The post North Korean hackers shatter records, steal $2.02 billion in crypto in 2025 appeared on BitcoinEthereumNews.com. North Korean hackers, the cyber attackersThe post North Korean hackers shatter records, steal $2.02 billion in crypto in 2025 appeared on BitcoinEthereumNews.com. North Korean hackers, the cyber attackers

North Korean hackers shatter records, steal $2.02 billion in crypto in 2025

North Korean hackers, the cyber attackers sponsored by the rogue regime, have swiped over $2.02 billion in crypto since January. This has pushed the Democratic People’s Republic of Korea’s (DPRK) all-time haul to over $6 billion.

DPRK hack volumes from 2016-2025. Source: Chainanalysis

According to the Chainalysis report, hackers stole $681 million more in 2024, representing a 51% year-over-year increase. This brought the total identified haul from crypto theft since 2016 to $6.75 billion. 

North Korea hackers shift their strategy to fewer but larger attacks

The report revealed that the hackers have changed their strategy to fewer but dramatically larger attacks, underpinned by March’s $1.4 billion hack of Bybit. They have achieved these results by embedding IT workers inside crypto services to gain privileged access and enable high‑impact compromises. 

North Korean groups mainly target large, centralized crypto services, aiming for maximum impact rather than frequency. DPRK-linked actors were responsible for 76% of all service-level compromises in 2025, the most ever recorded.

DPRK actors have demonstrated consistency in working with smaller tranches below $500,000, rather than distributing stolen funds in large on-chain transfers in the $1M to $10M+ range, unlike other hackers. This is a sign of increasingly sophisticated operational security.

Analysis of post-hack activity reveals a consistent pattern in how these events are associated with the movement of stolen funds throughout the crypto ecosystem. Following major theft events between 2022 and 2025, stolen funds follow a structured, multi-wave laundering pathway that unfolds over approximately 45 days. This is a widow that the law enforcers can use to intercept.

Additionally, DPRK-linked wallets rely heavily on Chinese-language guarantee services, brokers, and over-the-counter networks, and extensive use of bridges and mixing services. They largely avoid the DeFi lending protocols, decentralized exchanges, and peer-to-peer platforms favored by other criminals. 

This year, North Korea has used AI in its hacking efforts. They integrate large language models into nearly every stage of their attacks: reconnaissance, phishing, code analysis, and laundering the proceeds.

Personal wallet comprises a decline of over 50%

Overall, the cryptocurrency industry experienced over $3.4 billion in theft from January to early December 2025. Total theft incidents surged to 158,000 in 2025, nearly triple the 54,000 recorded in 2022. 

The number of new and unique victims increased from 40,000 in 2022 to at least 80,000 in 2025. This rise is likely due to greater crypto adoption. For instance, Solana, one of the blockchains with the greatest number of active personal wallets, was at the lead with 26,500 victims.

When measuring crime rates per 100K wallets in 2025, Ethereum and Tron show the highest rates of theft. Ethereum’s large size is reflected in both high rates of theft and a high victim count. On the other hand, although it has a smaller active wallet base, Tron’s position shows an elevated rate of theft.

Personal wallet theft volumes. Source: Chainalysis

Personal wallet compromises surged from just 7.3% of total stolen value in 2022 to 44% in 2024. In 2025, they now account for 20% of all value stolen. The total amount stolen from individual victims declined from 2024’s peak of $1.5 billion to $713 million in 2025. However, the share would have been 37% if it weren’t for the outsized impact of the Bybit attack.

Centralized services have experienced large losses due to private key compromises. These platforms remain vulnerable because of this security challenge. While such compromises are rare, their scale still drives a significant share of stolen volumes when they do occur. For instance, they accounted for 88% of losses in Q1 2025.

For the first time, the ratio between the largest hack and the middle of all cases has exceeded 1,000 times. The amount of money stolen in the biggest attacks is now 1,000 times more than in the average case. It’s even more than the bull market peak in 2021. The top three hacks in 2025 account for 69% of all service losses.

Get seen where it counts. Advertise in Cryptopolitan Research and reach crypto’s sharpest investors and builders.

Source: https://www.cryptopolitan.com/north-korean-hackers-steal-2-02-billion-2025/

Market Opportunity
CyberConnect Logo
CyberConnect Price(CYBER)
$0.5821
$0.5821$0.5821
+2.08%
USD
CyberConnect (CYBER) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

CME Group to Launch Solana and XRP Futures Options

CME Group to Launch Solana and XRP Futures Options

The post CME Group to Launch Solana and XRP Futures Options appeared on BitcoinEthereumNews.com. An announcement was made by CME Group, the largest derivatives exchanger worldwide, revealed that it would introduce options for Solana and XRP futures. It is the latest addition to CME crypto derivatives as institutions and retail investors increase their demand for Solana and XRP. CME Expands Crypto Offerings With Solana and XRP Options Launch According to a press release, the launch is scheduled for October 13, 2025, pending regulatory approval. The new products will allow traders to access options on Solana, Micro Solana, XRP, and Micro XRP futures. Expiries will be offered on business days on a monthly, and quarterly basis to provide more flexibility to market players. CME Group said the contracts are designed to meet demand from institutions, hedge funds, and active retail traders. According to Giovanni Vicioso, the launch reflects high liquidity in Solana and XRP futures. Vicioso is the Global Head of Cryptocurrency Products for the CME Group. He noted that the new contracts will provide additional tools for risk management and exposure strategies. Recently, CME XRP futures registered record open interest amid ETF approval optimism, reinforcing confidence in contract demand. Cumberland, one of the leading liquidity providers, welcomed the development and said it highlights the shift beyond Bitcoin and Ethereum. FalconX, another trading firm, added that rising digital asset treasuries are increasing the need for hedging tools on alternative tokens like Solana and XRP. High Record Trading Volumes Demand Solana and XRP Futures Solana futures and XRP continue to gain popularity since their launch earlier this year. According to CME official records, many have bought and sold more than 540,000 Solana futures contracts since March. A value that amounts to over $22 billion dollars. Solana contracts hit a record 9,000 contracts in August, worth $437 million. Open interest also set a record at 12,500 contracts.…
Share
BitcoinEthereumNews2025/09/18 01:39
Metaplanet CEO Denies Hiding Details

Metaplanet CEO Denies Hiding Details

The post Metaplanet CEO Denies Hiding Details appeared on BitcoinEthereumNews.com. Storm Over Bitcoin Trades: Metaplanet CEO Denies Hiding Details
Share
BitcoinEthereumNews2026/02/21 21:03
Shadows in the Payment Rail: The Urbenics.com Mystery

Shadows in the Payment Rail: The Urbenics.com Mystery

A new, anonymous player has emerged in the high-risk payment sector. Operating without a public face, Urbenics.com is quietly fueling the offshore casino industry
Share
Fintelegram2026/02/21 20:44