North Korea stole a record $2 billion in crypto in 2025 — even as hacks declined

ambcryptoPublicado em 2025-12-18Última atualização em 2025-12-18

Resumo

North Korea set a record in 2025 by stealing $2.02 billion in cryptocurrency despite carrying out fewer attacks than in previous years, according to Chainalysis. The DPRK shifted its strategy from high-frequency exploits to targeted, high-value infiltrations, focusing on compromising people and internal systems—such as executives and contractors—rather than just code. A major driver was the $1.5 billion Bybit breach. The report also details North Korea's efficient 45-day laundering cycle using mixers, bridges, and off-ramping via Chinese OTC brokers. While DeFi protocols saw improved security breaches, retail wallet hacks rose to 158,000 incidents. North Korea remains the most significant state-level threat in crypto, with total lifetime thefts reaching $6.75 billion. The industry must now prioritize human and organizational security, not just technical defenses.

North Korea set a new record for crypto theft in 2025, stealing $2.02 billion despite carrying out far fewer attacks than in previous years, according to new data from Chainalysis.

The report indicates that the DPRK’s cyber strategy has shifted from high-frequency exploits to precision, high-value infiltrations—a change that signals an evolving threat to the global crypto ecosystem.

Fewer attacks, but bigger and more strategic heists

Chainalysis found that North Korea-linked groups now focus on deep, targeted intrusions rather than the broad exploit patterns seen in earlier cycles.

DPRK hackers stole more money in 2025 than in any year on record, while the total number of incidents actually fell.

A major driver was the $1.5 billion Bybit breach, but the trend extends beyond any single event.

The report highlights a shift toward infiltrating people and internal systems, not just codebases — including impersonating executives, compromising contractors, and gaining upstream access to drain funds.

This shift marks a new phase of state-level crypto exploitation: fewer hacks, larger payoffs, and far more strategic targeting.

DPRK relies on fast-moving laundering networks

The report also outlines how North Korea has refined its laundering operations.

Chainalysis identified a repeatable 45-day cycle used to clean stolen funds, involving:

  • rapid obfuscation through mixers,
  • chain-hops through bridges, and
  • eventual off-ramping via Chinese-language OTC brokers and instant exchangers.

Use of these off-ramp channels by DPRK-linked groups has surged between 97% and 1,000%, depending on the network.

Retail users face a different threat: mass wallet drains

While institutional targets faced the largest losses, retail users experienced a rising wave of account takeover attacks.

Chainalysis recorded 158,000 personal wallet hacks in 2025 — three times higher than in 2022.

Total value stolen from wallets dropped to $713 million, but Solana users took the largest hit, reflecting persistent exposure at the individual level even as DeFi platforms improve their security posture.

DeFi is more secure — but institutions are now the weak point

The report notes that despite the rise in total value locked across DeFi, successful protocol-level exploits remained surprisingly low.

Instead, attackers targeted the organizational layers surrounding these platforms:

  • IT contractors
  • executives
  • customer support personnel
  • internal system administrators
  • The attacks became about people, not smart contracts.

This evolution suggests traditional security models — which focus on code audits and protocol hardening — no longer address the most exploited vulnerabilities.

A new phase of global crypto security risk

Chainalysis warns that DPRK’s cyber operations have reached a level of sophistication that demands a new security approach.

With lifetime crypto thefts now at $6.75 billion, North Korea remains the single most dangerous state actor in the industry.


Final Thoughts

  • North Korea’s shift to high-impact, institution-level infiltrations marks a new era of crypto security risk.
  • The industry must harden its human and organizational defences, not just its smart contracts.

Perguntas relacionadas

QHow much did North Korea steal in cryptocurrency in 2025 according to Chainalysis?

ANorth Korea stole a record $2.02 billion in cryptocurrency in 2025.

QWhat major shift in cyber strategy did the report identify for DPRK-linked hacking groups?

AThe report identified a shift from high-frequency exploits to precision, high-value infiltrations, focusing on targeted intrusions rather than broad exploit patterns.

QWhat was a key component of North Korea's 45-day laundering cycle for stolen funds?

AKey components included rapid obfuscation through mixers, chain-hops through bridges, and off-ramping via Chinese-language OTC brokers and instant exchangers.

QHow did the number of personal wallet hacks in 2025 compare to 2022?

AChainalysis recorded 158,000 personal wallet hacks in 2025, which was three times higher than the number in 2022.

QWhat does the report suggest is now the weak point in crypto security, as opposed to protocol-level exploits?

AThe report suggests that organizational layers, such as IT contractors, executives, and internal system administrators, are now the weak point, as attackers are targeting people rather than smart contracts.

