Senator Cynthia Lummis has claimed new anti-money laundering powers in the proposed CLARITY Act would close loopholes exploited by North Korea’s Lazarus Group, which researchers say has stolen $6.75bn in digital assets since 2019.
The Wyoming Republican, one of the bill’s lead sponsors, argues the legislation would allow the U.S. Treasury Department and cryptocurrency platforms to freeze suspicious transactions before they can be shifted abroad, targeting techniques used in some of the largest hacks on record.
Lummis has been highlighting the bill’s illicit-finance measures in a series of posts on X as she presses for a vote on the Senate floor before Congress breaks for its August recess. She has repeatedly advanced the case in recent weeks, including while defending the proposal from criticism by Senator Elizabeth Warren earlier this month.
New powers for Treasury and crypto firms
At the centre of Lummis’s argument is Section 303 of the CLARITY Act, which would give the Treasury a new “special-measure” authority tailored to digital assets. Under the provision, the department could designate a foreign jurisdiction or financial institution as a “primary money laundering concern” specifically for crypto-related activity.
Once such a designation is made, exchanges and stablecoin issuers covered by the law would be required either to block or sharply restrict transfers of funds involving that jurisdiction or institution. The measure would effectively extend to the crypto sector a tool U.S. regulators have long applied to correspondent banking relationships.
A separate component, Section 305, is designed to operate at the level of individual transactions. It would empower exchange operators and stablecoin issuers to impose an initial 30‐day hold on any transfer they reasonably suspect is linked to illicit behaviour. That hold could be extended up to a total of 180 days if law enforcement agencies submit a formal written request.
Companies that use the new powers “in good faith” would benefit from a safe harbour against civil liability, while their existing obligations to file suspicious activity reports would remain unchanged. Lummis has linked both sections to Section 201 of the bill, which would, for the first time, bring digital asset firms fully under Bank Secrecy Act anti-money laundering rules.
She has described these elements as part of more than 16 separate illicit-finance safeguards built into the package, and has also argued that the CLARITY Act would help safeguard customers’ crypto holdings in the event of exchange bankruptcies.
Lazarus Group blamed for majority of 2026 crypto thefts
The legislative push comes against the backdrop of mounting losses attributed to hackers linked to North Korea.
Researchers estimate that in the first half of 2026, North Korea‐associated actors were responsible for roughly two‐thirds of global crypto hacking losses. Out of $972m stolen across a record 207 incidents worldwide, around $643m was tied to such groups.
The largest individual thefts during that period were both attributed to the Lazarus Group and occurred in April. One saw Solana-based Drift Protocol drained of $285m. In a separate operation, attackers compromised the Layerzero bridge connecting DeFi platform KelpDAO to Ethereum, seizing a further $292m.
Those incidents have added to a long-running pattern. Analysts say DPRK-linked operatives stole a record $2.02bn in 2025 alone, a 51% increase on the previous year, taking the estimated cumulative total since 2019 to $6.75bn. The biggest single exploit remains the February 2025 attack on Bybit, in which hackers linked to Lazarus made off with about $1.5bn in ethereum.
Shift in tactics towards targeting individuals
Investigators also believe the Lazarus Group has been evolving its methods in 2026, moving beyond its earlier focus on exploiting cross‐chain bridges and DeFi protocols.
According to Bitcoin.com News, the group has been tied to a campaign dubbed “Mach-O Man” that surfaced in April. The operation reportedly targets executives and staff at fintech and crypto firms using fake meeting invitations and a social‐engineering approach known as ClickFix.
Victims are tricked into pasting malicious commands into their Mac terminals, inadvertently granting attackers a foothold on their devices before any onchain theft is attempted.
Doubts over CLARITY Act’s prospects
Despite Lummis’s lobbying, market analysts are sceptical about the bill’s chances of becoming law next year.
Galaxy Research has cut its estimate of the CLARITY Act passing in 2026 to 30% following the publication of the final legislative text.
