FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
MCap $2.7T +0.1%24h Vol $46.6B -58%Fear & Greed 63/100Alts Index 31/100
BTC.D 58.4% 0%Stable.D 10.0% 0%ETH.D 11.6% +0.1%Others.D 20.0% -0.1%
AI$0.3437+36.42%UAI$0.7955+18.86%BTW$0.5531+10.54%PENDLE$2.195+9.83%PROM$5.685+9.59%ZRX$0.1090+8.5%PYTH$0.0548+8.1%USELESS$0.2284+7.09%CRO$0.0602+6.75%UNI$6.353+6.35%
APEPE$0.00000133-20.5%Q$0.0239-11.18%RAY$1.528-9.48%XCN$0.00421916-7.07%EGLD$4.339-6.8%MET$0.2285-4.24%RAIN$0.0152-4.23%MORPHO$2.211-3.83%ZEN$6.252-3.62%MNT$0.5584-3.62%
Top movers 24h
    Filters
      Coins
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      North Korean Crypto Heists: How Hackers Target Digital…

      KEY TAKEAWAYS
      1. North Korea's Lazarus Group has stolen an estimated $6.75 billion in cryptocurrency since 2017, making it the single largest state-sponsored crypto theft operation documented by researchers globally.
      2. The February 2025 Bybit hack yielded $1.5 billion in one single attack, representing the largest individual cryptocurrency theft ever recorded, according to FBI attribution and blockchain analysis firms.
      3. Lazarus Group includes one identified unit, APT38, also known as BlueNoroff, alongside two long-running campaign clusters tracked as TraderTraitor and AppleJeus.
      4. Stolen cryptocurrency flows through a structured laundering pipeline using cross-chain bridges, mixer services, and over-the-counter desks within a documented 45-day average conversion window period.
      5. Chainalysis data shows North Korean hackers accounted for 60% of the more than $3.4 billion in cryptocurrency stolen globally from January through early December 2025, far exceeding other nation-state and criminal hacking groups.
        State-sponsored cryptocurrency theft has grown into a multibillion-dollar national security issue. North Korea's hacking units have targeted exchanges, bridges, and DeFi protocols since 2017. The scale of their operations now exceeds any private criminal enterprise operating worldwide.The Lazarus Group sits at the centre of this ongoing state-sponsored hacking campaign. The group operates under multiple code names across overlapping attack clusters globally. This article examines how North Korean hackers identify targets and execute breaches.It also covers the specific incidents that define the current threat landscape. Understanding these methods helps exchanges and individuals protect their digital assets effectively. The financial scale of these operations demands attention from the entire crypto industry.

      The $6.75 Billion Theft Timeline From 2017 to 2026

      North Korean crypto theft operations began against South Korean exchanges in 2017 directly. The Youbit exchange declared bankruptcy after two separate Lazarus Group breaches that year. Total losses during those initial years reached approximately $500 million across multiple targets.The operation scaled dramatically in March 2022 with the Ronin bridge attack incident. That single incident yielded $625 million from the Axie Infinity-connected bridge infrastructure. It demonstrated Lazarus Group's strategic shift toward cross-chain bridge vulnerabilities specifically.Chainalysis data shows North Korea-linked hackers stole approximately $1.7 billion in cryptocurrency in 2022 and slightly more than $1.0 billion in 2023. Each year brought significant thefts and increasingly sophisticated attack methods from hackers.The February 2025 Bybit hack marked a qualitative escalation, yielding $1.5 billion alone. Chainalysis documented total North Korean theft at $2.02 billion for 2025. That figure represented 60% of the more than $3.4 billion in cryptocurrency stolen globally from January through early December 2025.Through April 2026, an additional $577 million was stolen, including a Kelp DAO exploit. The cumulative total now stands at $6.75 billion in stolen cryptocurrency assets worldwide. UN Panel of Experts reports document how these proceeds fund weapons programmes directly.North Korea arguably qualifies as the most prolific financial cyber threat actor today. No private criminal organisation has matched the scale of these state-sponsored operations. The trajectory suggests annual theft totals will continue climbing in future years.Each major hack has targeted a different vulnerability in the cryptocurrency infrastructure ecosystem. This pattern shows the Lazarus Group continuously adapts its methods to exploit new weaknesses. The group's ability to evolve makes it exceptionally difficult for defenders to anticipate.

