TRM has published new research showing that North Korea-linked actors were responsible for more than half of the US$2.7 billion stolen in cryptocurrency hacks inTRM has published new research showing that North Korea-linked actors were responsible for more than half of the US$2.7 billion stolen in cryptocurrency hacks in

North Korea Linked to Over Half of 2025 Crypto Heist Losses

2025/12/19 13:07

TRM has published new research showing that North Korea-linked actors were responsible for more than half of the US$2.7 billion stolen in cryptocurrency hacks in 2025, marking the regime as the single most dominant and sophisticated threat actor in the crypto theft ecosystem.

For years, North Korea has used crypto theft to fund weapons proliferation, evade sanctions, and pursue destabilising activities.

Notably, high-value heists in 2023–2025 have shifted from exploiting smart-contract flaws to targeting the operational infrastructure of exchanges and custodial services. Single points of failure in these systems allow access to large sums.

Source: TRMSource: TRM

TRM attributes several major incidents to the regime, including Atomic Wallet, CoinsPaid, Alphapo, Stake.com, CoinEx, and the February 2025 Bybit exploit.

North Korean operators typically gain entry through social engineering.

They use fake job offers or investment pitches to compromise developer systems and extract wallet keys.

Once assets are stolen, they are laundered through a complex network known as the “Chinese Laundromat.”

This network comprises brokers, money transmitters, and trade-based intermediaries.

TRM notes that this process now occurs end-to-end with Chinese actors.

Funds move across chains, exchanges, and jurisdictions, often converting into stablecoins such as USDT on Tron before settlement in yuan, goods, or payments to North Korean front companies.

Source: TRMSource: TRM

Therefore, for exchanges and financial institutions, this evolution collapses traditional silos between cybersecurity and AML.

Static blocklists are insufficient; effective detection requires monitoring cross-chain flows and nested service counterparts, while pairing hardware-secured key storage with tiered withdrawal policies and privileged-access segmentation.

Overall, North Korea’s operations reflect the industrialisation of crypto theft.

They blend cyber activity, intelligence support, and outsourced laundering to create a state-directed revenue system.

As stablecoins and crypto payments grow, tracing stolen assets becomes increasingly complex.

This highlights the need for coordinated, cross-border measures to counter these structured, high-volume operations.

Featured image credit: Edited by Fintech News Hong Kong, based on image by aukid via Freepik

The post North Korea Linked to Over Half of 2025 Crypto Heist Losses appeared first on Fintech Hong Kong.

시장 기회
Moonveil 로고
Moonveil 가격(MORE)
$0.00246
$0.00246$0.00246
-16.06%
USD
Moonveil (MORE) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, service@support.mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.