North Korean Hackers Infiltrate Crypto Firms as IT Workers, Steal More Than $2 Billion in 2025
North Korean hackers have long used false identities to apply for remote IT jobs, gaining access to private keys, core code and internal systems after infiltrating blockchain and AI companies. Such attacks not only lead to cryptoasset theft but also increase the risks facing multinational companies in employee screening and supply-chain security.
A Chainalysis report found that North Korean hackers stole about $2.02 billion in cryptoassets in 2025, up 51% year on year and accounting for roughly 60% of the global total stolen. CertiK put the figure at $2.06 billion. In a recent case, an interviewer exposed a North Korean operative posing as a Japanese engineer by asking the applicant to criticize Kim Jong Un.
All Coverage
3 original reportsThe Backstory
The history behind this eventNorth Korea-Linked Lazarus Deploys New Malware Against Financial and Crypto Institutions
Lazarus is regarded as a North Korea-linked hacking group that has long targeted banks, payment systems and cryptocurrency companies to steal funds through cyber intrusions. Financial and digital-asset institutions hold large amounts of high-value assets, leaving them vulnerable to theft and operational disruption if security systems fail to detect an attack.
Cybersecurity firm Fox-IT recently said Lazarus had switched to the newly developed RemotePE malware toolkit. The malware uses in-memory execution and multiple evasion techniques to bypass security tools while establishing remote-access capabilities. However, available information does not specify the report’s publication date, the names of the targeted institutions, the number of victims or the amount of losses.
CertiK Says North Korea ‘Industrialized’ Crypto Theft, Stole More Than $2 Billion in 2025
North Korea has long used state-backed hacking groups to target cryptocurrency exchanges and related services. Blockchain security firm CertiK said the country has “industrialized” such theft, turning it into a core channel for evading international sanctions and obtaining foreign currency. The proceeds have also been used to fund its nuclear weapons and missile programs.
CertiK’s latest report showed that North Korea-linked hacking groups stole about $2.06 billion in cryptocurrency in 2025, accounting for roughly 60% of global losses from crypto hacks that year. The report said North Korea has built systematic operations spanning attacks, asset transfers and money laundering, indicating that the activity has evolved from isolated crimes into a state-level revenue model.
North Korean Hackers Account for 76% of Crypto Stolen in 2026
North Korea-linked hacking groups have long targeted cryptocurrency platforms, with organizations such as Lazarus particularly adept at attacking DeFi protocols. Because stolen assets can be moved rapidly across borders, such attacks not only threaten investors and protocol security but also renew concerns about North Korea obtaining funds through digital assets.
A TRM Labs report found that North Korea-linked hackers accounted for 76% of total cryptocurrency thefts in 2026. In April, hackers stole about $577 million from DeFi protocols including Drift Protocol and Kelp DAO over 18 days. Global crypto hack losses exceeded $630 million that month, the highest since February 2025.
North Korean IT Operatives Exposed Earning $1 Million a Month Through Crypto Scams
North Korea has long used overseas IT workers posing as job applicants to infiltrate crypto projects and gain salaries, system access and digital assets. The network uncovered by blockchain investigator ZachXBT involved about 140 people, indicating that the operation had developed into a sizable, sustainable source of foreign currency that could help North Korea evade international sanctions.
As of July 19, 2026, data released by ZachXBT showed that the team earned about $1 million a month from IT jobs and crypto scams. Members used simple passwords such as “123456” to manage payment and ranking platforms. Stolen crypto was converted into fiat currency and then transferred to Chinese bank accounts.
North Korean IT Workers Infiltrated DeFi for Seven Years, Affecting More Than 40 Crypto Platforms
North Korea has long used IT workers posing as overseas contractors to secure blockchain development work, earning foreign currency and gaining access to core DeFi privileges. Security researcher Taylor Monahan said some of these workers have more than seven years of experience. The networks are believed to have ties to Lazarus Group, highlighting shortcomings in existing identity screening and defense strategies.
A recent investigation found that North Korean IT workers had infiltrated more than 40 crypto platforms and DeFi protocols, and were suspected of outsourcing work to non-North Koreans. Related attacks include the theft of about $625 million from Ronin Bridge in March 2022 and the theft of about $235 million from Indian exchange WazirX in July 2024.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.