North Korea stole a record $2 billion in crypto in 2025 — even as hacks declined

ambcryptoPublicado a 2025-12-18Actualizado a 2025-12-18

Resumen

North Korea set a record in 2025 by stealing $2.02 billion in cryptocurrency despite carrying out fewer attacks than in previous years, according to Chainalysis. The DPRK shifted its strategy from high-frequency exploits to targeted, high-value infiltrations, focusing on compromising people and internal systems—such as executives and contractors—rather than just code. A major driver was the $1.5 billion Bybit breach. The report also details North Korea's efficient 45-day laundering cycle using mixers, bridges, and off-ramping via Chinese OTC brokers. While DeFi protocols saw improved security breaches, retail wallet hacks rose to 158,000 incidents. North Korea remains the most significant state-level threat in crypto, with total lifetime thefts reaching $6.75 billion. The industry must now prioritize human and organizational security, not just technical defenses.

North Korea set a new record for crypto theft in 2025, stealing $2.02 billion despite carrying out far fewer attacks than in previous years, according to new data from Chainalysis.

The report indicates that the DPRK’s cyber strategy has shifted from high-frequency exploits to precision, high-value infiltrations—a change that signals an evolving threat to the global crypto ecosystem.

Fewer attacks, but bigger and more strategic heists

Chainalysis found that North Korea-linked groups now focus on deep, targeted intrusions rather than the broad exploit patterns seen in earlier cycles.

DPRK hackers stole more money in 2025 than in any year on record, while the total number of incidents actually fell.

A major driver was the $1.5 billion Bybit breach, but the trend extends beyond any single event.

The report highlights a shift toward infiltrating people and internal systems, not just codebases — including impersonating executives, compromising contractors, and gaining upstream access to drain funds.

This shift marks a new phase of state-level crypto exploitation: fewer hacks, larger payoffs, and far more strategic targeting.

DPRK relies on fast-moving laundering networks

The report also outlines how North Korea has refined its laundering operations.

Chainalysis identified a repeatable 45-day cycle used to clean stolen funds, involving:

  • rapid obfuscation through mixers,
  • chain-hops through bridges, and
  • eventual off-ramping via Chinese-language OTC brokers and instant exchangers.

Use of these off-ramp channels by DPRK-linked groups has surged between 97% and 1,000%, depending on the network.

Retail users face a different threat: mass wallet drains

While institutional targets faced the largest losses, retail users experienced a rising wave of account takeover attacks.

Chainalysis recorded 158,000 personal wallet hacks in 2025 — three times higher than in 2022.

Total value stolen from wallets dropped to $713 million, but Solana users took the largest hit, reflecting persistent exposure at the individual level even as DeFi platforms improve their security posture.

DeFi is more secure — but institutions are now the weak point

The report notes that despite the rise in total value locked across DeFi, successful protocol-level exploits remained surprisingly low.

Instead, attackers targeted the organizational layers surrounding these platforms:

  • IT contractors
  • executives
  • customer support personnel
  • internal system administrators
  • The attacks became about people, not smart contracts.

This evolution suggests traditional security models — which focus on code audits and protocol hardening — no longer address the most exploited vulnerabilities.

A new phase of global crypto security risk

Chainalysis warns that DPRK’s cyber operations have reached a level of sophistication that demands a new security approach.

With lifetime crypto thefts now at $6.75 billion, North Korea remains the single most dangerous state actor in the industry.


Final Thoughts

  • North Korea’s shift to high-impact, institution-level infiltrations marks a new era of crypto security risk.
  • The industry must harden its human and organizational defences, not just its smart contracts.

Preguntas relacionadas

QHow much did North Korea steal in cryptocurrency in 2025 according to Chainalysis?

ANorth Korea stole a record $2.02 billion in cryptocurrency in 2025.

QWhat major shift in cyber strategy did the report identify for DPRK-linked hacking groups?

AThe report identified a shift from high-frequency exploits to precision, high-value infiltrations, focusing on targeted intrusions rather than broad exploit patterns.

QWhat was a key component of North Korea's 45-day laundering cycle for stolen funds?

AKey components included rapid obfuscation through mixers, chain-hops through bridges, and off-ramping via Chinese-language OTC brokers and instant exchangers.

QHow did the number of personal wallet hacks in 2025 compare to 2022?

AChainalysis recorded 158,000 personal wallet hacks in 2025, which was three times higher than the number in 2022.

QWhat does the report suggest is now the weak point in crypto security, as opposed to protocol-level exploits?

AThe report suggests that organizational layers, such as IT contractors, executives, and internal system administrators, are now the weak point, as attackers are targeting people rather than smart contracts.

Lecturas Relacionadas

Raising Interest Rates Is Not a Tech Killer, EPS Is: A Strategy for Discarding the Weak and Retaining the Strong After the AI Theme's Sharp Decline

**Summary: Rising Interest Rates Are Not the Killer of Tech; EPS Is: The "Keep the Strong, Ditch the Weak" Strategy After the AI Theme Plunge** The author argues that the sharp sell-off in tech and AI-related stocks, triggered by a strong US jobs report that heightened Fed rate hike fears, represents a "pullback to pick up passengers" rather than a "car crash." The true end of a tech bull market is not determined by an extra 25 basis point hike, but by industry overcapacity and the disproval of earnings per share (EPS) expectations. Historical analysis shows that during past rate hike cycles, the Nasdaq-100 often outperformed, provided EPS growth remained strong. The current phase is seen as a shift from a "broad narrative-driven rally" to a "focused verification stage" for AI. The investment strategy should be to "keep the strong, ditch the weak." * **Retain exposure** to high-conviction AI infrastructure leaders with clear order visibility, stable margins, strong cash flow, and upward EPS revisions (e.g., AI servers, advanced packaging, optical modules, key cloud suppliers). * **Reduce exposure** to high-beta, narrative-driven stocks with unclear profit paths (e.g., some quantum computing, space, or speculative chip stocks), especially on rebounds. Valuation concerns should focus on whether earnings can catch up to high multiples, not on high P/E alone. Crowded positioning signals a concentration into quality assets, not necessarily a market top. The upcoming Q2 earnings season will be a key validation point. The core principle is to hold stocks with proven EPS, while using macro events (CPI data, central bank meetings) to manage timing and risk.

