North Korea Blamed for £17m Crypto Heist That Bankrupted UK Start-Up
UK crypto firm Lykke collapses after £17m hack blamed on North Korea’s Lazarus Group, raising alarms over state-backed cyber theft.
North Korea’s infamous Lazarus Group has been accused of carrying out a £17 million cryptocurrency theft that led to the collapse of Lykke, a British-registered trading platform. If confirmed, it would mark the regime’s most significant known digital heist against a UK company, underscoring Pyongyang’s increasing reliance on cybercrime to fund its sanctioned military and nuclear programs.
Lykke, founded in 2015 by Richard Olsen—a descendant of Swiss banking patriarch Julius Baer—was incorporated in the UK but operated primarily from Zug, Switzerland, within the country’s so-called “crypto valley.” The platform promoted itself as a fee-free trading exchange, but it was forced to freeze operations after reporting losses of $22.8 million (£16.8m) in Bitcoin, Ethereum, and other digital assets. By March 2025, a UK court ordered the company to be liquidated following petitions from more than 70 customers who collectively lost £5.7 million.
A recent report by the Office of Financial Sanctions Implementation (OFSI), part of the UK Treasury, attributed the theft to “malicious Democratic People’s Republic of Korea cyberactors, who stole funds on both the Bitcoin and Ethereum networks.” The Treasury said OFSI worked closely with law enforcement agencies but did not disclose the intelligence sources behind the attribution.
Independent research firms have also weighed in. Whitestream, an Israeli crypto intelligence company, separately blamed Lazarus, asserting that the stolen funds were laundered through two cryptocurrency services notorious for bypassing anti-money laundering controls. However, other analysts have disputed these claims, arguing that the evidence remains circumstantial and that definitive attribution is difficult in the opaque world of blockchain forensics.
The collapse of Lykke has had lasting repercussions for both its customers and its leadership. Olsen, who once positioned the platform as a disruptive force in crypto finance, was declared bankrupt in January and now faces criminal investigations in Switzerland. The company’s Swiss parent entity also entered liquidation last year. Interpath Advisory has since been appointed to oversee the distribution of remaining funds to affected users.
The Financial Conduct Authority (FCA) had already issued a warning about Lykke in 2023, noting that it was not authorised to offer financial services to UK consumers. That warning has resurfaced in the wake of the collapse, adding to criticism that regulators were slow to respond to potential risks in the exchange’s operations.
For North Korea, the alleged heist fits a broader pattern. International monitors estimate that Pyongyang has stolen billions in digital assets over the past decade, using the funds to circumvent sanctions and bankroll weapons development. The Lazarus Group, long accused of orchestrating major hacks including the WannaCry ransomware outbreak and attacks on global banks, remains central to these operations.
The Lykke case illustrates the vulnerability of even established platforms to state-backed cybercrime. It also underscores the urgent need for tighter regulatory frameworks and improved cybersecurity standards to protect both investors and the broader financial system.



