Crypto theft will remain a core funding strategy for North Korea, expert warns

2025-12-30 14:31

North Korean hackers were behind the vast majority of crypto-targeted security breaches in 2025, and the threat is only expected to amplify in the years ahead, according to Chainalysis’s head of national security intelligence, Andrew Fierman.

“North Korea will always seek new vectors to steal funds on behalf of the regime, whether through fiat or crypto,” Fierman told crypto media, adding that “their mechanisms are forever evolving, and are highly sophisticated, diversified, and deeply embedded across jurisdictions.”

As previously reported by Invezz, North Korean hackers were behind the lion’s share of attacks that hit the cryptocurrency space in 2025.

Throughout the year, state-backed cyber groups were responsible for 76% of service-level compromises across exchanges and custodians, successfully stealing at least $2.02 billion worth of crypto assets.

The 2025 numbers marked a 51% year-on-year increase, despite a nearly 74% decrease in the total number of confirmed incidents, highlighting a strategic shift toward fewer but significantly larger incidents.

Interestingly, just three incidents alone were responsible for 69% of total service-level losses, which goes to show that notorious hacking outfits like the Lazarus Group and the affiliated UNC5342 are now focused almost entirely on breaching large infrastructure targets that promise bigger and faster payouts.

For the crypto industry, this translates to significantly larger financial losses that can potentially disrupt entire ecosystems and wipe out the funds of vast numbers of investors across the globe.

One of the biggest incidents of the year involving North Korean groups was the $1.5 billion Bybit hack that shook the industry back in late February.

Over 400,000 ETH was stolen in the breach, leading to the largest digital asset heist in the history of the crypto industry.

Several other incidents followed, including the $223 million theft from the decentralized exchange Cetus, and a $128 million exploit targeting the Ethereum-based protocol Balancer.

Additional confirmed breaches at WOO X, Seedify, and LND.fi only added to the staggering figures that made 2025 the most successful year to date for North Korean hackers.

Over the past several months, North Korean actors have been found to be using a variety of attack vectors to breach targets. 

For instance, back in October, they were found to be embedding malware within Ethereum and BNB Chain smart contracts as part of a stealth campaign now linked to the state-backed group UNC5342.

Across the globe, major economies like the United States, South Korea, Australia, and members of the European Union have rolled out targeted sanctions against North Korea’s cybercrime infrastructure in a bid to curb its illegal revenue generation. 

But that alone may not be enough, according to Andrew Fierman, who noted that disrupting North Korea’s operations requires coordinated action across the entire industry, including exchanges, infrastructure providers, analytics firms, and law enforcement agencies.

Fierman warned that the regime is expected to continue to rely on crypto theft as a primary revenue stream, especially as international sanctions tighten and other income channels shrink.

Evolving crypto laundering techniques

Once the funds are stolen, the process by which they are laundered further compounds the problem, making recovery efforts extremely difficult and transforming the threat into a persistent and systemic risk for the broader crypto ecosystem.

“Stolen funds follow diverse laundering paths, including mixing services, OTC brokers, chain-hopping, token swaps, decentralised exchanges, and bridge protocols to obscure flows,” Fierman said.

Some of the techniques used by North Korean groups include the so-called Chinese laundromat network, which comprises over-the-counter brokers, underground banking channels, and cross-border money transmitters based largely in China and Southeast Asia.

On the technical side, they rely on complex cross-chain bridge routes and a rotation of mixing services to fragment the stolen assets across blockchains. These are often withdrawn through loosely regulated Chinese-language platforms with weak KYC requirements.

Although North Korea’s cyber attacks also target areas beyond the crypto sector, the crypto industry remains an especially attractive target, mainly due to its liquidity, global accessibility, and fragmented oversight.

Last month, during the Devconnect conference in Buenos Aires, web3 audit firm Opsek’s founder Pablo Sabbatella warned that roughly 30% to 40% of applicants flooding into crypto jobs may be North Korean attempts to gain insider access through fake identities.

The post Crypto theft will remain a core funding strategy for North Korea, expert warns appeared first on Invezz

origin »

North Korean Won (KPW) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.00 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Доступно / Всего 0 KPW

north crypto korea attack contract smart malware

north crypto → Результатов: 126


Фото:

North Korean Crypto Social Media Monitoring on the Rise

Recent reports by the South Korean press warned that North Korea might be expanding its crypto social media monitoring.   Yesterday’s report by NK Economy claims that North Korean firm Marine Chain is actively keeping an eye on leading names in the crypto and blockchain space This would not have mattered for most other companies, but for Marine Chain, it has a particular significance.

2019-12-7 11:47


Фото:

UN Panel: North Korea Hacked $571M From Asian Crypto Exchanges

The U.N. Security Council has heard that North Korea uses cyberattacks and blockchain technology to evade economic sanctions and obtain foreign currency. Through hacking, the reclusive Republic has raked in around $670 million in foreign exchange and cryptocurrency, a panel of experts told the Security Council’s North Korea sanctions committee, ahead of the council’s annual […] The post UN Panel: North Korea Hacked $571M From Asian Crypto Exchanges appeared first on Bitcoin News.

2019-3-9 23:25


Майк Новограц предсказал рост биткоина «через несколько месяцев»

Основатель и CEO инвестиционной компании Galaxy Digital Майк Новограц заявил, что по-прежнему верит в рост биткоина, однако случится это, по его мнению, не ранее чем через несколько месяцев. Об этом он написал в Twitter.

2019-2-3 12:05


Фото:

Top Officials at Two Korean Cryptocurrency Exchanges Face Fraud Indictments

Several of South Korea’s top crypto exchanges have found themselves in hot water, with executives at a couple of exchanges facing criminal charges and jail time. According to a news report on the Korean website Blockinpress, the CEO of Komid, a Korean crypto exchange, has received a three-year prison sentence for committing fraud against investors by artificially inflating the exchange’s actual trading volume.

2019-1-23 00:57


Фото:

Alternative Investment Firm Regal Assets Expands Crypto Reach to Canada

Regal Assets is one of North America’s most trusted alternative investment firms. The company has recently announced it was expanding its service to support Registered Retirement Savings Plan (RRSP) for Tax-Free Savings Account (TFSA) Canadian investors According to reports, Regal Assets, a firm that specializes in offering alternative investment services for retirement account holders, has officially announced it was opening.

2019-1-10 04:00


Фото:

Report: Cryptocurrency Related Lawsuits Skyrocketed in 2018; Up by 300 Percent

In contrast with the bear market we have watched throughout the year it seems that cryptocurrency-related lawsuits have skyrocketed as far up to 300 percent, reports Dior, November 19, 2018. Crypto Lawsuits Go North While bitcoin continues to go south, the business for digital currency focused lawyers looks to have a bright future ahead.

2018-11-23 16:00