marsbitHace 4 hora(s)

Raising Interest Rates Is Not a Tech Killer, EPS Is: A Strategy for Discarding the Weak and Retaining the Strong After the AI Theme's Sharp Decline

marsbitHace 4 hora(s)

Trading

Spot
Futuros

Artículos destacados

Cómo comprar BILL

¡Bienvenido a HTX.com! Hemos hecho que comprar Billions Network (BILL) sea simple y conveniente. Sigue nuestra guía paso a paso para iniciar tu viaje de criptos.Paso 1: crea tu cuenta HTXUtiliza tu correo electrónico o número de teléfono para registrarte y obtener una cuenta gratuita en HTX. Experimenta un proceso de registro sin complicaciones y desbloquea todas las funciones.Obtener mi cuentaPaso 2: ve a Comprar cripto y elige tu método de pagoTarjeta de crédito/débito: usa tu Visa o Mastercard para comprar Billions Network (BILL) al instante.Saldo: utiliza fondos del saldo de tu cuenta HTX para tradear sin problemas.Terceros: hemos agregado métodos de pago populares como Google Pay y Apple Pay para mejorar la comodidad.P2P: tradear directamente con otros usuarios en HTX.Over-the-Counter (OTC): ofrecemos servicios personalizados y tipos de cambio competitivos para los traders.Paso 3: guarda tu Billions Network (BILL)Después de comprar tu Billions Network (BILL), guárdalo en tu cuenta HTX. Alternativamente, puedes enviarlo a otro lugar mediante transferencia blockchain o utilizarlo para tradear otras criptomonedas.Paso 4: tradear Billions Network (BILL)Tradear fácilmente con Billions Network (BILL) en HTX's mercado spot. Simplemente accede a tu cuenta, selecciona tu par de trading, ejecuta tus trades y monitorea en tiempo real. Ofrecemos una experiencia fácil de usar tanto para principiantes como para traders experimentados.

262 Vistas totalesPublicado en 2026.05.07Actualizado en 2026.06.02

Cómo comprar BILL

Qué es ATWO

I. Introducción al ProyectoArena Two es una plataforma interactiva descentralizada que permite a los fanáticos jugar un papel activo y tokenizado en los resultados de eventos en tiempo real. A diferencia de los modelos de transmisión tradicionales que reducen a los fanáticos a espectadores pasivos, Arena Two aprovecha la tecnología blockchain para permitir que los fanáticos voten directamente en tiempo real e influyan en los resultados en el campo.II. Información del TokenNombre del token: ATWO (Arena Two)III. Enlaces RelacionadosSitio web: https://arenatwo.com/Exploradores: https://basescan.org/token/0x499D35eBE6cEe9B2Ac35Fd003fcBbeeB9CFc7B32Twitter: https://x.com/arenatwoXNota: La introducción del proyecto proviene de los materiales publicados o proporcionados por el equipo oficial del proyecto, que es solo para referencia y no constituye asesoramiento de inversión. HTX no se hace responsable de ninguna pérdida directa o indirecta resultante.

161 Vistas totalesPublicado en 2026.05.18Actualizado en 2026.06.02

Qué es ATWO

Cómo comprar ATWO

¡Bienvenido a HTX.com! Hemos hecho que comprar Arena Two (ATWO) sea simple y conveniente. Sigue nuestra guía paso a paso para iniciar tu viaje de criptos.Paso 1: crea tu cuenta HTXUtiliza tu correo electrónico o número de teléfono para registrarte y obtener una cuenta gratuita en HTX. Experimenta un proceso de registro sin complicaciones y desbloquea todas las funciones.Obtener mi cuentaPaso 2: ve a Comprar cripto y elige tu método de pagoTarjeta de crédito/débito: usa tu Visa o Mastercard para comprar Arena Two (ATWO) al instante.Saldo: utiliza fondos del saldo de tu cuenta HTX para tradear sin problemas.Terceros: hemos agregado métodos de pago populares como Google Pay y Apple Pay para mejorar la comodidad.P2P: tradear directamente con otros usuarios en HTX.Over-the-Counter (OTC): ofrecemos servicios personalizados y tipos de cambio competitivos para los traders.Paso 3: guarda tu Arena Two (ATWO)Después de comprar tu Arena Two (ATWO), guárdalo en tu cuenta HTX. Alternativamente, puedes enviarlo a otro lugar mediante transferencia blockchain o utilizarlo para tradear otras criptomonedas.Paso 4: tradear Arena Two (ATWO)Tradear fácilmente con Arena Two (ATWO) en HTX's mercado spot. Simplemente accede a tu cuenta, selecciona tu par de trading, ejecuta tus trades y monitorea en tiempo real. Ofrecemos una experiencia fácil de usar tanto para principiantes como para traders experimentados.

193 Vistas totalesPublicado en 2026.05.18Actualizado en 2026.06.02

Cómo comprar ATWO

Discusiones

Bienvenido a la comunidad de HTX. Aquí puedes mantenerte informado sobre los últimos desarrollos de la plataforma y acceder a análisis profesionales del mercado. A continuación se presentan las opiniones de los usuarios sobre el precio de A (A).

活动图片