Senator Cynthia Lummis has put national security at the center of her push for the Digital Asset Market Clarity Act, claiming the bill’s three core illicit-finance provisions are the most direct mechanism available to cut off North Korea’s Lazarus Group from crypto markets.
The argument lands as the bill’s Senate ground vote slips toward the August recess, and Polymarket traders price 2026 passage at simply 33–37%, down from above 80% in February.

Clarity ACT: Three Provisions, One Target
Lummis has pointed to a three specific sections of H.R. 3633 to make her case. Section 201 broadens the Bank Secrecy Act and AML crypto compliance obligations to crypto firms, exchanges, DeFi front ends, and crypto ATMs, consisting of. Section 303 adds a latest Treasury crypto sanctions authority targeted at Iran.
Section 305 creates a safe harbor that permits exchanges to voluntarily freeze funds linked to suspicious activity before than acquiring a court order, offered they cooperate with law enforcement.
That last provision is the operational crux of Lummis’s argument. Lazarus moves stolen funds rapidly across chains and through mixers, and the present legal framework gives exchanges little incentive to act unilaterally. Section 305 closes that window by removing liability for platforms that freeze fast-moving suspicious transactions.
On July 26, Lummis posted that North Korea’s Lazarus Group and other bad actors thrive on gaps in financial rules, and that the CLARITY Act offers Treasury new sanctions authority alongside a secure harbor for companies to freeze suspicious transactions before the money moves, a paraphrase of her public declaration on X.
Lazarus’s Track Record Makes the Case
The scale of the issue is not abstract. Lazarus Group stole around $625 million from the Ronin Bridge in 2022, the infrastructure underpinning Axie Infinity.
In February 2025, it launched the biggest single crypto heist on record, taking $1.5 billion from Bybit. Treasury analysis the group has taken at least $3.4 billion in crypto since 2007, with proceeds routed toward North Korea’s weapons programs.
The Axie Infinity main menu screen features a player’s team of 3-Axies.
The group has also deployed operatives posing as remote IT employees to directly infiltrate crypto firms, a vector that AML and KYC controls at the corporate level are specifically designed to catch. Lummis frames Section 201’s extension of BSA obligations as an direct response to exactly this kind of insider-access attack surface.
Senator Elizabeth Warren has pushed back difficult, calling the Digital Asset Market Clarity Act a sanctions loophole in place of a sanctions tool. A former NSC Iran director. Those aren’t frivolous objections. Republicans have already absorbed extra ethics language right into a integrated draft launched July 22.












