North Korean hackers, the cyber attackers sponsored by the rogue regime, have swiped over $2.02 billion in crypto since January. This has pushed the Democratic North Korean hackers, the cyber attackers sponsored by the rogue regime, have swiped over $2.02 billion in crypto since January. This has pushed the Democratic

North Korean hackers steal over $2 billion in crypto this year, pushing total haul past $6 billion

North Korean hackers, the cyber attackers sponsored by the rogue regime, have swiped over $2.02 billion in crypto since January. This has pushed the Democratic People’s Republic of Korea’s (DPRK) all-time haul to over $6 billion.

DPRK hack volumes from 2016-2025. Source: Chainanalysis

According to the Chainalysis report, hackers stole $681 million more in 2024, representing a 51% year-over-year increase. This brought the total identified haul from crypto theft since 2016 to $6.75 billion. 

North Korea hackers shift their strategy to fewer but larger attacks

The report revealed that the hackers have changed their strategy to fewer but dramatically larger attacks, underpinned by March’s $1.4 billion hack of Bybit. They have achieved these results by embedding IT workers inside crypto services to gain privileged access and enable high‑impact compromises. 

North Korean groups mainly target large, centralized crypto services, aiming for maximum impact rather than frequency. DPRK-linked actors were responsible for 76% of all service-level compromises in 2025, the most ever recorded.

DPRK actors have demonstrated consistency in working with smaller tranches below $500,000, rather than distributing stolen funds in large on-chain transfers in the $1M to $10M+ range, unlike other hackers. This is a sign of increasingly sophisticated operational security.

Analysis of post-hack activity reveals a consistent pattern in how these events are associated with the movement of stolen funds throughout the crypto ecosystem. Following major theft events between 2022 and 2025, stolen funds follow a structured, multi-wave laundering pathway that unfolds over approximately 45 days. This is a widow that the law enforcers can use to intercept.

Additionally, DPRK-linked wallets rely heavily on Chinese-language guarantee services, brokers, and over-the-counter networks, and extensive use of bridges and mixing services. They largely avoid the DeFi lending protocols, decentralized exchanges, and peer-to-peer platforms favored by other criminals. 

This year, North Korea has used AI in its hacking efforts. They integrate large language models into nearly every stage of their attacks: reconnaissance, phishing, code analysis, and laundering the proceeds.

Personal wallet comprises a decline of over 50%

Overall, the cryptocurrency industry experienced over $3.4 billion in theft from January to early December 2025. Total theft incidents surged to 158,000 in 2025, nearly triple the 54,000 recorded in 2022. 

The number of new and unique victims increased from 40,000 in 2022 to at least 80,000 in 2025. This rise is likely due to greater crypto adoption. For instance, Solana, one of the blockchains with the greatest number of active personal wallets, was at the lead with 26,500 victims.

When measuring crime rates per 100K wallets in 2025, Ethereum and Tron show the highest rates of theft. Ethereum’s large size is reflected in both high rates of theft and a high victim count. On the other hand, although it has a smaller active wallet base, Tron’s position shows an elevated rate of theft.

Personal wallet theft volumes. Source: Chainalysis

Personal wallet compromises surged from just 7.3% of total stolen value in 2022 to 44% in 2024. In 2025, they now account for 20% of all value stolen. The total amount stolen from individual victims declined from 2024’s peak of $1.5 billion to $713 million in 2025. However, the share would have been 37% if it weren’t for the outsized impact of the Bybit attack.

Centralized services have experienced large losses due to private key compromises. These platforms remain vulnerable because of this security challenge. While such compromises are rare, their scale still drives a significant share of stolen volumes when they do occur. For instance, they accounted for 88% of losses in Q1 2025.

For the first time, the ratio between the largest hack and the middle of all cases has exceeded 1,000 times. The amount of money stolen in the biggest attacks is now 1,000 times more than in the average case. It’s even more than the bull market peak in 2021. The top three hacks in 2025 account for 69% of all service losses.

The smartest crypto minds already read our newsletter. Want in? Join them.

