North Korean Hackers Made $6.75 Billion From Crypto Hacks

TLDR

  • According to this newest report from Chainalysis, North Korean hackers are working smarter, not harder.
  • They’re hacking less, but walking away with bigger hauls per job.
  • On the flip side, DeFi is actually becoming safer as security protocols shut down hack attempts.

According to a new report from Chainalysis, North Korean hackers stole a whopping $2.02 billion in cryptocurrency in 2025 alone. For those of us just trying to stack a few sats or buy our first fraction of a Bitcoin, these numbers can feel like they belong in a spy movie rather than real life. 

While the total amount stolen by these cybercriminals hit an all-time high of $6.75 billion, the way they operate is changing. They are getting smarter, sneakier, and frankly, a bit more creative with their job applications (we’ll get to that in a minute).

In 2025, we saw massive hacks on centralized services, a worrying rise in regular folks getting their wallets drained, and — believe it or not — some actual improvements in how decentralized finance (DeFi) protocols defend themselves. Think of this as your neighborhood watch update. Let’s get after it.

The North Korean Hackers Scorecard

North Korean hackers increased their theft by 51% this year compared to the previous year. They walked away with over $2 billion, cementing their status as the heavyweight champions of crypto crime.

What makes this year different is efficiency. They launched fewer attacks than in previous years but made way more money per hack. In fact, a single massive breach of the Bybit exchange in February accounted for $1.5 billion of that total. It’s the classic “work smarter, not harder” philosophy, applied to international grand larceny.

To put this in perspective, the gap between the largest hacks and the average hack is widening. The funds stolen in the largest attacks of 2025 were 1,000 times larger than the median incident. 

While there are plenty of small-time scammers out there, the whale-sized losses are concentrated in just a few catastrophic events. The top three hacks alone accounted for 69% of all service losses. When these hackers strike, they don’t just take a slice of the pie; they take the whole bakery.

The New “Fake Recruiter” Scam You Need to Know 

Now, you might be thinking, “I’m not a billion-dollar exchange, so I’m safe, right?” Not necessarily. The tactics used by these groups rely heavily on social engineering, and understanding them can help you spot red flags in your own digital life.

Historically, North Korean hackers liked to embed IT workers into crypto companies. Imagine hiring a developer who seems perfect on paper, only to find out they are secretly opening backdoors for a state-sponsored hacking team. That’s still happening, but they’ve flipped the script.

Recently, these operators have started impersonating recruiters for big-name Web3 and AI firms. They reach out to people with legitimate-looking job offers. The interview process seems normal until you get to the “technical screening”. That’s when they trick you into downloading software that harvests your credentials, steals source code, or gives them access to your company’s internal network.

They are even targeting executives with fake investment pitches. They’ll set up meetings posing as strategic investors, using the due diligence process to fish for sensitive information. It’s a sophisticated cat-and-phishing game targeting the people who hold the keys to the castle.

Breaking Down the 45-Day Cycle

Once they have the loot, they can’t exactly walk into a bank and deposit it. They have to clean it — or “launder” it — to make it usable. The Chainalysis report identified a distinct 45-day laundering cycle that North Korean hackers tend to follow.

Here is the play-by-play of how a billion dollars disappears:

  1. Days 0-5 (The Panic Run): Immediately after a hack, they move funds furiously. They use DeFi protocols and “mixing services” (tools that jumble crypto transactions to hide their origin) to create the first layer of confusion.
  2. Days 6-10 (The Shuffle): They start moving funds to exchanges that have lax identity checks (KYC) and use cross-chain bridges to hop from one blockchain to another. It’s like switching getaway cars three times in a row.
  3. Days 20-45 (The Cash Out): Finally, they move the funds to services where they can convert them into cash or other assets. This often involves Chinese-language money-laundering networks and over-the-counter traders who ask few questions.

Interestingly, North Korean hackers prefer Chinese-language services and specific bridges, avoiding the peer-to-peer platforms that other criminals use. They move in smaller chunks (under $500,000) to fly under the radar, even though their total haul is massive.

Why Your Personal Wallet Might Be at Risk

Okay, let’s bring it back to you. While the billion-dollar headlines grab attention, a quieter, more annoying trend is rising: personal wallet compromises.

In 2025, the number of individual wallet hacks nearly tripled to 158,000 incidents. That’s about 80,000 unique victims who woke up to find their digital assets gone. This spike is likely due to more people entering the crypto space — welcome to the party, by the way! — but it also shows that scammers are casting a wider net.

The good news? The total value stolen from individuals actually went down, from $1.5 billion in 2024 to $713 million in 2025. This suggests attackers are hitting more people but getting less money per victim. It’s quantity over quality for the lower-level scammers.

Certain networks are riskier than others. Ethereum and Tron had the highest rates of theft. If you are using these networks, you need to be extra vigilant. Double-check every transaction, use a hardware wallet if you can, and never — ever — give your seed phrase to anyone (not even if they claim to be “Wallet Support”).

Finally, Some Good News for DeFi

It’s not all doom and gloom. Decentralized Finance (DeFi) — which is basically banking without the banks — is actually getting safer.

In the past, as the amount of money in DeFi grew (Total Value Locked, or TVL), the amount of money stolen grew right along with it. It made sense: more money in the vault meant more robbers trying to crack it. But in 2025, we saw a divergence. The amount of money in DeFi rose, but hack losses remained low.

Why? Security is improving. Protocols are getting better at spotting attacks before they happen.

Take the Venus Protocol incident from September 2025 as a prime example. An attacker compromised a user’s account and appeared ready to drain millions. But Venus had installed a security monitoring platform called Hexagate. The system flagged suspicious activity 18 hours before the attack. When the malicious transaction finally hit, the protocol paused itself within 20 minutes.

The result? They froze the funds, fixed the issue, and the attacker actually lost money on the failed attempt. That is the kind of win we love to see. It proves that with the right tools, the good guys can win.

The Report and How It Impacts the Crypto Journey of New Users

The crypto world is maturing. Yes, the threats are real, and yes, state-sponsored hackers are still pulling off Ocean’s Eleven-style heists. But the defenses are catching up.

For you, the new investor, the lessons from 2025 are:

  • Be skeptical of unsolicited messages: Whether it’s a “recruiter” on LinkedIn or a “support agent” on Telegram, assume it’s a scam until proven otherwise.
  • Secure your own fortress: Personal wallet hacks are up. Use strong security practices and don’t be the low-hanging fruit.
  • Trust the process: The industry is building better alarms and locks (like we saw with Venus Protocol).

Crypto is still the most exciting financial frontier on the planet. Don’t let the headlines keep you on the sidelines — just make sure you bring your helmet.

Disclaimer

This article is for educational and information purposes, and should not be considered financial advice. For more information visit our disclaimer page

About the Author

Countdown to next draw

days

hours

minutes

seconds