Finance Share Share this article Copy linkX (Twitter)LinkedInFacebookEmail North Korean hackers stole a record $2 billi Finance Share Share this article Copy linkX (Twitter)LinkedInFacebookEmail North Korean hackers stole a record $2 billi

North Korean hackers stole a record $2 billion of crypto in 2025, Chainalysis says

2025/12/18 21:00
6 min read
Share
Share this article
Copy linkX (Twitter)LinkedInFacebookEmail

North Korean hackers stole a record $2 billion of crypto in 2025, Chainalysis says

North Korea-linked hackers drove a record year for crypto thefts, favoring rare but massive attacks on centralized services, led by Bybit’s $1.4 billion breach.

By Oliver Knight|Edited by Sheldon Reback
Dec 18, 2025, 1:00 p.m.
North Korea hackers stole $2 billion in 2025 (Micha Brändli, Unsplash modified by CoinDesk)

What to know:

  • North Korean hackers stole at least $2 billion in 2025, up 51% from the year before, pushing their all-time haul to $6.75 billion.
  • The hackers were behind 76% of service-level hacks, reflecting a shift toward fewer, larger breaches.
  • Laundering patterns show heavy use of Chinese-language brokers, bridges and mixers, with a typical 45-day cash-out window.

North Korean hackers stole at least $2 billion in cryptocurrency this year, the most on record, pushing the Democratic People’s Republic of Korea's (DPRK) all-time haul to $6.75 billion, according to a new Chainalysis report.

The figure represents a 51% increase over 2024 from fewer confirmed incidents. The numbers underscore a shift toward fewer, dramatically larger attacks, underpinned by March's $1.4 billion hack of Bybit.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters
Sign me up

In contrast to other cybercriminals, North Korean groups overwhelmingly target large, centralized crypto services, aiming for maximum impact rather than frequency, the report said. DPRK-linked actors were responsible for 76% of all service-level compromises in 2025, the most ever recorded.

How they launder the cash also stands out. While other hackers tend to distribute stolen funds in large onchain transfers, DPRK actors consistently work with smaller tranches below $500,000, a sign of increasingly sophisticated operational security.

DPRK-linked wallets show a heavy reliance on Chinese-language guarantee services, brokers and over-the-counter networks, as well as extensive use of bridges and mixing services. They largely avoid the DeFi lending protocols, decentralized exchanges and peer-to-peer platforms favored by other criminals. These patterns suggest structural constraints and a dependence on specific regional facilitators rather than broad access to global financial infrastructure.

Earlier this year, CoinDesk reported on how North Korea is now using AI as a "superpower" in its hacking efforts.

"North Korea facilitates the laundering of their crypto heists with consistency and fluidity indicative of the use of AI," Andrew Fierman, head of national security intelligence at Chainalysis told CoinDesk.

"The mechanism by which the laundering is structured, and the scale at which it is done, creates a workflow that combines mixers, DeFi protocols, and bridges early on in the laundering process to convert funds across various crypto assets," he said. "To execute this type of efficacy in stealing such large volumes of crypto, North Korea needs a large laundering network, along with streamlined mechanisms to facilitate that laundering, which likely comes in the form of the use of AI."

Analysis of post-hack activity reveals that major North Korean thefts typically unfold over a roughly 45-day laundering window, moving through distinct phases from immediate obfuscation to final integration, Chainalysis said. While not universal, the consistency of this timeline across multiple years provides valuable intelligence for law enforcement and compliance teams seeking to intercept stolen funds before they are fully cashed out.

At the same time, the broader theft landscape is shifting. Personal wallet compromises accounted for 20% of total value stolen in 2025, dropping from 44% last year. While the number of incidents surged to 158,000, the dollar value taken from individual victims fell 52% to $713 million. The data suggest attackers are targeting more users but stealing less from each.

As the year winds to a close, North Korea's crypto hacking efforts show no sign of curtailing, the report's findings point to an increasingly polarized threat environment: mass, low-value thefts from individuals on one end, and rare but catastrophic service-level breaches on the other, with North Korea firmly at the center of the latter.

North KoreaChainalysisHackCrime

More For You

Protocol Research: GoPlus Security

Commissioned byGoPlus

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.
View Full Report

More For You

SoFi unveils the first bank-issued stablecoin for enterprise payments

SoFi Bank becomes the first U.S. national bank to launch a stablecoin, positioning SoFiUSD as a faster, safer alternative to crypto-native tokens.

