CertiK, Chainalysis and Elliptic all say DPRK‑linked hackers stole about 60% of 2025’s $3.4B crypto theft, including an estimated $2.02B taken by North Korean groupsCertiK, Chainalysis and Elliptic all say DPRK‑linked hackers stole about 60% of 2025’s $3.4B crypto theft, including an estimated $2.02B taken by North Korean groups

North Korean hackers now dominate crypto theft — and compliance is racing to catch up

2026/05/12 22:01
4분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 [email protected]으로 연락주시기 바랍니다

CertiK, Chainalysis and Elliptic all say DPRK‑linked hackers stole about 60% of 2025’s $3.4B crypto theft, including an estimated $2.02B taken by North Korean groups.

Summary
  • A handful of mega‑hacks like Bybit’s record $1.46B–$1.5B breach drove 2025 losses, even as the total number of DPRK incidents fell compared with previous years.
  • Investigators warn stolen crypto likely funds North Korea’s nuclear and missile programs, spurring a compliance arms race in screening, freezing and tracing tainted assets.

Blockchain security firm CertiK says North Korean state-linked hacking groups were responsible for roughly 60% of all crypto stolen in 2025, cementing the DPRK as the single most dangerous actor in the space. That share lines up with independent estimates from Chainalysis and others, which found that North Korea stole about $2.02 billion in digital assets last year out of roughly $3.4 billion in total global crypto thefts.

Chainalysis’ 2026 Crypto Crime Report, cited by outlets such as Fortune and the Korea Herald, puts global 2025 crypto theft at around $3.4 billion, with North Korean operations accounting for “nearly 60%” of that figure. The firm estimates that DPRK-linked hackers stole at least $2.02 billion worth of crypto last year — a 51% increase from 2024 — pushing the regime’s all‑time haul to about $6.75 billion, even as the number of confirmed incidents fell. Elliptic’s separate analysis is broadly consistent, concluding that North Korea–linked groups had already stolen “over $2 billion” in 2025 by early October, before the final wave of attacks.

The scale is being driven by fewer but much larger heists. Elliptic and Chainalysis both highlight February’s Bybit hack — variously estimated at around $1.46 billion to $1.5 billion — as the single biggest crypto theft in history, and one that U.S. authorities quickly attributed to North Korean actors. Other 2025 attacks linked to DPRK groups include the compromises of LND.fi, WOO X and Seedify, along with dozens of smaller service breaches and wallet‑draining campaigns. In aggregate, researchers say North Korean hackers were responsible for somewhere between 60% and “more than half” of all crypto stolen from centralized services and DeFi protocols last year, depending on how the sample of tracked incidents is defined.

The operational pattern has shifted as well. Instead of relying primarily on “spray and pray” phishing or brute‑force smart‑contract exploits, DPRK actors increasingly embed IT workers inside exchanges, custodians and Web3 companies to gain privileged access from the inside, according to Chainalysis and Elliptic. Chainalysis notes that North Korea is “achieving larger thefts with fewer incidents,” and that more than 60% of funds stolen in 2025 were laundered in tranches below $500,000 per transaction — a shift away from the million‑dollar‑plus lumps that used to define nation‑state laundering.

Those stolen assets have geopolitical consequences. The United Nations and multiple government agencies believe the proceeds are used to finance North Korea’s nuclear weapons and ballistic missile programs, with some estimates suggesting the 2025 take alone could amount to roughly 13% of the country’s GDP. That reality is why CertiK and other security firms frame the threat as systemic and “nation-state level,” not just another wave of opportunistic DeFi hacks — and why they argue that more sophisticated on‑chain compliance tooling, address screening and behavioral analytics are becoming non‑negotiable for exchanges, protocols and even wallets.

As one summary from Tom’s Hardware put it, the “infernal milestone” of $2.02 billion stolen — nearly 60% of all crypto theft in 2025 — is both a security and a policy problem, and it is pushing regulators to look harder at where hacks are happening, how quickly stolen assets are being frozen, and whether existing KYC/AML frameworks are anywhere near fit for purpose in a world where a single hostile state can drain billions from poorly defended platforms.

면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, [email protected]으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

No Chart Skills? Still Profit

No Chart Skills? Still ProfitNo Chart Skills? Still Profit

Copy top traders in 3s with auto trading!