Fireblocks report reveals $17B stolen since 2020, with DPRK's Lazarus Group behind 75% of crypto platform attacks. Defense-in-depth approach now critical. (ReadFireblocks report reveals $17B stolen since 2020, with DPRK's Lazarus Group behind 75% of crypto platform attacks. Defense-in-depth approach now critical. (Read

Crypto Hackers Stole $3.4B in 2025 as North Korea Dominates Attacks

2026/02/12 12:10
3 min read
For feedback or concerns regarding this content, please contact us at [email protected]

Crypto Hackers Stole $3.4B in 2025 as North Korea Dominates Attacks

Jessie A Ellis Feb 12, 2026 04:10

Fireblocks report reveals $17B stolen since 2020, with DPRK's Lazarus Group behind 75% of crypto platform attacks. Defense-in-depth approach now critical.

Crypto Hackers Stole $3.4B in 2025 as North Korea Dominates Attacks

Cryptocurrency hackers made off with $3.4 billion in 2025, pushing total stolen digital assets past $17 billion since 2020, according to a new security white paper from institutional custody provider Fireblocks.

The numbers paint a stark picture: North Korea's Lazarus Group now accounts for roughly three-quarters of all attacks on crypto platforms. Their operations average nearly five times the haul of other threat actors, with DPRK-linked hackers responsible for over $2 billion of last year's losses alone.

Crime Goes Corporate

What's changed isn't just the scale—it's the sophistication. These aren't basement hackers anymore. They're running what amounts to criminal enterprises with business development teams, revenue targets, and customer service.

The emergence of "Drainer-as-a-Service" platforms has democratized crypto theft. Developers build turnkey wallet-draining kits and license them to non-technical affiliates on revenue-share deals. Think SaaS, but for stealing your tokens. These groups compete for market share like legitimate software companies.

Fireblocks identified three primary threat categories in their analysis: state-sponsored operations (primarily DPRK), commoditized crime-as-a-service offerings, and the perennial insider threat from employees and contractors with legitimate access.

Why Crypto Security Differs From Traditional IT

Here's the uncomfortable truth that makes digital asset security fundamentally different: attackers only need to win once. When a malicious transaction hits blockchain finality, those funds are gone. There's no IT team restoring from backup, no insurance claim that makes you whole.

"Nearly all digital asset theft incidents stem from actions that were 'technically authorized' by weak policies," the Fireblocks report states. A stolen credential combined with lax governance equals permanent loss.

The company, which claims to have secured over $10 trillion in digital asset transfers across 550 million wallets, advocates for what they call an "Assume Breach" architecture. Multiple independent security layers must protect funds even when individual components get compromised.

Practical Defense Layers

The white paper outlines several critical controls. A cryptographically enforced policy engine sits at the core—ensuring stolen credentials alone can't authorize transfers. Transaction clarity features decode complex smart contract interactions into readable actions, killing "blind signing" scenarios where approvers unknowingly authorize malicious unlimited token approvals.

This layered approach mirrors broader cybersecurity trends. Recent industry data shows identity misuse—stolen credentials and privilege abuse—factors into over 80% of ransomware operations. Backups, often considered the last line of defense, get compromised in 39% of incidents.

The timing of Fireblocks' report coincides with heightened cyber pressure across sectors. Google flagged sustained attacks on defense industrial bases from Russia and China-linked actors this week, while the FCC urged communications providers to strengthen ransomware defenses.

What This Means for Institutions

For institutional players managing client funds, the message is clear: point solutions won't cut it against adversaries running professional operations. The Fireblocks framework suggests every identified threat vector should face at least three independent protection layers.

With the total crypto market cap sitting at $2.34 trillion, the $17 billion stolen since 2020 represents a meaningful percentage of industry value. As threats continue evolving, security architecture that assumes eventual compromise—rather than hoping to prevent it entirely—may be the only realistic approach.

Image source: Shutterstock
  • crypto security
  • north korea hackers
  • lazarus group
  • digital asset theft
  • cybersecurity

AI Strategy: Powered 24/7

AI Strategy: Powered 24/7AI Strategy: Powered 24/7

Generate automated strategies using natural language

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags:

You May Also Like

NuScale Power (SMR) Stock Jumps on Amazon Deal — One Bigger Catalyst Still Ahead

NuScale Power (SMR) Stock Jumps on Amazon Deal — One Bigger Catalyst Still Ahead

TLDR NuScale Power (SMR) stock jumped after Amazon signed agreements to use SMR technology to power AI data centers Romania’s Final Investment Decision in February
Share
Coincentral2026/05/24 17:29
UK crypto holders brace for FCA’s expanded regulatory reach

UK crypto holders brace for FCA’s expanded regulatory reach

The post UK crypto holders brace for FCA’s expanded regulatory reach appeared on BitcoinEthereumNews.com. British crypto holders may soon face a very different landscape as the Financial Conduct Authority (FCA) moves to expand its regulatory reach in the industry. A new consultation paper outlines how the watchdog intends to apply its rulebook to crypto firms, shaping everything from asset safeguarding to trading platform operation. According to the financial regulator, these proposals would translate into clearer protections for retail investors and stricter oversight of crypto firms. UK FCA plans Until now, UK crypto users mostly encountered the FCA through rules on promotions and anti-money laundering checks. The consultation paper goes much further. It proposes direct oversight of stablecoin issuers, custodians, and crypto-asset trading platforms (CATPs). For investors, that means the wallets, exchanges, and coins they rely on could soon be subject to the same governance and resilience standards as traditional financial institutions. The regulator has also clarified that firms need official authorization before serving customers. This condition should, in theory, reduce the risk of sudden platform failures or unclear accountability. David Geale, the FCA’s executive director of payments and digital finance, said the proposals are designed to strike a balance between innovation and protection. He explained: “We want to develop a sustainable and competitive crypto sector – balancing innovation, market integrity and trust.” Geale noted that while the rules will not eliminate investment risks, they will create consistent standards, helping consumers understand what to expect from registered firms. Why does this matter for crypto holders? The UK regulatory framework shift would provide safer custody of assets, better disclosure of risks, and clearer recourse if something goes wrong. However, the regulator was also frank in its submission, arguing that no rulebook can eliminate the volatility or inherent risks of holding digital assets. Instead, the focus is on ensuring that when consumers choose to invest, they do…
Share
BitcoinEthereumNews2025/09/17 23:52
Rubio Drops Iran Breakthrough Bombshell as Nuclear Deal Talks Heat Up

Rubio Drops Iran Breakthrough Bombshell as Nuclear Deal Talks Heat Up

Rubio Signals Breakthrough in Iran Nuclear Talks as Strait of Hormuz Deal Reshapes Global Market Risk Outlook US Secretary of State Marco Rubio has confirmed
Share
Hokanews2026/05/24 17:05

No Chart Skills? Still Profit

No Chart Skills? Still ProfitNo Chart Skills? Still Profit

Copy top traders in 3s with auto trading!