      How Lazarus Group Executes Cryptocurrency Exchange Breaches

      The Lazarus Group includes one identified unit, APT38, also known as BlueNoroff, alongside two long-running campaign clusters tracked as TraderTraitor and AppleJeus. APT38 focuses on financial system intrusions, while TraderTraitor targets cryptocurrency platforms through social engineering campaigns against employees.The Bybit attack illustrates the TraderTraitor method in documented operational detail clearly. Attackers compromised a developer's laptop at Safe{Wallet}, the multisig platform Bybit used. FBI attribution confirmed they redirected $1.5 billion during a scheduled wallet transfer operation.The attack exploited trust in third-party infrastructure rather than Bybit's own systems. The transaction appeared completely legitimate to Bybit operators during the transfer process itself. Only after completion did the unauthorised redirection of funds become apparent to staff.By March 2026, OFAC designated new targets connected to North Korean IT worker infiltration. Sanctions briefings reveal operatives pose as recruiters for Web3 and AI companies globally. They harvest credentials, source code, and VPN access from unsuspecting employees systematically.The AppleJeus campaign deploys supply chain attacks through compromised software update channels. Legitimate software packages receive malicious modifications that create backdoor access for attackers. Exchange operators installing routine updates unknowingly grant network access to North Korean hackers.These units and campaign clusters operate through different methods but can share a common laundering infrastructure for stolen funds afterward. A single exchange may face social engineering and infrastructure attacks simultaneously from multiple teams. Bybit CEO Ben Zhou confirmed the breach originated from third-party vendor infrastructure directly.The overlap between these units and campaign clusters makes attribution and defence significantly more complicated for targets. Security teams must defend against multiple attack vectors from a single coordinated state actor. This multi-pronged approach distinguishes Lazarus Group from typical private hacking organisations operating today.

      The Laundering Pipeline: From Theft to Fiat Cash

      Stolen cryptocurrency follows a structured four-stage laundering process after each successful theft. The first stage involves rapid cross-chain movement within hours of the initial hack. Attackers convert stolen tokens across multiple blockchains to fragment transaction history trails immediately.Speed is critical during the first stage because exchanges can freeze identified wallet addresses. Lazarus Group typically disperses funds across hundreds of wallets within the first 24 hours. This rapid dispersal makes comprehensive freezing nearly impossible for compliance teams to achieve.The second stage uses mixer services that pool transactions from multiple wallet users. After the US Treasury sanctioned Tornado Cash, Lazarus pivoted to alternative mixing services. Privacy coins with built-in anonymisation features also entered their laundering toolkit during 2023.Stage three involves chain hopping through decentralised bridges and peer-to-peer transactions. The final stage converts crypto to fiat through over-the-counter desk operations globally. Chinese money laundering services handle the majority of final conversion steps overall.The entire pipeline is historically completed within three to twelve months after initial theft. Recent operations suggest the timeline is accelerating as laundering techniques improve continuously. In the Bybit case, Chainalysis documented rapid dispersal of the stolen funds, with the FBI publishing 51 Ethereum addresses linked to the laundering operation within days.The FBI released 51 Ethereum addresses linked to the Bybit laundering operation publicly afterward. Compliance teams at exchanges can screen deposits against OFAC's SDN list for known matches. However, rapid fund dispersal across thousands of addresses limits effective freezing opportunities significantly.Over-the-counter desks in jurisdictions with weak enforcement provide the final cash conversion. These desks operate outside regulated financial systems and face minimal compliance requirements currently. Closing this gap requires international coordination that has proven difficult to achieve so far.

