---
title: "North Korean Hackers Stole Record $2.02B in Crypto in 2025, Chainalysis Reports"
description: "A 51% surge pushed cumulative DPRK crypto thefts to $6.75 billion, driven by larger compromises against centralized platforms."
url: https://basisdesk.news/news/north-korea-dprk-crypto-theft-record-chainalysis
published: 2026-10-06T02:01:49.726Z
modified: 2026-10-06T02:01:49.726Z
section: Security & Hacks
author: Basis Desk Newsroom (AI-generated, source-verified)
sentiment: bearish
tickers: []
tags: [north-korea, chainalysis, hacks, cybersecurity, bybit]
license: Quote with attribution to Basis Desk (basisdesk.news). Not financial advice.
---

# North Korean Hackers Stole Record $2.02B in Crypto in 2025, Chainalysis Reports

A 51% surge pushed cumulative DPRK crypto thefts to $6.75 billion, driven by larger compromises against centralized platforms.

## At a glance

- **What happened:** Chainalysis reported that North Korean threat actors stole $2.02 billion in cryptocurrency in 2025, bringing their all-time total to $6.75 billion.
- **Why it matters:** The DPRK accounted for 76% of all platform theft in 2025, concentrating losses through massive single attacks on centralized services.
- **Who is affected:** Centralized crypto exchanges, custodians, and web3 and AI firms targeted by worker infiltration and credential phishing.
- **What's next:** Security teams monitor on-chain cross-chain bridges and Chinese-language laundering services during the typical 45-day post-theft cycle.
- **Primary source:** [North Korea Drives Record $2 Billion Crypto Theft Year, Pushing All-Time Total to $6.75 Billion](https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2026-) — chainalysis.com

## Key points

- DPRK hackers stole $2.02 billion in 2025, lifting North Korea's cumulative crypto theft haul to at least $6.75 billion [1].
- North Korean operations accounted for 76% of all funds stolen from crypto services in 2025, led by the $1.5 billion Bybit compromise [1].
- Laundering patterns showed over 60% of transfers structured below $500,000, heavily utilizing Chinese-language guarantee services and bridges [1].

## Editorial remark

- **Context:** State-backed North Korean hacking units have long targeted the digital asset industry to circumvent international sanctions. In 2025, their tactical focus pivoted from high-frequency DeFi exploits toward high-impact centralized compromises using advanced social engineering, credential harvesting, and IT worker infiltration [1].
- **Impact:** Centralized exchanges, custodians, and infrastructure providers bear the brunt of nation-state targeting, with single breaches creating systemic financial and reputational losses. Platforms face growing operational risks from remote hiring vectors and executive impersonation schemes [1].
- **Watch:** Compliance and security teams are tracking cross-chain bridge transaction patterns, mixer usage, and regional guarantee desks within the DPRK's standard 45-day post-hack laundering window [1].

North Korean state-sponsored hackers stole $2.02 billion in cryptocurrency across 2025, marking a 51% year-over-year increase, according to a report published by blockchain analytics firm Chainalysis on Oct. 6, 2026 [1]. The record annual haul pushed estimated all-time crypto funds stolen by the Democratic People’s Republic of Korea (DPRK) to $6.75 billion, even as the overall frequency of its attacks decreased [1].

The broader digital asset sector recorded more than $3.4 billion in total stolen funds between January and early December 2025 [1]. North Korean actors accounted for 76% of all value stolen from crypto services during the year [1]. Losses became heavily concentrated in high-value incidents, driven largely by the February 2025 breach of centralized exchange Bybit, which alone represented $1.5 billion in losses [1]. Chainalysis noted that the top three exploits in 2025 made up 69% of all platform theft, with the ratio between the largest single hack and the median incident exceeding 1,000x for the first time [1].

## Shifting Infiltration Tactics and Laundering Networks

Chainalysis found that North Korean operatives achieved larger returns by evolving infiltration techniques rather than launching broad attacks [1]. Threat actors expanded beyond embedding remote IT staff directly into crypto platforms [1]. Operatives increasingly impersonated corporate recruiters for artificial intelligence and web3 firms, deploying fraudulent technical screening tasks to capture virtual private network (VPN) and single sign-on (SSO) credentials, source code, and internal access [1]. Attackers also conducted social engineering schemes targeting executives while posing as strategic investors or acquirers during corporate due diligence [1].

Once funds were taken, DPRK groups executed a typical 45-day laundering cycle characterized by structured transfers [1]. In contrast to other cybercriminals who often move capital in transactions between $1 million and $10 million, North Korean actors directed over 60% of their on-chain volume in tranches under $500,000 [1]. Chainalysis tracked significant reliance on Chinese-language money laundering and guarantee networks, cross-chain bridges, mixing protocols, and specialized platforms such as Huione, while showing markedly lower participation in lending protocols and peer-to-peer exchanges [1].

## Sources

1. [North Korea Drives Record $2 Billion Crypto Theft Year, Pushing All-Time Total to $6.75 Billion](https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2026-) — chainalysis.com, 2026-10-06

---
Basis Desk Newsroom · AI-generated, source-verified · https://basisdesk.news/about/how-we-use-ai
