North Korean Hackers Make History with $2 Billion Crypto Heist in 2025
## Cybersecurity: Cryptocurrency Thefts by North Korean Hackers
Cybersecurity: Cryptocurrency Thefts by North Korean Hackers
In 2025, North Korean hackers executed a significant cryptocurrency heist, stealing $2.02 billion. This marks a 51% increase from 2024, with total theft reaching $6.75 billion since 2016.
These state-sponsored groups are achieving larger payouts despite fewer attacks, signifying a shift toward more sophisticated operations. North Korean activities accounted for 76% of all service compromises in the cryptocurrency sector, which experienced over $3.4 billion in total theft in 2025.
Embedding IT workers within crypto exchanges, custodians, and web3 companies for trusted access. Using fake recruiter schemes to impersonate representatives of major web3 and AI firms, deceiving employees during job interviews and technical screenings.
Attackers have reversed their traditional approach by impersonating recruiters to steal credentials, source code, and VPN access. At a strategic level, they pose as investors or acquirers to gather sensitive information through pitch meetings and due diligence processes.
In 2025, North Korean hackers executed a significant cryptocurrency heist, stealing $2.02 billion.
A notable incident includes the February 2025 attack on the Bybit exchange, resulting in a $1.5 billion theft, highlighting the shift from numerous small attacks to fewer but larger-scale operations.
North Korean hackers utilize a structured 45-day laundering cycle, which occurs in three phases:
Initial five days: Rapid movement of stolen funds through DeFi protocols (370% activity spike) and mixing services (135% increase). Days six to ten: Transition using exchanges with limited identity checks and cross-chain bridges. Centralized exchanges see a 32% increase in fund reception. Days 20 to 45: Conversion of cryptocurrency to cash via no-KYC exchanges (82% increase) and Chinese-language services like Tudou Danbao (87% increase).
Chainalysis researchers observed a strong preference for Chinese-language money laundering services, with usage rates significantly higher than those of other cybercriminals. Transactions are structured to avoid detection, with 60% under $500,000.
This pattern indicates operational constraints and a reliance on Asia-Pacific criminal networks, providing law enforcement and security teams with opportunities to track and intercept stolen funds.
Based on reporting by Cyber Security News.
