North Korea-linked hacking groups stole about $2.02 billion in crypto in 2025, accounting for nearly 60% of the roughly $3.4 billion taken globally that year. Estimates from CertiK, Chainalysis and Elliptic point in the same direction, placing DPRK actors at the center of the industry’s largest theft cases.
In its 2026 Crypto Crime Report, Chainalysis said DPRK-linked operators stole at least $2.02 billion in 2025, up 51% from 2024. The firm said that figure pushed North Korea’s all-time crypto haul to about $6.75 billion. Elliptic reached a similar conclusion, saying by early October 2025 North Korea-linked groups had already taken more than $2 billion before another wave of attacks arrived later in the year.
Fewer hacks drove larger losses
Researchers say the year’s losses were shaped by a small number of outsized breaches rather than a long list of mid-sized incidents. The February attack on Bybit, estimated at around $1.46 billion to $1.5 billion, was highlighted by both Elliptic and Chainalysis as the largest crypto theft on record. U.S. authorities quickly attributed that case to North Korean actors.
Other 2025 incidents linked to DPRK groups included attacks affecting LND.fi, WOO X and Seedify, along with many smaller breaches and wallet-draining campaigns. Even with fewer confirmed incidents than in prior years, investigators said North Korean groups were taking more value per operation. Depending on how tracked incidents were sampled, those actors were responsible for somewhere between more than half and about 60% of all crypto stolen from centralized services and DeFi protocols in 2025.
Intrusion tactics moved inside companies
Blockchain investigators also described a shift in how these groups operate. Instead of relying mainly on broad phishing campaigns or brute-force smart contract exploitation, DPRK actors are increasingly placing IT workers inside exchanges, custodians and Web3 firms, then using privileged internal access to reach funds. That change helps explain why the incident count fell while the size of individual thefts kept rising.
Laundering patterns changed as well. Chainalysis said more than 60% of the funds stolen in 2025 were moved in tranches below $500,000 per transaction, replacing the larger million-dollar transfers that had been more common in earlier state-linked laundering activity. For exchanges, protocols and wallet providers, that raises the bar for address screening and behavioral monitoring rather than simple large-transfer alerts.
Stolen crypto is now a policy problem as well as a security one
The United Nations and several government agencies believe proceeds from these thefts help fund North Korea’s nuclear weapons and ballistic missile programs. Some estimates cited in the report suggest the 2025 haul alone could equal about 13% of the country’s GDP. Security firms now describe the threat as systemic and operating at a nation-state level, not as another cycle of opportunistic DeFi hacks.
That assessment is feeding a faster compliance push across the sector. CertiK and other firms argue that stronger on-chain compliance tools, address screening, freeze response and behavioral analytics are becoming essential for exchanges, protocols and wallets. Regulators are asking a narrower set of questions now: where the hacks occur, how quickly stolen funds can be frozen, and whether current KYC and AML frameworks are capable of handling a market where a single hostile state can extract billions from weakly defended platforms.