Leituras Relacionadas

A Clod of Chinese Soil Chokes Two Japanese Giants

"Chinese Soil Chokes Japanese Giants" The production of a key electronic specialty gas, tungsten hexafluoride (WF6), vital for manufacturing AI chips, was halted by two leading Japanese producers—Kanto Denka and Central Glass. Their shutdown was not due to a technological failure but a sudden, critical shortage of a raw material they had long taken for granted: ultra-high-purity (6N-grade) tungsten powder, which is almost entirely sourced from China. Following a quiet Chinese export announcement in January 2026, tungsten powder shipments to Japan dropped to zero for months. Despite frantic efforts, Japanese companies found no viable alternative; imported powder was three times more expensive and lacked the required purity. Their existing stockpiles were exhausted by mid-2026. WF6 is essential for depositing tungsten into the microscopic contact holes of High Bandwidth Memory (HBM) chips, which are crucial for advanced processors like those from Nvidia. While Japanese firms had mastered producing ultra-pure WF6 gas, their entire supply chain relied on China's 6N tungsten powder—a dependency now revealed as a fatal vulnerability. China's dominance in this "soil" results from decades of painstaking R&D by companies like Xiamen Tungsten and China Tungsten & Hightech. They overcame immense technical hurdles, such as separating chemically similar molybdenum from tungsten, to achieve mass production of the world's purest tungsten powder. With their primary suppliers gone, Kanto Denka and Central Glass announced a permanent halt to WF6 production starting July 1, 2026. This immediately created a supply crisis for major semiconductor manufacturers like Samsung and SK Hynix, forcing them to urgently seek and certify new Chinese suppliers for WF6 itself. The reversal marks a dramatic shift: China has moved from exporting low-value raw materials to controlling the high-purity foundation of a critical global tech supply chain, upending a long-established industrial hierarchy.

marsbitHá 9m

A Clod of Chinese Soil Chokes Two Japanese Giants

marsbitHá 9m

Without Tencent, What's Left for Suiyuan?

The article centers on the crucial question posed in the title: what is Seyond Technology really worth if its dominant customer, Tencent, were to stop purchasing its AI chips? As the last of China's "Four AI Chip Dragons" to secure approval for a public listing, Seyond's IPO filing reveals a profound and controversial dependency. In 2025, 74.9% to over 80% of its revenue came from Tencent. The piece argues that this extreme customer concentration is not merely a vulnerability but a strategic outcome of China's AI industry evolution. It contrasts Seyond's path with its peers (Moore Thread, Biren Technology, and MetaX), noting that while others raced to market with ambitious stories, Seyond focused first on securing and delivering for a major client. Its explosive revenue growth—with Q1 2026 up 1474.85% year-on-year—is driven by concentrated orders from Tencent, which itself faces massive, escalating AI compute demands for products like its Yuanbao and Hunyuan models. The relationship is framed as a deliberate, symbiotic cultivation of a supply chain. As both a major shareholder (20.26%) and primary client, Tencent is actively fostering Seyond to build a controllable, stable alternative to NVIDIA, similar to how global tech giants historically nurtured key suppliers. The high switching costs—involving software stacks and deployed systems—create a deep "ecological moat" for Seyond within Tencent's ecosystem. The analysis positions the AI chip landscape in three tiers: NVIDIA as the global leader, Huawei's Ascend as the state-backed player, and commercial firms like Seyond competing for market orders. Seyond is increasingly seen as "Tencent's compute foundation," with its product roadmap closely aligned with the tech giant's needs. The conclusion is that the industry's metric for success is shifting from fundraising and technical specs to real orders, delivery capability, and ecosystem binding. Seyond's value, therefore, lies not just in its chips but in holding a massive, multi-year procurement order from China's largest internet company—a tangible asset arguably more telling than any technical whitepaper in the current climate. The core insight is that for domestic chips, the ultimate challenge isn't just catching up technologically with NVIDIA, but earning the trust, scenarios, and recurring orders from a major anchor client.

marsbitHá 1h

Without Tencent, What's Left for Suiyuan?

