Senator Cynthia Lummis says two provisions in the Clarity Act would let the Treasury Department and crypto exchanges freeze funds before they reach North Korea, an argument she’s making as the regime’s hackers pushed their cumulative crypto theft to $6.75 billion in 2025, according to Chainalysis.
The Wyoming Republican, one of the legislation’s leading supporters, has singled out provisions she says would give the U.S. Treasury Department and crypto companies more effective ways to identify, restrict and freeze suspicious digital-asset flows before they can be moved offshore.
Her argument comes as the scale of North Korea’s crypto operation continues to expand. Chainalysis estimates that DPRK-linked hackers stole at least $2.02 billion in cryptocurrency during 2025, lifting the cumulative total since records began to $6.75 billion. The February 2025 Bybit breach, worth roughly $1.5 billion, remains the largest single crypto theft on record and was attributed by the FBI to North Korean actors.
Lummis puts crypto sanctions at the heart of the bill
Lummis has increasingly framed the Clarity Act as an anti-illicit-finance measure as much as a market-structure bill.
In a July response to criticism from Senator Elizabeth Warren, Lummis highlighted Sections 303 and 305 as two provisions she believes would strengthen the government’s ability to disrupt illicit digital-asset activity.
“Sec. 303 enables new crypto sanctions on Iran. Sec. 305 lets exchanges stop illicit funds before they reach North Korea,” Lummis wrote on X.
Her comments came after Warren argued that the legislation, in its current form, could create new opportunities for sanctions evasion. Warren wrote that the Clarity Act, “as currently drafted,” was “a ticket to sanctions evasion,” intensifying an already contentious debate over the bill’s financial-crime provisions.
Lummis has countered that criticism by pointing to more than 16 safeguards she says are included in the legislation. She has particularly emphasized Section 201, which would apply Bank Secrecy Act anti-money-laundering requirements to covered digital-asset firms, alongside provisions dealing with sanctions and suspicious transactions.
The Senate Banking Digital Assets Subcommittee chair released updated Clarity Act text on July 22 after work by the Senate Banking and Agriculture committees was merged. Lummis described the revised legislation as another step toward establishing a U.S. framework for digital assets and urged lawmakers to reach a compromise.
Lazarus threat shows why the debate matters
The urgency behind Lummis’ argument is underscored by the size and sophistication of North Korea’s crypto operations.
Chainalysis said DPRK-linked hackers stole $2.02 billion during 2025 alone, a 51% increase from the previous year. The firm said the haul pushed the cumulative lower-bound estimate to $6.75 billion, with attackers increasingly relying on high-value compromises and sophisticated infiltration rather than simply launching large numbers of attacks.
The Bybit attack illustrates the scale of the threat. The exchange lost approximately $1.5 billion in Ethereum in February 2025, making it the largest cryptocurrency theft ever recorded. Chainalysis said the incident was central to North Korea’s record-breaking year.
North Korean-linked operations have continued to target decentralized finance infrastructure in 2026.
On April 1, Solana-based Drift Protocol suffered a $285 million loss. Chainalysis said the attack was likely connected to DPRK actors, although it noted that formal attribution was still pending. Investigators found that attackers spent months building relationships with members of the Drift team before exploiting privileged access.
Just over two weeks later, KelpDAO’s rsETH bridge was hit for approximately $292 million. LayerZero Labs said Mandiant, CrowdStrike and independent researchers attributed the attack to the DPRK threat actor TraderTraitor.
Hackers are moving beyond simple exploits
The KelpDAO incident also highlights why conventional smart-contract defenses are no longer enough.
According to Chainalysis, the attackers compromised infrastructure supporting LayerZero’s verification process, manipulated RPC nodes and ultimately caused the system to accept a fraudulent cross-chain message. The result was the release of approximately 116,500 rsETH worth $292 million.
The Drift attack followed a similarly sophisticated pattern. Rather than simply discovering a coding vulnerability, the attackers reportedly cultivated relationships with contributors and used social engineering to obtain access that could later be converted into control over funds.
That evolution is significant for policymakers. North Korean operators are increasingly attacking the people, infrastructure and trust relationships surrounding crypto networks—not just the code itself.
Chainalysis has previously warned that DPRK-linked actors increasingly use techniques such as IT-worker infiltration, impersonation and social engineering to gain privileged access to exchanges, custodians and Web3 companies.
Senate clock adds pressure to crypto security fight
The Clarity Act now faces a political test as much as a regulatory one.
Lummis and other supporters are attempting to build enough bipartisan backing for Senate passage before lawmakers leave Washington for the August recess. The legislation needs 60 votes in the Senate to overcome a filibuster, meaning Republicans would need support from Democrats to move it forward. Negotiations have continued over issues including ethics provisions, anti-money-laundering requirements and other elements of the bill.
That makes the Lazarus argument particularly powerful for supporters. They contend that the existing system has struggled to stop sophisticated digital-asset theft and laundering networks before stolen funds disappear across jurisdictions.
Critics, meanwhile, remain concerned that parts of the legislation could leave gaps around decentralized finance and sanctions compliance. That disagreement means the debate is unlikely to end with a simple question of whether crypto needs more regulation.
The larger question is whether Washington can design rules that simultaneously give law enforcement sharper tools, protect legitimate digital-asset businesses and prevent criminals such as North Korea-linked hackers from exploiting regulatory boundaries.
For Lummis, the Clarity Act represents an opportunity to close those boundaries before another Bybit-scale theft forces Congress to react after the damage is already done.
With North Korea’s cumulative crypto theft estimate now at $6.75 billion and major attacks continuing into 2026, the stakes extend far beyond crypto market regulation. The Senate’s decision could determine how aggressively the United States confronts the growing use of digital assets as a tool for state-sponsored cybercrime and sanctions evasion.