Let’s take a slightly darkly humorous angle: when it comes to the art of “sheep-shearing,” the highest-ranked players in Web3 are really Lazarus.

This North Korean–backed hacking group strikes in the billions to the tens of billions of dollars each time. What’s interesting is that the numbers seem to hover around the threshold of an exchange’s annual profits:

They don’t shear you so hard you’re crippled, because you’ve still got to be kept alive—so they can shear you again next year.

Even more thought-provoking is the logic behind choosing targets: they specifically go after smaller exchanges with less stringent regulatory backgrounds, while major firms in the U.S. and Hong Kong largely avoid.

This isn’t a matter of technical capability—it’s because the risk-reward equation is crystal clear. If they provoke a strongly regulated jurisdiction, the chase for stolen funds and sanctions will follow them all the way.

So the fact that something gets stolen has never been only a “security vulnerability” issue—it’s a business calculated down to the last detail.

What defenders need to do isn’t just stack up more firewalls, but to think clearly: in the cost-benefit sheet of the underground economy, how much is your exchange actually worth? 😅