CertiK reports North Korea stole $2.06B in crypto in 2025, accounting for 60% of global hack losses, funding nuclear programs. (Read More)CertiK reports North Korea stole $2.06B in crypto in 2025, accounting for 60% of global hack losses, funding nuclear programs. (Read More)

North Korea Linked to $2B in Crypto Hacks in 2025: CertiK

2026/05/12 22:00
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 [email protected]으로 연락주시기 바랍니다

North Korea Linked to $2B in Crypto Hacks in 2025: CertiK

Peter Zhang May 12, 2026 14:00

CertiK reports North Korea stole $2.06B in crypto in 2025, accounting for 60% of global hack losses, funding nuclear programs.

North Korea Linked to $2B in Crypto Hacks in 2025: CertiK

North Korea-linked hackers were responsible for approximately $2.06 billion in cryptocurrency thefts in 2025, accounting for 60% of global crypto hack losses, according to blockchain security firm CertiK. The stolen funds reportedly played a key role in financing the country’s nuclear and missile programs, highlighting the nation’s increasing reliance on illicit digital asset operations for state revenue.

The findings are part of CertiK’s latest Skynet report, which tracked $3.4 billion in total crypto-related security breaches across 656 incidents during 2025. North Korea-linked groups were involved in just 12% of these incidents but accounted for the majority of the overall value stolen. CertiK described this as a shift toward "precision and scale," with fewer attacks targeting larger pools of capital.

The most significant heist of the year, the Bybit exploit in February 2025, resulted in $1.5 billion in losses. CertiK attributed the attack to North Korea’s TraderTraitor cluster, which leveraged a supply chain compromise of a third-party signing provider. Onchain analysis found that 86% of the stolen Ether was converted into Bitcoin within 30 days, utilizing a combination of mixing services, cross-chain bridges, and OTC brokers to obscure the funds’ origins.

From Phishing to Physical Infiltration

CertiK’s report also highlights a notable evolution in hacking tactics. While social engineering remains a core strategy—examples include fake job offers and malware-laden PDFs—recent operations have incorporated more sophisticated methods, including physical infiltration. The April 2026 Drift Protocol exploit, which drained $285 million from a Solana-based platform, involved a six-month campaign with attackers attending conferences, building relationships, and exploiting governance mechanisms.

Jonathan Riss, a blockchain intelligence analyst at CertiK, warned that North Korean IT workers, often posing as legitimate professionals, are infiltrating Western crypto and fintech companies. These trusted insider roles allow them to execute highly targeted attacks.

A Broader Security Threat

Beyond financial damage, the report underscores the geopolitical implications of these thefts. Both United Nations monitors and U.S. intelligence assessments confirm that proceeds from North Korea’s crypto operations are funneled into its nuclear and ballistic missile programs. CertiK’s analysis suggests that cryptocurrency theft has become a core pillar of the regime’s external income strategy, effectively "industrializing" these operations.

Since 2016, North Korean-linked hackers have reportedly stolen $6.75 billion across 263 documented incidents, according to onchain researcher Taylor Monahan. The scale and sophistication of these operations elevate them from a cybersecurity issue to an international security concern.

As digital assets grow in prominence, the risks associated with state-sponsored cybercrime are expected to increase. CertiK predicts that tools like deepfakes and supply chain attacks will further fuel crypto-related losses in 2026, posing ongoing challenges for the industry and global regulators.

Image source: Shutterstock
  • north korea
  • crypto hacks
  • certik
  • cybersecurity
  • nuclear funding
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, [email protected]으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

KAIO Global Debut

KAIO Global DebutKAIO Global Debut

Enjoy 0-fee KAIO trading and tap into the RWA boom