Lummis: CLARITY Act closes gaps Lazarus Group exploited
Sen. Cynthia Lummis argues the CLARITY Act would close gaps Lazarus Group exploited and give Treasury and U.S. crypto exchanges power to freeze suspicious transfers.
Sen. Cynthia Lummis, a lead sponsor of the CLARITY Act, has argued the bill would close illicit-finance gaps used by North Korea’s Lazarus Group and give the Treasury Department and crypto exchanges authority to freeze suspicious transfers before funds leave U.S. platforms.
Lummis has urged Senate leaders to hold a floor vote before the August recess. The measure requires 60 votes, including seven Democratic crossovers, to clear a procedural threshold.
Section 303 would let Treasury designate a foreign jurisdiction or financial institution as a “primary money laundering concern” for digital-asset activity. Once designated, covered exchanges and stablecoin issuers would be required to prohibit or limit transfers involving that jurisdiction or institution.
Section 305 would allow exchange operators and stablecoin issuers to place a 30-day hold on any transfer they reasonably suspect involves illicit activity. Law enforcement could file a written request to extend the hold up to 180 days. Firms that act in good faith while using the hold would receive a civil-liability safe harbor, and existing suspicious-activity reporting duties would remain in force.
Lummis pairs those measures with Section 201, which would extend Bank Secrecy Act anti-money-laundering requirements to digital-asset firms. She has argued the bill contains more than 16 illicit-finance safeguards and would help protect customer assets in exchange bankruptcies.
“Sec. 303 enables new crypto sanctions on Iran. Sec. 305 lets exchanges stop illicit funds before they reach North Korea,” Lummis wrote on X.
Lawmakers and researchers cite a rise in cryptocurrency thefts linked to Democratic People’s Republic of Korea–affiliated actors. In the first half of 2026, North Korea–linked groups accounted for about two-thirds of $972 million in reported crypto hacking losses, roughly $643 million across 207 incidents. April breaches included a $285 million theft from the Solana-based Drift Protocol and a $292 million compromise of a LayerZero bridge used by the DeFi platform KelpDAO.
Researchers recorded $2.02 billion in DPRK-linked crypto thefts in 2025, a 51% increase from 2024, bringing the group’s cumulative total since 2019 to about $6.75 billion. The largest single exploit tracked to date was a February 2025 attack on Bybit, where Lazarus-linked actors withdrew roughly $1.5 billion in ether.
Researchers report the group has diversified tactics, moving beyond protocol and bridge exploits toward social-engineering campaigns that target executives and staff. A campaign tracked in April, called Mach-O Man, used fake meeting invitations and a technique known as ClickFix to trick employees into pasting malicious commands into Mac terminals, giving attackers access before on-chain thefts.
Supporters contend the bill’s authorities would make it harder for state-linked cybercriminals to launder stolen crypto through U.S.-linked platforms or stablecoins. Opponents have raised concerns about the scope of new Treasury powers and the potential operational burden on exchanges. Backers are working to secure the votes needed to bring the bill to the Senate floor before the August recess.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








