Key Takeaways
- Lummis says CLARITY Act Sections 303 and 305 target North Korea’s Lazarus Group with new freeze tools.
- North Korea-linked hackers took roughly two-thirds of the $972 million stolen in H1 2026.
- CLARITY Act needs 60 Senate votes and seven Democratic crossovers before its floor-vote deadline.
Section 303 and 305 Target Illicit Funds
Cynthia Lummis, one of the CLARITY Act’s lead sponsors, took to X and pointed to the bill’s anti-money laundering provisions as she pushes for a Senate floor vote before lawmakers leave for August recess.

The Wyoming Republican has repeated the argument since defending the legislation from Senator Elizabeth Warren earlier this month, stating that:
“Sec. 303 enables new crypto sanctions on Iran. Sec. 305 lets exchanges stop illicit funds before they reach North Korea.”
Section 303 gives the Treasury new special-measure authority to designate foreign jurisdictions or financial institutions as a “primary money laundering concern” specifically for digital asset activity. Once a jurisdiction is designated, covered exchanges and stablecoin issuers must prohibit or restrict fund transfers involving it, extending a tool regulators have long used against correspondent banks into crypto for the first time.
Section 305, on the other hand, works at the transaction level, allowing exchange operators and stablecoin issuers to place a 30-day hold on any transaction they have reason to believe involves illicit activity, extendable to 180 days total if law enforcement submits a formal written request.
Firms that act in good faith get a safe harbor from civil liability, while existing suspicious activity report obligations stay in place. Lummis has paired both sections with Section 201, which extends Bank Secrecy Act (BSA) anti-money laundering (AML) requirements to digital asset firms for the first time, part of what she calls more than 16 illicit-finance safeguards built into the bill, a case she has also made for why the CLARITY Act would protect customer crypto in exchange bankruptcies.
Lazarus Group’s Escalating 2026 Haul
North Korea-linked hackers were responsible for roughly two-thirds of all crypto hacking losses worldwide in the first half of 2026, about $643 million of the $972 million stolen across a record 207 incidents.
The single largest hits came in April, when the Lazarus Group drained Solana-based Drift Protocol of $285 million and then compromised the Layerzero bridge connecting DeFi platform KelpDAO to Ethereum for another $292 million.
Those losses build on a pattern researchers have tracked for years, with DPRK-linked actors stealing a record $2.02 billion in 2025 alone, a 51% jump from the year before, pushing the group’s cumulative haul since 2019 to $6.75 billion. The single largest exploit remains the February 2025 attack on Bybit, where Lazarus-linked hackers made off with roughly $1.5 billion in ethereum.
The group has also shifted tactics this year, moving beyond bridge and protocol exploits toward direct targeting of crypto executives. To this point, Bitcoin.com News tracked a Lazarus-linked campaign dubbed Mach-O Man in April, which uses fake meeting invitations and a social-engineering technique called ClickFix to trick fintech and crypto staff into pasting malicious commands into their own Mac terminals, giving hackers a foothold before any onchain theft even begins.





Be the first to comment