marsbitHá 1h

War Trade Unwinding | TradeXYZ Weekend Observations

Weekend markets saw a clear return of risk appetite. Major indices rose broadly, with significant gains in tech and precious metals, while energy sectors fell sharply on the "end of war" narrative. On June 14, oil prices initially rose on reports Iran had not yet finalized a memorandum of understanding. Later, YNET reported Trump might immediately lift the maritime blockade on Iran and the Strait of Hormuz. At 21:30, Trump confirmed on Truth Terminal that a deal with Iran was done, authorizing an immediate end to the US blockade and toll-free opening of the Strait. Iran's deputy foreign minister simultaneously announced an immediate and permanent halt to military actions on multiple fronts. Oil prices had already fallen to weekend boundaries, pre-pricing the news. The S&P 500 subsequently touched 7530. Markets will likely remain in a waiting period until the formal peace deal signing on June 19. At the moment of the deal announcement, gold jumped from ~4,221 to a high of 4,337, and silver from ~67.85 to 70.83, before stabilizing at higher levels. Individual stocks and ETFs like NBIS, RKLB, and LITE performed strongly. NBIS, added to the Nasdaq index, saw a target price increase due to strong AI cloud growth. RKLB, also added to the index, benefited from positive SpaceX valuation sentiment. LITE received a $1,130 target from JPMorgan. SPCX rose quickly after Musk tweeted SpaceX could potentially reach ~$1 trillion in revenue by 2030. In summary, the market shock from the multi-month war is beginning to dissipate. Israel's actions remain the key variable before the June 19 signing. Upcoming events like Fed Chair Warsh's debut and BoJ rate hike expectations will also significantly impact markets this week.

marsbitHá 1h

War Trade Unwinding | TradeXYZ Weekend Observations

marsbitHá 1h

Trading

Spot
Futuros

Artigos em Destaque

O que é ATWO

I. Introdução ao ProjetoArena Two é uma plataforma interativa descentralizada que permite aos fãs desempenhar um papel ativo e tokenizado nos resultados de eventos em tempo real. Ao contrário dos modelos tradicionais de transmissão que reduzem os fãs a espectadores passivos, a Arena Two utiliza a tecnologia blockchain para permitir que os fãs votem diretamente em tempo real e influenciem os resultados em campo.II. Informação sobre o TokenNome do token: ATWO(Arena Two)III. Links RelacionadosWebsite:https://arenatwo.com/Exploradores:https://basescan.org/token/0x499D35eBE6cEe9B2Ac35Fd003fcBbeeB9CFc7B32Twitter:https://x.com/arenatwoXNota: A introdução ao projeto provém dos materiais publicados ou fornecidos pela equipa oficial do projeto, que é apenas para referência e não constitui aconselhamento de investimento. A HTX não se responsabiliza por quaisquer perdas diretas ou indiretas resultantes.

258 Visualizações TotaisPublicado em {updateTime}Atualizado em 2026.06.02

O que é ATWO

Como comprar ATWO

Bem-vindo à HTX.com!Tornámos a compra de Arena Two (ATWO) simples e conveniente.Segue o nosso guia passo a passo para iniciar a tua jornada no mundo das criptos.Passo 1: cria a tua conta HTXUtiliza o teu e-mail ou número de telefone para te inscreveres numa conta gratuita na HTX.Desfruta de um processo de inscrição sem complicações e desbloqueia todas as funcionalidades.Obter a minha contaPasso 2: vai para Comprar Cripto e escolhe o teu método de pagamentoCartão de crédito/débito: usa o teu visa ou mastercard para comprar Arena Two (ATWO) instantaneamente.Saldo: usa os fundos da tua conta HTX para transacionar sem problemas.Terceiros: adicionamos métodos de pagamento populares, como Google Pay e Apple Pay, para aumentar a conveniência.P2P: transaciona diretamente com outros utilizadores na HTX.Mercado de balcão (OTC): oferecemos serviços personalizados e taxas de câmbio competitivas para os traders.Passo 3: armazena teu Arena Two (ATWO)Depois de comprar o teu Arena Two (ATWO), armazena-o na tua conta HTX.Alternativamente, podes enviá-lo para outro lugar através de transferência blockchain ou usá-lo para transacionar outras criptomoedas.Passo 4: transaciona Arena Two (ATWO)Transaciona facilmente Arena Two (ATWO) no mercado à vista da HTX.Acede simplesmente à tua conta, seleciona o teu par de trading, executa as tuas transações e monitoriza em tempo real.Oferecemos uma experiência de fácil utilização tanto para principiantes como para traders experientes.

