Cryptocurrency

How North Korean Hackers Target Crypto Exchanges, Wallets

How North Korean Hackers Target Crypto Exchanges and Wallets Through Social Engineering, Malware and Insider Access

Written By : Bhavesh Maurya
Reviewed By : Achu Krishnan

North Korean cyber groups are considered a major security threat to cryptocurrency companies.  They combine sophisticated social engineering with malware, insider access, and rapid laundering of stolen funds. The size of their operations has grown as exchanges and custodians have accumulated larger pools of digital assets.

Crypto Theft Reached Record Levels

According to Chainalysis, hackers from North Korea stole nearly USD 2.02 billion from the crypto industry in 2025, up 51% from 2024. That brought the total value stolen by North Korean hackers to at least USD 6.75 billion. 

North Korean hacking accounted for 76% of the service hacks during the year. The major incident was the hacking of Bybit in February 2025, when hackers stole around USD 1.5 billion. The FBI has linked the incident to North Korean hackers, while North Korea has always claimed that it was not involved in the incident.

Employees Can Become the Entry Point

Attackers do not always begin by attempting to break blockchain technology. Instead, they increasingly target people who control access to exchange infrastructure.

The FBI has warned that DPRK-linked groups research cryptocurrency employees through professional and social networks before approaching them with carefully constructed scenarios. These can involve fake recruitment opportunities, investment discussions or impersonation of people the victim may recognize. 

After building trust, attackers may attempt to persuade employees to download malicious software, open files or interact with compromised websites. Access to internal systems can then provide opportunities to target wallets, transaction approval systems or private infrastructure.

Chainalysis also found evidence of North Korean IT workers obtaining positions inside crypto businesses, potentially providing privileged access before larger compromises occur. 

Wallet Users Face Different Risks

Individual wallets can be compromised through stolen private keys, malicious applications, phishing links and fraudulent transaction approvals. Chainalysis recorded approximately 158,000 individual wallet compromise incidents affecting 80,000 unique victims in 2025, with around USD 713 million stolen. 

Once cryptocurrency leaves a compromised wallet, attackers can move assets rapidly across addresses, bridges and different tokens.

Laundering Makes Recovery Difficult

North Korean groups have used cross-chain bridges, mixers and laundering services to obscure transaction trails. Blockchain transactions remain traceable, but recovering assets becomes more difficult once funds move through multiple networks and services.

The FBI recommends crypto companies restrict software execution, protect sensitive repositories and use stronger authentication around transaction approvals. 

Final Thoughts

North Korean crypto attacks increasingly combine technical compromise with manipulation of employees and insiders. As the value held by exchanges and wallets grows, security increasingly depends on protecting both blockchain infrastructure and the people authorized to access it.

Also Read: OKX Founder Questions THORChain’s Role After USD 387.5 Million Bitget Hack

FAQs:

1. How much cryptocurrency did North Korean hackers steal in 2025?

According to Chainalysis, North Korea-linked hackers stole approximately USD 2.02 billion in 2025, bringing their estimated cumulative crypto theft to at least USD 6.75 billion.

2. How do North Korean hackers target crypto exchange employees?

They may research employees through professional and social networks before using fake job offers, investment discussions or impersonation. Victims can then be directed toward malicious files, software or websites.

3. Was North Korea linked to the Bybit hack?

The FBI attributed the February 2025 Bybit theft, involving approximately USD 1.5 billion, to North Korean actors. North Korea has denied involvement in cryptocurrency theft.

4. How are individual cryptocurrency wallets compromised?

Attackers can target private keys through phishing, malicious applications and fraudulent transaction approvals. Chainalysis recorded about 158,000 individual wallet compromise incidents during 2025.

5. How do hackers launder stolen cryptocurrency?

Stolen assets can be moved between wallets, blockchains and tokens using cross-chain bridges, mixers and other services. These movements can make recovery more difficult even when blockchain transactions remain traceable.

Join our WhatsApp Channel to get the latest news, exclusives and videos on WhatsApp

                                                                                                       _____________                                             

Disclaimer: Analytics Insight does not provide financial advice or guidance on cryptocurrencies and stocks. Also note that the cryptocurrencies mentioned/listed on the website could potentially be risky, i.e. designed to induce you to invest financial resources that may be lost forever and not be recoverable once investments are made. This article is provided for informational purposes and does not constitute investment advice. You are responsible for conducting your own research (DYOR) before making any investments. Read more about the financial risks involved here.

Crypto Prices Today: Bitcoin Holds Near USD 83,000 as Zcash Slides 12%

Fixed vs. Flexible Crypto Reward Plans: How the Two Structures Compare in 2026

Binance Funding Account Changes Explained: What Crypto Users Need to Know in 2026

Blockchain in European Finance: How Tokenized Finance Could Reshape Markets

How the GENIUS Act Could Change Stablecoin Regulation