Blockchain AcademicsBlockchain Academics
How North Korea Turned Precision Cybercrime Into the Crypto Industry’s Biggest Threat

How North Korea Turned Precision Cybercrime Into the Crypto Industry’s Biggest Threat

North Korea led global crypto theft in 2025, stealing over $2 billion through fewer but far more sophisticated attacks.

Blockchain Academics NewsroomDecember 21, 20253 min read
Share

North Korea has cemented its position as the most prolific state-backed crypto thief in the world, stealing more than $2 billion in digital assets in 2025 and accounting for nearly 60 percent of all cryptocurrency theft globally. New findings from blockchain analytics firm Chainalysis suggest the country’s hackers are no longer relying on volume, but on precision, scale, and deep infiltration to maximize impact.

Between January and early December, North Korea–linked groups siphoned off roughly $2.02 billion in crypto, a 51 percent increase compared with the previous year. Global crypto theft for 2025 reached an estimated $3.4 billion, pushing Pyongyang’s cumulative haul to about $6.75 billion. The figures come from Chainalysis’s annual review of crypto crime, which paints a picture of fewer attacks but dramatically higher-value breaches.

That shift is one of the report’s most striking conclusions. While the total number of hacking incidents tied to North Korea fell by 74 percent compared with 2024, their effectiveness surged. North Korean groups were responsible for 76 percent of all service-level compromises, excluding personal wallet hacks. According to Chainalysis, non–North Korean attackers showed a relatively even spread across theft sizes, but North Korean operations overwhelmingly dominated the largest losses. “When North Korean hackers strike, they target large services and aim for maximum impact,” the report noted.

The change in strategy reflects the evolving security landscape of crypto. As decentralized finance protocols have hardened their defenses, attackers have increasingly turned their attention to centralized exchanges and custodial platforms. The February breach of Dubai-based exchange Bybit, which resulted in losses of around $1.5 billion and stands as the largest crypto heist on record, exemplifies this pivot toward fewer but catastrophic attacks.

Chainalysis identified insider access as a critical factor behind these outsized thefts. North Korean operatives have been embedding IT workers inside crypto companies, granting themselves privileged access that can later be exploited. “North Korean threat actors are increasingly achieving these outsized results by embedding IT workers inside crypto services,” the report said, enabling compromises that would be nearly impossible through external exploits alone.

Once assets are stolen, laundering follows a disciplined and increasingly sophisticated pattern. More than 60 percent of stolen funds were moved on-chain in transactions under $500,000, a stark contrast to other attackers, whose transfers tend to exceed $1 million. This fragmentation reflects both an effort to evade detection and the structural constraints North Korea faces due to its isolation from the global financial system. Historically, laundering unfolds over about 45 days, with funds rapidly shuffled to obscure their origin before slowly re-entering the broader crypto ecosystem through exchanges, bridges, and mixing services.

The report also highlighted the role of external facilitators, particularly Chinese-language laundering networks. It singled out Cambodia-based Huione Group, which US authorities identified this year as a major conduit for laundering proceeds from North Korean cyber thefts, estimated at at least $4 billion since 2021. Washington has since barred US financial institutions from engaging with the firm.

Perhaps most concerning is how North Korea’s methods are evolving beyond fake IT résumés. Hackers are now posing as recruiters at prominent Web3 and AI firms, running elaborate hiring processes to extract credentials, code, and system access. Others masquerade as investors, using staged pitches to quietly map internal networks. Together, these tactics underscore a sobering reality: North Korea’s crypto operations are becoming more strategic, patient, and deeply embedded, posing a systemic risk to the digital asset industry as a whole.

Discussion

Loading comments...