141 Visualizações TotaisPublicado em {updateTime}Atualizado em 2026.06.02

Como comprar ATWO

O que é ZEST

I. Introdução ao Projeto1. O que é o Zest Protocol?O Zest Protocol é um protocolo de empréstimos nativo do Bitcoin construído na camada 2 do Stacks que permite aos utilizadores ganhar rendimento com BTC ou emprestar ativos colateralizando BTC. Os contratos inteligentes do protocolo são escritos na linguagem Clarity, operam totalmente em cadeia e são de código aberto, com um design inspirado no Aave v3. O Zest é atualmente o maior protocolo DeFi no Stacks, com mais de 800 BTC depositados e um pico de TVL superior a 100 milhões de dólares. Em maio de 2026, o protocolo introduziu ainda os Cofres de Colateral em Bitcoin, estendendo as capacidades de empréstimo do Stacks para a rede principal do Bitcoin. Isso permite que os utilizadores emprestem stablecoins sem mover BTC da rede Bitcoin, possibilitando empréstimos com custódia própria.2. Como funciona o Zest Protocol?O Zest Protocol consiste em dois mercados. O mercado do Stacks é construído sobre o Aave v3, permitindo que os utilizadores depositem ativos como sBTC, STX e USDC para ganhar rendimento ou contrair empréstimos sobre-colateralizados. O LTV máximo padrão é de 50% (70% para sBTC). O mercado do Bitcoin opera através dos recém-lançados Cofres de Colateral em Bitcoin. Os utilizadores emprestam stablecoins ao bloquear BTC em cofres de custódia própria na cadeia do Bitcoin. O colateral permanece na rede principal do Bitcoin durante todo o processo, e os utilizadores mantêm a custódia, a menos que a posição seja liquidada.3. Quem fundou o Zest Protocol?Tycho Onnasch (Co-Fundador): Formado na Universidade de Oxford. Envolvido em pesquisa e subsídios para a Stacks Open Internet Foundation. Antigo Gestor na Trust Machines e Fundador da Deedmob. Perfil do LinkedIn: https://www.linkedin.com/in/tychokoonnasch/.Fernando Foy (Co-Fundador): Trabalhou anteriormente em consultoria de TI na Objectif Emploi. Perfil do LinkedIn: https://www.linkedin.com/in/fernando-foy/.Emil E. (Co-Fundador): Possui um Mestrado em Física pela Universidade de Warwick. Antigo Partner de Engenharia na Trust Machines, Desenvolvedor Full-Stack para projetos Web3 e Cientista de Dados no HSBC. Perfil do LinkedIn: https://www.linkedin.com/in/emil-e-49771a145/.Detalhes de Financiamento: Em maio de 2024, o Zest Protocol anunciou a conclusão de uma ronda de financiamento inicial de 3,5 milhões de dólares liderada por Tim Draper, com a participação da Binance Labs, Flow Traders, Trust Machines, entre outros.4. Tokenomics do $ZEST$ZEST é o token nativo do Zest Protocol com um fornecimento total fixo de 1 mil milhões de tokens e sem mecanismo inflacionário.Comunidade (27,83%): Usado para airdrops e incentivos aos utilizadores;Desenvolvimento do Ecossistema (24,82%): Usado para liquidez, parcerias, marketing, listagens em bolsas, etc.;Investidores (22,35%): Apoio às partes investidoras que apoiaram o desenvolvimento inicial do Zest Protocol;Equipa (25%): Alocado para colaboradores principais.Calendário de Vesting: Os tokens da Equipa e dos Investidores estão sujeitos a um período de bloqueio de 1 ano, seguido de 3 anos de desbloqueio linear.5. Cronologia dos Principais Marcos2022: O Zest Protocol é oficialmente fundado.Março de 2024: Concluída a auditoria de segurança e lançado o mercado de empréstimos do Stacks na rede principal.Em fevereiro de 2026, é lançado o Stacks Market V2, introduzindo Grupos de Risco.Em maio de 2026, foram introduzidos os Cofres de Colateral em Bitcoin, e um protótipo operacional da rede principal está agora disponível. Isso permite que os utilizadores utilizem BTC com custódia própria na L1 do Bitcoin como colateral para emprestar stablecoins em cadeias EVM, encerrando a necessidade de bridging, wrapping e custódia de terceiros. Este lançamento é dividido em duas fases. Fase 1: Utiliza transações pré-assinadas para restringir o movimento de BTC; Fase 2: Utiliza BitVM para verificação. II. Informações sobre o TokenNome do token: ZEST (Zest Protocol)III. Links RelacionadosWebsite: https://www.zestprotocol.com/Exploradores: https://bscscan.com/token/0x5506599c722389a60580b5213ea1da60d64754a1Twitter: https://twitter.com/ZestProtocolNota: A introdução ao projeto provém dos materiais publicados ou fornecidos pela equipa oficial do projeto, que é apenas para referência e não constitui aconselhamento de investimento. A HTX não se responsabiliza por quaisquer perdas diretas ou indiretas resultantes.

203 Visualizações TotaisPublicado em {updateTime}Atualizado em 2026.06.02

O que é ZEST

Discussões

Bem-vindo à Comunidade HTX. Aqui, pode manter-se informado sobre os mais recentes desenvolvimentos da plataforma e obter acesso a análises profissionais de mercado. As opiniões dos utilizadores sobre o preço de A (A) são apresentadas abaixo.

活动图片