The U.S. Treasury Department’s Office of Foreign Assets Control added three Ethereum addresses to the sanctions-list entry for North Korea-linked Lazarus Group on April 22, 2022, expanding the blockchain identifiers associated with an already-blocked cyber organization.
The update mattered because it translated a national-security investigation into specific data that exchanges, custodians and other digital-asset businesses could screen. It also demonstrated a practical limit of address-based enforcement: publishing identifiers could help regulated intermediaries stop transactions, but it could not erase an address, reverse earlier transfers or prevent the Ethereum network from processing a valid transaction.
An identifier update, not three new defendants
Lazarus Group was already a Specially Designated National. OFAC’s April 22 record changed its existing entry by retaining one previously listed Ethereum address and attaching three additional addresses as alternative digital-currency identifiers. The resulting entry displayed four Ethereum addresses in total.
That distinction is legally important. OFAC did not create three new legal persons, charge three wallet owners with crimes or impose sanctions on Ethereum itself. It published additional identifiers that it attributed to Lazarus Group, whose property and interests in property were already blocked under North Korea-related authorities.
Under OFAC’s virtual-currency guidance available on April 22, U.S. persons and other parties subject to its jurisdiction had the same sanctions obligations for digital currency as for conventional money. They generally had to block property in which a listed person held an interest and avoid unauthorized dealings with that person. OFAC’s guidance also encouraged virtual-currency companies to screen listed addresses and investigate related transactional activity.
The addresses nevertheless were not a complete map of Lazarus Group’s activity. OFAC’s inclusion of an address identifies a potential destination or source associated with a blocked person; it does not establish that every address interacting with it is controlled by that person. Compliance decisions still required attribution work and safeguards against false matches.
The Ronin investigation supplied the context
The April 22 update followed the March exploitation of the Ronin bridge used by the Axie Infinity gaming ecosystem. On April 14, the Federal Bureau of Investigation said its investigation confirmed that Lazarus Group and APT38—cyber actors associated with the Democratic People’s Republic of Korea—were responsible for a theft the FBI valued at $620 million.
Contemporaneous cryptocurrency reporting connected the three additional addresses to the Ronin investigation. The OFAC list update itself did not publish transaction hashes, balances, token quantities or an address-by-address explanation of how investigators established control. The connection beyond the broader Lazarus attribution therefore depended partly on contemporaneous reporting rather than a detailed public forensic report from Treasury.
The government’s attribution was an official investigative conclusion, not a criminal judgment following a trial. The public record on April 22 did not identify the natural persons controlling the private keys, disclose the evidentiary chain behind each address or state how much recoverable cryptocurrency remained at them.
Why the action mattered for crypto infrastructure
Public blockchains make transaction histories observable, but sanctions compliance depends on connecting pseudonymous addresses to legally identified actors. OFAC’s update supplied that connection for three more Ethereum identifiers. A centralized exchange could use the list to stop deposits, withdrawals or account activity within its control; a self-executing blockchain protocol might continue operating without such an intermediary.
That difference made the April 22 action significant for exchanges, wallet providers, analytics companies and decentralized-protocol developers. It showed that sanctions authorities were treating blockchain addresses as operational compliance data, while leaving unresolved how far screening should extend beyond expressly listed identifiers.
No cryptocurrency price, return, trading-volume or market-capitalization claim can be reliably attributed to the list update from the reviewed records. Its event-day significance was regulatory and investigative: the United States had expanded the address-level sanctions trail surrounding a major state-linked cryptocurrency theft without publishing a complete forensic reconstruction.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