Market Opportunity
CyberConnect Logo
CyberConnect Price(CYBER)
$0,679
$0,679$0,679
+0,68%
USD
CyberConnect (CYBER) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Unexpected Developments Shake the Financial Sphere

Unexpected Developments Shake the Financial Sphere

The post Unexpected Developments Shake the Financial Sphere appeared on BitcoinEthereumNews.com. Japan’s recent move to hike its interest rate to 0.75 ahead of
Share
BitcoinEthereumNews2025/12/19 22:07
Foreigner’s Lou Gramm Revisits The Band’s Classic ‘4’ Album, Now Reissued

Foreigner’s Lou Gramm Revisits The Band’s Classic ‘4’ Album, Now Reissued

The post Foreigner’s Lou Gramm Revisits The Band’s Classic ‘4’ Album, Now Reissued appeared on BitcoinEthereumNews.com. American-based rock band Foreigner performs onstage at the Rosemont Horizon, Rosemont, Illinois, November 8, 1981. Pictured are, from left, Mick Jones, on guitar, and vocalist Lou Gramm. (Photo by Paul Natkin/Getty Images) Getty Images Singer Lou Gramm has a vivid memory of recording the ballad “Waiting for a Girl Like You” at New York City’s Electric Lady Studio for his band Foreigner more than 40 years ago. Gramm was adding his vocals for the track in the control room on the other side of the glass when he noticed a beautiful woman walking through the door. “She sits on the sofa in front of the board,” he says. “She looked at me while I was singing. And every now and then, she had a little smile on her face. I’m not sure what that was, but it was driving me crazy. “And at the end of the song, when I’m singing the ad-libs and stuff like that, she gets up,” he continues. “She gives me a little smile and walks out of the room. And when the song ended, I would look up every now and then to see where Mick [Jones] and Mutt [Lange] were, and they were pushing buttons and turning knobs. They were not aware that she was even in the room. So when the song ended, I said, ‘Guys, who was that woman who walked in? She was beautiful.’ And they looked at each other, and they went, ‘What are you talking about? We didn’t see anything.’ But you know what? I think they put her up to it. Doesn’t that sound more like them?” “Waiting for a Girl Like You” became a massive hit in 1981 for Foreigner off their album 4, which peaked at number one on the Billboard chart for 10 weeks and…
Share
BitcoinEthereumNews2025/09/18 01:26
Adoption Leads Traders to Snorter Token

Adoption Leads Traders to Snorter Token

The post Adoption Leads Traders to Snorter Token appeared on BitcoinEthereumNews.com. Largest Bank in Spain Launches Crypto Service: Adoption Leads Traders to Snorter Token Sign Up for Our Newsletter! For updates and exclusive offers enter your email. Leah is a British journalist with a BA in Journalism, Media, and Communications and nearly a decade of content writing experience. Over the last four years, her focus has primarily been on Web3 technologies, driven by her genuine enthusiasm for decentralization and the latest technological advancements. She has contributed to leading crypto and NFT publications – Cointelegraph, Coinbound, Crypto News, NFT Plazas, Bitcolumnist, Techreport, and NFT Lately – which has elevated her to a senior role in crypto journalism. Whether crafting breaking news or in-depth reviews, she strives to engage her readers with the latest insights and information. Her articles often span the hottest cryptos, exchanges, and evolving regulations. As part of her ploy to attract crypto newbies into Web3, she explains even the most complex topics in an easily understandable and engaging way. Further underscoring her dynamic journalism background, she has written for various sectors, including software testing (TEST Magazine), travel (Travel Off Path), and music (Mixmag). When she’s not deep into a crypto rabbit hole, she’s probably island-hopping (with the Galapagos and Hainan being her go-to’s). Or perhaps sketching chalk pencil drawings while listening to the Pixies, her all-time favorite band. This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy. I Agree Source: https://bitcoinist.com/banco-santander-and-snorter-token-crypto-services/
Share
BitcoinEthereumNews2025/09/17 23:45