# LazarusBounty Program

Combating Cybercrime with Transparency

Bybit is taking a firm stand against cybercriminals, including the notorious Lazarus Group, with the launch of the **LazarusBounty Program** ([LazarusBounty.com](https://www.lazarusbounty.com/en)). This initiative is dedicated to bringing full transparency to the industry and strengthening security across the crypto ecosystem.

As part of this effort, we've developed HackScan, a powerful tool designed to track, expose, and disrupt illicit fund flows, ensuring that bad actors have nowhere to hide.

### **Key Features of the LazarusBounty Program**

* **Track Hacker Fund Flows** – Access real-time, publicly available data on hacker addresses and fund movements.
* **Monitor Entity Actions** – Gain insights into how industry players respond to illicit activities and foster institutional collaboration.
* **Become a Bounty Hunter** – Submit leads on illicit funds and claim bounties upon successful asset recovery.

Built on the principle that transparency is the strongest defense, this program ensures every transaction, response, and inaction is recorded—holding all parties accountable.


# Fund Flow Monitor

The movement of compromised funds often leads to untraceable destinations, including exchanges, mixers, bridges, or conversion into stablecoins.

This section provides a live view of all involved entities—highlighting their actions, updates on fund movements, and their role in ongoing tracing efforts.

A **ranking system** tracks **good and bad actors** based on their response times to sanctioned Lazarus Group transactions, offering complete transparency into which organizations are assisting—or obstructing—investigations.

<figure><img src="https://980317055-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHyS1Km6gRP88S9MWA03E%2Fuploads%2FthmDvb2NwdAGu8sVFEvm%2FFund%20Flow.png?alt=media&amp;token=004ef93e-5a9b-4dfd-9231-6b56ff9f0697" alt=""><figcaption></figcaption></figure>


# Hacker Addresses

A dedicated section featuring confirmed hacker addresses, enabling industry stakeholders to monitor and block illicit activities.

<figure><img src="https://980317055-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHyS1Km6gRP88S9MWA03E%2Fuploads%2FLruh5TVWcKW4cMmXQxht%2FHacker%20Addresses.png?alt=media&amp;token=30a94ff8-9ea5-495b-b35b-2ecb193d3ac9" alt=""><figcaption></figcaption></figure>


# Verified Reports

Access a repository of verified reports, detailing each entity's handling status regarding compromised funds.

<figure><img src="https://980317055-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHyS1Km6gRP88S9MWA03E%2Fuploads%2FHAGZipFOAbdob8bljRGl%2FVerified-addresses.png?alt=media&amp;token=344164c6-a91b-4284-a516-f2af672050b2" alt=""><figcaption></figcaption></figure>


# Bounty Hunters

Explore a leaderboard of successful participants, showcasing their contributions and the bounties they have earned.

<figure><img src="https://980317055-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHyS1Km6gRP88S9MWA03E%2Fuploads%2Ftji0ex1rAhxOiz4JsCsL%2FBounty%20Hunters%20Leaderboard.png?alt=media&amp;token=f7e1db3d-294d-459e-8b38-f682672e9010" alt=""><figcaption></figcaption></figure>


# Rewards & Participation

Bybit offers a bounty amounting up-to 10% of stolen funds that have been returned to Bybit ("**Returned Funds**") to participants in this programme that rewards participants for tracking, freezing and returning funds ("**Bounty**").

Distributions are made as follows:

1. **5%** to the entity that assists in freezing the funds. Freezing shall be the first durable and acting freeze at the time of the funds return to qualify.
2. **5%** to the first reporters who helped trace the funds up to the stage of successful freezing.
3. A participant may fufill both roles.

**Bounty Payment Terms**

1. Bounties will be paid for the respective appliable participation in Returned Funds.
2. Bounties will be paid porportinate to the amount of Returned Funds and out of the Returned Funds.
3. Payouts will be made directly to the contributor's wallet address within 1-2 weeks.
4. Bounty payouts are not automatic and will be done on request.
5. Each request is audited and verified.

### **How to Join**

Take action to safeguard the crypto industry—submit a report and contribute to the fight against cybercrime.

{% embed url="<https://www.lazarusbounty.com/en>" %}

## **Disclaimer**

Participation does not guarantee a bounty award. Admission on the leaderboard does not represent a qualified Bounty. Bybit reserves the right to modify or terminate this program at its discretion. All participants must comply with applicable laws and regulations. Fraudulent or misleading claims will result in disqualification.


# Step-by-Step Guide

### 1. Visit the Reporting Site

Click [**this link**](https://www.lazarusbounty.com/en/report) to access the reporting page.

### 2. Connect Wallet

Click the **Connect Wallet** button in the top right hand corner and connect your wallet.

<figure><img src="https://980317055-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHyS1Km6gRP88S9MWA03E%2Fuploads%2F9MIfIFKQUtaB9Baryr13%2FTutorail-connect-wallet.png?alt=media&amp;token=b740ce04-5d58-4ef5-ab9f-a2fc32fd01cd" alt=""><figcaption></figcaption></figure>

### 3. Enter Information

Complete all required fields **(marked with a red asterisk)**. You may also include optional information, which helps us review your report more effectively.

