North Korea stole a record $2 billion in crypto in 2025 — even as hacks declined

ambcryptoPublished on 2025-12-18Last updated on 2025-12-18

Abstract

North Korea set a record in 2025 by stealing $2.02 billion in cryptocurrency despite carrying out fewer attacks than in previous years, according to Chainalysis. The DPRK shifted its strategy from high-frequency exploits to targeted, high-value infiltrations, focusing on compromising people and internal systems—such as executives and contractors—rather than just code. A major driver was the $1.5 billion Bybit breach. The report also details North Korea's efficient 45-day laundering cycle using mixers, bridges, and off-ramping via Chinese OTC brokers. While DeFi protocols saw improved security breaches, retail wallet hacks rose to 158,000 incidents. North Korea remains the most significant state-level threat in crypto, with total lifetime thefts reaching $6.75 billion. The industry must now prioritize human and organizational security, not just technical defenses.

North Korea set a new record for crypto theft in 2025, stealing $2.02 billion despite carrying out far fewer attacks than in previous years, according to new data from Chainalysis.

The report indicates that the DPRK’s cyber strategy has shifted from high-frequency exploits to precision, high-value infiltrations—a change that signals an evolving threat to the global crypto ecosystem.

Fewer attacks, but bigger and more strategic heists

Chainalysis found that North Korea-linked groups now focus on deep, targeted intrusions rather than the broad exploit patterns seen in earlier cycles.

DPRK hackers stole more money in 2025 than in any year on record, while the total number of incidents actually fell.

A major driver was the $1.5 billion Bybit breach, but the trend extends beyond any single event.

The report highlights a shift toward infiltrating people and internal systems, not just codebases — including impersonating executives, compromising contractors, and gaining upstream access to drain funds.

This shift marks a new phase of state-level crypto exploitation: fewer hacks, larger payoffs, and far more strategic targeting.

DPRK relies on fast-moving laundering networks

The report also outlines how North Korea has refined its laundering operations.

Chainalysis identified a repeatable 45-day cycle used to clean stolen funds, involving:

  • rapid obfuscation through mixers,
  • chain-hops through bridges, and
  • eventual off-ramping via Chinese-language OTC brokers and instant exchangers.

Use of these off-ramp channels by DPRK-linked groups has surged between 97% and 1,000%, depending on the network.

Retail users face a different threat: mass wallet drains

While institutional targets faced the largest losses, retail users experienced a rising wave of account takeover attacks.

Chainalysis recorded 158,000 personal wallet hacks in 2025 — three times higher than in 2022.

Total value stolen from wallets dropped to $713 million, but Solana users took the largest hit, reflecting persistent exposure at the individual level even as DeFi platforms improve their security posture.

DeFi is more secure — but institutions are now the weak point

The report notes that despite the rise in total value locked across DeFi, successful protocol-level exploits remained surprisingly low.

Instead, attackers targeted the organizational layers surrounding these platforms:

  • IT contractors
  • executives
  • customer support personnel
  • internal system administrators
  • The attacks became about people, not smart contracts.

This evolution suggests traditional security models — which focus on code audits and protocol hardening — no longer address the most exploited vulnerabilities.

A new phase of global crypto security risk

Chainalysis warns that DPRK’s cyber operations have reached a level of sophistication that demands a new security approach.

With lifetime crypto thefts now at $6.75 billion, North Korea remains the single most dangerous state actor in the industry.


Final Thoughts

  • North Korea’s shift to high-impact, institution-level infiltrations marks a new era of crypto security risk.
  • The industry must harden its human and organizational defences, not just its smart contracts.

Related Questions

QHow much did North Korea steal in cryptocurrency in 2025 according to Chainalysis?

ANorth Korea stole a record $2.02 billion in cryptocurrency in 2025.

QWhat major shift in cyber strategy did the report identify for DPRK-linked hacking groups?