What to know:

  • SoFi has launched SoFiUSD, a U.S. dollar stablecoin backed 1:1 by cash held at the Federal Reserve and issued by its FDIC-insured national bank.
  • The coin runs on a public blockchain, offering instant, low-cost settlement and opening the door to white-labeled stablecoin services for fintechs, banks and enterprises.
  • Initially limited to internal use, SoFiUSD is expected to roll out to SoFi members in the coming months as part of a broader payments strategy.
Read full story
Latest Crypto News

U.S. inflation data surprises, with CPI higher by just 2.7% in November

SoFi unveils the first bank-issued stablecoin for enterprise payments

Dogecoin and Shiba Inu lag market as memecoins continue to lose ground to bitcoin

Hut 8 price target boosted at Cantor and Canaccord after Google-backed AI deal

BNB holds onto fourth-largest crypto spot even as price falls, selling pressure builds

Uniswap vote could soon tie UNI token value to its multibillion-dollar trading engine

Top Stories

U.S. inflation data surprises, with CPI higher by just 2.7% in November

Crypto Market Today: Bitcoin-gold ratio drops to lowest since January 2024

Micron crushes earnings, calming markets and helping boost bitcoin back above $87,000

Hut 8 price target boosted at Cantor and Canaccord after Google-backed AI deal

JPMorgan’s tokenized dollars are quietly rewiring how Wall Street moves money

World Liberty Financial proposes using treasury funds to boost USD1 stablecoin growth

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Big News: First U.S. Spot XRP and DOGE ETF by Rex-Osprey Officially Launches: Details

Big News: First U.S. Spot XRP and DOGE ETF by Rex-Osprey Officially Launches: Details

In a landmark development for digital asset investors, REX-Osprey, a collaboration between REX Shares and Osprey Funds, has rolled out the first-ever U.S.-listed exchange-traded funds (ETFs) offering direct spot exposure to Dogecoin (DOGE) and XRP. According to a press release on Businessnewswire, the new products, trading under tickers DOJE and XRPR on the Cboe exchange, mark a significant step in bringing two of the most recognized cryptocurrencies into regulated investment vehicles. Dogecoin Gets Its First ETF The launch of DOJE represents a historic milestone as the first Dogecoin spot ETF in the United States. Once regarded as a meme coin driven by online culture and celebrity endorsements, Dogecoin has since grown into one of the top cryptocurrencies by market capitalization, supported by a highly active global community. Also Read: Massive Breakout Imminent? ‘XRP is Now Where ETH Was in 2017 Right Before Explosion’ By structuring DOGE under the 1940 Act fund framework, REX-Osprey is making the asset more accessible to traditional investors who prefer trading through established brokerage accounts rather than crypto exchanges. Analysts note that this could broaden institutional interest in DOGE, especially as regulatory-compliant exposure options expand. XRP ETF Brings Utility-Focused Crypto Into Spotlight Alongside DOJE, the XRPR ETF provides exposure to XRP, the digital asset powering Ripple’s payments network. XRP has long been associated with fast, low-cost cross-border transactions, a use case that has attracted growing attention from both banks and payment providers. The XRPR fund will hold most of its assets directly in spot XRP, with the remainder invested in XRP-backed exchange-traded products. This hybrid structure aims to provide investors with a liquid and straightforward way to gain exposure to an asset that continues to be at the center of conversations about the future of international payments. Expanding a Growing ETF Lineup The new DOGE and XRP ETFs follow the July debut of the REX-Osprey SOL + Staking ETF (SSK), which became the first U.S.-listed ETF to combine spot Solana exposure with on-chain staking rewards. That fund has already surpassed $275 million in assets under management and recently converted to a Regulated Investment Company (RIC) structure, boosting tax efficiency for investors while keeping its staking benefits intact. According to Greg King, CEO of REX Financial and Osprey Funds, the launch of DOJE and XRPR underscores the firm’s ambition to pioneer regulated investment pathways for digital assets. “ETFs have always been about access,” King said in a statement. “The digital asset revolution is accelerating, and to deliver exposure to leading tokens like Dogecoin and XRP within the protection of the U.S. ETF framework is something we are proud to bring to the market.” What This Means for Crypto Adoption Market watchers suggest that the arrival of DOGE and XRP ETFs could broaden crypto exposure in retirement portfolios, wealth management products, and institutional trading desks. For Dogecoin, this marks a shift from meme-driven volatility to potentially more structured investment flows. For XRP, the ETF comes at a time when analysts, including those at Morgan Stanley, have speculated on its potential to capture a share of the $150 trillion cross-border payments market currently dominated by SWIFT. With these launches, REX-Osprey continues to carve out a niche as one of the leading firms bridging crypto-native assets with the regulated ETF space, setting the stage for broader institutional adoption in the coming years. Also Read: Egrag Crypto: XRP Could be Around $6 or $7 by Mid-November Based on this Analysis The post Big News: First U.S. Spot XRP and DOGE ETF by Rex-Osprey Officially Launches: Details appeared first on 36Crypto.
Share
Coinstats2025/09/18 21:40
‘Failed Experiment’: Are Bitcoin Treasury Companies Dumping BTC? Bitdeer Holdings Hit Zero

‘Failed Experiment’: Are Bitcoin Treasury Companies Dumping BTC? Bitdeer Holdings Hit Zero

The post ‘Failed Experiment’: Are Bitcoin Treasury Companies Dumping BTC? Bitdeer Holdings Hit Zero appeared first on Coinpedia Fintech News SwanDesk CEO Jacob
Share
CoinPedia2026/02/23 20:45
‘Not ours’: Rizal gov’t washes hands of Rodriguez landfill incident

‘Not ours’: Rizal gov’t washes hands of Rodriguez landfill incident

Rodriguez Mayor Ronnie Evangelista says the town has 'limited scope of authority' over the landfill
Share
Rappler2026/02/23 20:12