traders that a large, patient actor still holds significant ETH inventory.
When multiple such sales stack within a short window, short-term sentiment can turn cautious even if the actual order flow stays modest.
Ethereum price action after the September 15 dump stayed relatively contained, yet traders continue monitoring the same address for follow-on activity that could change the picture.

How do on-chain trackers like Lookonchain reliably identify Lazarus Group wallets?
Attribution rests on layered evidence rather than a single magic label. Firms begin with addresses the Federal Bureau of Investigation (FBI) and Office of Foreign Assets Control (OFAC) have publicly designated.
They then expand the cluster by following fund flows, shared deposit patterns, common mixers, and distinctive operational habits.
Lazarus operators often reuse certain bridging routes, timing windows, and intermediary services.
Lookonchain and Arkham combine these technical signals with open-source intelligence and prior case work by independent researchers such as ZachXBT.
Once an address demonstrates consistent behaviour with known Lazarus clusters—long dormancy, sudden multi-hop transfers, and specific exchange interactions—the label sticks.
Confidence grows with every additional matching transaction. The process is never perfect, yet the track record of accurate early alerts has made these labels a trusted signal for both traders and compliance teams.
What happens to the proceeds after the sale — how does Lazarus typically launder the funds?
After converting ETH into USDT or similar stables, Lazarus rarely parks the money in one place.
The next steps usually involve rapid layering: cross-chain bridges, decentralised exchanges (DEXs), privacy-focused protocols, and lightly regulated OTC desks.
THORChain has appeared repeatedly in past laundering paths because it allows relatively frictionless swaps without heavy Know Your Client/Customer (KYC).
From there, the funds often split into smaller amounts, move onto Tron or other chains, and eventually reach peer-to-peer (P2P) platforms or regional brokers that can cash out into fiat.
The entire sequence aims to break the on-chain trail before the value reaches the final destination.
This is because speed and scalability matters when crypto hacking comes into place.
In previous large heists, the group has moved hundreds of millions within days. The current $2.28 million sale looks like a smaller, routine cycle rather than the start of a brand-new laundering wave, yet the same playbook remains visible.
The latest Lazarus Group sale fits a long-running pattern: quiet accumulation of stolen assets, patient holding, then sudden conversion when market conditions allow.
On-chain transparency makes every step visible, yet the group continues to operate at scale.
Traders, exchanges, and investigators will keep the same wallets under close watch, because the next movement could arrive just as quickly as this one did.