      Exchange Defences and Global Industry Response Measures

      North Korean operations have forced structural changes in exchange custody management practices worldwide. Multisig wallet providers implemented additional verification layers after the Safe{Wallet} compromise incident. Several major exchanges now require hardware security keys for all developer signing accounts.Bybit filed a lawsuit against North Korea and the Lazarus Group in August 2026. CoinDesk reported the legal action secured asset freeze orders against identified wallet addresses. Whether courts can enforce judgments against North Korean entities remains an open legal question.The lawsuit represents an unusual attempt to use civil litigation against a state actor. Legal experts question whether meaningful asset recovery is possible through this court approach. The precedent could influence how future exchange breach victims pursue legal remedies globally.Blockchain analytics firms now flag suspicious addresses within minutes of major theft events. Chainalysis reported that DPRK actors accounted for a record 76% of all service compromises in 2025. Exchange security budgets effectively compete against a state military intelligence operation every day.Industry groups have established shared threat intelligence databases to coordinate defensive responses collectively. Real-time alerts between exchanges enable faster freezing of funds moving through identified addresses. These collaborative efforts have improved, but still lag behind the speed of laundering operations.The next escalation point will likely involve AI-generated deepfakes in recruitment scam operations. Developer vetting processes relying on video interviews may prove insufficient against synthetic identities. Exchanges failing to adapt to hiring security remain vulnerable to infiltration tactics from state attackers.Third-party vendor security has become a critical focus area after the Bybit case. Exchanges increasingly require vendors to meet specific security standards before granting system access. The industry's defensive posture continues evolving in response to each new attack method used.

      FAQs

      How much cryptocurrency has North Korea stolen in total since 2017? North Korea's Lazarus Group has stolen an estimated $6.75 billion in cryptocurrency since 2017, according to Chainalysis cumulative data and blockchain analysis reports compiled through early 2026 research. What was the largest single cryptocurrency heist by North Korean hackers? The February 2025 Bybit exchange hack yielded approximately $1.5 billion in stolen cryptocurrency, making it the largest individual crypto theft ever publicly attributed to a state-sponsored actor. How does the Lazarus Group typically attack cryptocurrency exchanges worldwide? Lazarus Group uses social engineering, developer laptop compromises, supply chain attacks through compromised software updates, and fake recruitment campaigns that specifically target employees at Web3 and cryptocurrency companies. What happens to cryptocurrency after North Korean hackers successfully steal it? Stolen crypto moves through a four-stage laundering pipeline involving cross-chain transfers, cryptocurrency mixer services, chain hopping via decentralised bridges, and final fiat conversion through OTC desk operations. Can stolen cryptocurrency from North Korean heists ever be recovered afterward? Recovery is extremely difficult in most documented cases overall. The FBI has frozen some identified addresses, but rapid cross-chain dispersal across thousands of wallets severely limits effective asset seizure. What role does the FBI play in tracking North Korean crypto theft? The FBI attributes attacks to specific groups, publishes wallet addresses linked to stolen funds, issues public service announcements for exchanges, and coordinates with international partners to freeze identified assets. How can cryptocurrency exchanges protect against state-sponsored hacking operations effectively? Exchanges implement hardware security keys, enhanced developer vetting processes, real-time OFAC screening, multisig verification layers, and regular third-party vendor security audits to reduce breach risk effectively.

      References

      1. Picus Security - FBI Confirms North Korean Lazarus Group Behind $1.5 Billion Bybit Crypto Heist.
      2. Hacker News - North Korea Linked Hackers Steal $2.02 Billion in 2025, Leading Global Crypto Theft.
      3. Sanctions.io - The Lazarus Group and DPRK Crypto Theft in 2026: Compliance Team Guide.
      4. CoinDesk - Bybit Sues North Korea and Lazarus Group Over $1.5 Billion Hack.

      Source: FinanceFeeds
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud