|
News North Korean crypto theft hits new high in 2025 on back of Bybit heist: ReportsResearchers say DPRK actors stole up to $2B this year, accounting for over half of all global crypto theft North Korean cybercriminals took their already prolific cryptocurrency theft to new highs in 2025 despite carrying out fewer confirmed attacks this year, according to blockchain researchers, as Pyongyang refined its proven tactics to inflict more damage. Driven largely by the record theft of $1.46 billion from the Dubai-based exchange Bybit in February, DPRK actors have pulled in at least $2.02 billion in stolen virtual currency so far this year, U.S. blockchain analytics firm Chainalysis said in a report Thursday. In the process, North Korea comfortably surpassed its previous largest haul of $681 million last year, becoming the first nation-state actor to steal cryptocurrency worth over $2 billion in a single year. This year’s sum takes Pyongyang’s cumulative virtual currency theft to over $6.75 billion since 2016, the firm assessed. This figure represented almost 60% of all cryptocurrency theft worldwide in 2025, which amounted to $3.4 billion, according to the report. North Korea also accounted for 76% of all attacks compromising services such as exchanges, with other global actors mostly targeting personal wallets. TRM Labs, another U.S. blockchain analytics company, offered a more conservative estimate of DPRK and global cryptocurrency crime in 2025, according to a report Thursday. The firm said DPRK-linked actors were responsible for the theft of over $1.5 billion in virtual assets this year, more than half of the $2.7 billion stolen worldwide. This amount is almost double the $800 million TRM attributed to Pyongyang-backed actors last year. TRM’s figure appears to suggest virtually all of Pyongyang’s stolen proceeds this year came from the Bybit attack, but the firm also highlighted North Korean actors’ broader focus on centralized exchanges and custodial service providers offering secure storage for digital assets. Discrepancies in estimates between analytics firms are quite common as researchers attribute attacks differently based on the information available to them, which may change further if new data emerges later. North Korean actors’ expanding crypto crime operations highlight Pyongyang’s increased reliance on cybercrime to generate foreign currency for its weapons development. “North Korea’s crypto theft operations function as a structured, state-directed revenue system — a coordinated apparatus that blends cyber activity, intelligence support, illicit finance infrastructure and partnerships with overseas facilitators,” TRM said. SHIFTING TARGETS North Korea appears to be the exception to the global norm favoring personal wallet compromises, with the Bybit heist representing more than 1,000 times the median theft value this year, according to Chainalysis. “The DPRK continues to undertake significantly higher-value attacks than other threat actors,” the firm said. “When North Korean hackers strike, they target large services and aim for maximum impact.” TRM assessed that North Korea has moved on from targeting decentralized bridges facilitating transfers between different blockchains to “centralized giants,” such as global exchanges, to maximize returns. While the targets have shifted in recent years, North Korean cybercriminals’ methods have been “refined, not reinvented,” the firm said. DPRK actors have long relied on social engineering skills that exploit human error, and TRM said they infiltrate target networks by deploying malware through fake job offers sent to unsuspecting developers. After gaining access, they try to take control of systems that authorize withdrawals, after which they start converting stolen assets to other virtual currencies to throw investigators off their trail. Chainalysis noted that DPRK actors are also increasingly pulling off “outsized” thefts by embedding remote IT workers inside cryptocurrency services to gain privileged access. These overseas workers are also increasingly impersonating recruiters for prominent Web3 and AI firms to acquire credentials, source code and network access, the firm added. LAUNDERING STRATEGIES North Korean cybercriminals typically cash out their stolen cryptocurrency in three waves over the course of approximately 45 days, according to Chainalysis. Initially, they try to distance the stolen assets from the source by moving them through decentralized finance (DeFi) protocols and mixers that combine them with other virtual tokens. They then begin transferring funds to other services linked to the broader ecosystem, including exchanges, cross-chain bridges and other mixing services. Finally, they move toward “off-ramps” designed for conversion to official currency, including financial services without know-your-customer (KYC) protocols, centralized exchanges and online marketplaces in less regulated markets. North Korean cybercriminals are particularly reliant on what TRM Labs described as the “Chinese Laundromat,” a vast network of underground bankers, over-the-counter (OTC) brokers, money transmitters and traders who have stepped in to fill the void left by sanctioned mixers. These “professional money-laundering organizations” launder stolen assets across different blockchains, jurisdictions and payment systems long before they enter the DPRK financial system, making it harder to shutter Pyongyang’s sanctions evasion activities. This network has allowed Pyongyang to move its record cryptocurrency haul more effectively than its traditional toolkit, and TRM called for a unified strategy linking governments, financial institutions and technology firms to counter the world’s “most sophisticated, financially motivated cyber operator.” Chainalysis also emphasized the need for “enhanced vigilance” and improved detection of DPRK laundering patterns to curb its financially-motivated cybercrime. “As North Korea continues to use cryptocurrency theft to fund state priorities and circumvent international sanctions, the industry must recognize that this threat actor operates by different rules than typical cybercriminals,” the firm said. Edited by David Choi © Korea Risk Group. All rights reserved. |