AThe report identified a shift from high-frequency exploits to precision, high-value infiltrations, focusing on targeted intrusions rather than broad exploit patterns.

QWhat was a key component of North Korea's 45-day laundering cycle for stolen funds?

AKey components included rapid obfuscation through mixers, chain-hops through bridges, and off-ramping via Chinese-language OTC brokers and instant exchangers.

QHow did the number of personal wallet hacks in 2025 compare to 2022?

AChainalysis recorded 158,000 personal wallet hacks in 2025, which was three times higher than the number in 2022.

QWhat does the report suggest is now the weak point in crypto security, as opposed to protocol-level exploits?

AThe report suggests that organizational layers, such as IT contractors, executives, and internal system administrators, are now the weak point, as attackers are targeting people rather than smart contracts.

Related Reads

Bear Market Script: Which Act Is Your 'Faith' Experiencing?

The article "Bear Market Script: Which Act Is Your 'Faith' Experiencing?" by TVBee analyzes the typical stages of a cryptocurrency bear market, using Bitcoin (BTC) and Tether (USDT) market capitalization as key indicators. It identifies 3-4 phases: 1. **Reaction Phase (Faith Intact)**: BTC declines while USDT rises, indicating some investors still hold hope. 2. **Confirmation Phase (Faith Collapses)**: BTC may fall or stagnate, and USDT decreases, confirming the bear market as capital exits. 3. **Accumulation Phase (Faith Consolidates)**: BTC may drop or trade sideways, but USDT rises again, suggesting stronger believers are preparing to re-enter. 4. **Final Panic Phase (Black Swan)**: A optional phase where both BTC and USDT fall sharply due to extreme events (e.g., 2022’s Luna collapse). The author suggests the current market (early 2026) is likely in Phase 2, driven by geopolitical tensions like the Iran conflict. The duration of this phase depends on external factors such as Trump administration policies, monetary changes, and potential black swan events. Ideal entry points for investors are during Phase 3 (USDT rising) or in the recovery phase (right-side entry), where USDT growth and BTC stabilization signal a market rebound. The analysis notes that bear markets are evolving—Phase 1 is shortening, but Phase 2 remains unpredictable due to external shocks. Caution and patience are advised.

marsbit44m ago

Bear Market Script: Which Act Is Your 'Faith' Experiencing?

marsbit44m ago

Trading

Spot
Futures

Hot Articles

How to Buy XMN

Welcome to HTX.com! We've made purchasing xMoney (XMN) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy xMoney (XMN) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your xMoney (XMN)After purchasing your xMoney (XMN), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade xMoney (XMN)Easily trade xMoney (XMN) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

719 Total ViewsPublished 2026.02.25Updated 2026.02.25

How to Buy XMN

What is WARD

I. Project IntroductionWarden Protocol is a full-stack purpose-built L1 blockchain designed for developers to build Intelligent Applications. Warden creates a verifiable, AI-native blockchain where models are accessible to anyone and anywhere, their outputs directly powering smart applications.II. Token Information1) Basic InformationToken name: WARD(Warden Protocol)III. Related LinksWebsite:https://wardenprotocol.org/Explorers:https://bscscan.com/token/0x6dc200b21894af4660b549b678ea8df22bf7cfacSocials:https://x.com/wardenprotocolNote: The project introduction comes from the materials published or provided by the official project team, which is for reference only and does not constitute investment advice. HTX does not take responsibility for any resulting direct or indirect losses.

886 Total ViewsPublished 2026.02.25Updated 2026.02.25

What is WARD

How to Buy WARD

Welcome to HTX.com! We've made purchasing Warden Protocol (WARD) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy Warden Protocol (WARD) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your Warden Protocol (WARD)After purchasing your Warden Protocol (WARD), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade Warden Protocol (WARD)Easily trade Warden Protocol (WARD) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

835 Total ViewsPublished 2026.02.25Updated 2026.02.25

How to Buy WARD

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of A (A) are presented below.

活动图片