<figure><img src="https://980317055-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHyS1Km6gRP88S9MWA03E%2Fuploads%2FGcniwQCKUZ45ueDL6ssW%2FEnter%20Info.png?alt=media&amp;token=0a182acd-df13-455c-97ed-5a01dadaff5e" alt=""><figcaption></figcaption></figure>

### 4. Submit Your Report

Click **Submit** and sign in to your wallet. Our team will review your submission within 48 hours.


# HackScan

Strengthening Crypto Security

Having experienced an attack firsthand and benefited from the unwavering support of industry partners, **Bybit** wants to give back by launching **HackScan** — an open-source tool designed to empower users in the fight against crypto crime.

We built **HackScan** with the intention of equipping the community with tools to track fund flows associated with hack events and uncover malicious hacker addresses.

By making fund flows visible and investigations more accessible, we aim to foster a stronger and more resilient crypto ecosystem — where transparency is the first line of defense.


# API References

This API is designed to allow ethical security experts racing against time to streamline and expedite their efforts in recovering the compromised funds.

## Retrieve all hacker addresses <a href="#request-url" id="request-url"></a>

<mark style="color:green;">**`Get`**</mark>  [**https://hackscan.hackbounty.io/public/hack-address.json**](https://hackscan.hackbounty.io/public/hack-address.json)

**Your Request**

{% tabs %}
{% tab title="cURL" %}

```bash
curl https://hackscan.hackbounty.io/public/hack-address.json
```

{% endtab %}

{% tab title="Go" %}

```go
import (
        "encoding/json"
        "fmt"
        "io/ioutil"
        "net/http"
)
...

        url := "https://hackscan.hackbounty.io/public/hack-address.json"

        resp, err := http.Get(url)
        if err != nil {
                fmt.Println("requestErr:", err)
                return
        }
        defer resp.Body.Close()

        if resp.StatusCode != http.StatusOK {
                fmt.Println("statueCode:", resp.StatusCode)
                return
        }

        body, err := ioutil.ReadAll(resp.Body)
        if err != nil {
                fmt.Println("readErr:", err)
                return
        }

        var data map[string]interface{}
        if err := json.Unmarshal(body, &data); err != nil {
                fmt.Println("jsonParseErr:", err)
                return
        }

        fmt.Println(data)
```

{% endtab %}

{% tab title="Java" %}

```java
import java.io.BufferedReader;
import java.io.InputStreamReader;
import java.net.HttpURLConnection;
import java.net.URL;
import org.json.JSONObject;
...

        String url = "https://hackscan.hackbounty.io/public/hack-address.json";

        try {
            URL obj = new URL(url);
            HttpURLConnection con = (HttpURLConnection) obj.openConnection();
            con.setRequestMethod("GET");

            int responseCode = con.getResponseCode();
            if (responseCode == 200) {
                BufferedReader in = new BufferedReader(new InputStreamReader(con.getInputStream()));
                String inputLine;
                StringBuilder response = new StringBuilder();
                while ((inputLine = in.readLine()) != null) {
                    response.append(inputLine);
                }
                in.close();

                JSONObject jsonResponse = new JSONObject(response.toString());
                System.out.println(jsonResponse.toString(2));
            } else {
                System.out.println("failed:" + responseCode);
            }
        } catch (Exception e) {
            System.out.println("requestErr:" + e.getMessage());
        }
```

{% endtab %}

{% tab title="Python" %}

```python
import requests

url = "https://hackscan.hackbounty.io/public/hack-address.json"

try:
    response = requests.get(url)
    response.raise_for_status()
    data = response.json()
    print(data)
except requests.exceptions.RequestException as e:
    print("requestErr:", e)
```

{% endtab %}

{% tab title="Node.js" %}

```javascript
const axios = require('axios');

const url = "https://hackscan.hackbounty.io/public/hack-address.json";

axios.get(url)
    .then(response => {
        console.log(response.data);
    })
    .catch(error => {
        console.error("requestErr:", error.message);
    });
```

{% endtab %}
{% endtabs %}

**Our Response**

{% tabs %}
{% tab title="200: OK Successful Response" %}

```json
{
    "0221": {
        "eth": [
            "0x47666fab8bd0ac7003bce3f5c3585383f09486e2",
            "..."
        ],
        "btc": [
            "bc1qf5ljnw6knr7egy7t65fkd3xau7j7za4fskmxpg",
            "..."
        ],
        "bsc": [
            "0x9c249b3db6345367b43b2ced4c07d4ffa1fb5e11",
            "..."
        ],
        "arbi": [
            "0xc74e74fd13e5136c4f4106688fd07838cd6314f4",
            "..."
        ]
    }
}
```

{% endtab %}
{% endtabs %}


