North Korea Crypto Theft: How Kim Jong Un’s Hackers Stole $6.75 Billion
February 21, 2025. A laptop belonging to a contractor working with Bybit — one of the world’s largest crypto exchanges — was compromised.
It seemed like a minor security incident. It was anything but.
Within seventeen days, North Korea’s hackers had used that single compromised laptop to steal $1.5 billion from Bybit — the largest single crypto theft in history, more than the entire GDP of some countries.
This was not a fluke. It was not a lucky break by a talented individual. It was the latest operation by the Lazarus Group — a state-sponsored hacking organization operating directly under the direction of Kim Jong Un’s North Korean government, and the single most prolific crypto thief in history.
Since 2017, North Korea has stolen an estimated $6.75 billion in cryptocurrency. In the first four months of 2026 alone, North Korean hackers were responsible for 76% of all crypto hack losses globally — $577 million out of $759 million total.
This is not a cybersecurity footnote. It is one of the most important stories in crypto — and one that directly affects every exchange, every protocol, and every investor in the market.
Who is the Lazarus Group?
The Lazarus Group is North Korea’s primary state-sponsored hacking organization — operating under the Reconnaissance General Bureau (RGB), Kim Jong Un’s intelligence agency.
They are not rogue hackers working for personal gain. They are salaried government employees with one mission: steal as much money as possible to fund North Korea’s nuclear weapons and ballistic missile programs while evading international sanctions that have effectively cut the country off from the global financial system.
From Sony to Crypto — The Evolution
2014 — Sony Pictures Lazarus gained international notoriety by destroying Sony Pictures’ infrastructure in retaliation for “The Interview” — a film depicting Kim Jong Un’s assassination. They deployed wiper malware and leaked embarrassing internal communications. First major proof they could operate at scale.
2016 — Bangladesh Bank Lazarus attempted to steal nearly $1 billion from Bangladesh Bank through the SWIFT international banking system — successfully stealing $81 million before transfers were blocked.
2017 — WannaCry Ransomware Lazarus launched WannaCry — a global ransomware attack affecting 230,000 computers across 150 countries, including UK hospitals and global corporations.
2017 onwards — Crypto Becomes Their Primary Target When crypto markets exploded in 2017, North Korea pivoted. Crypto offered something traditional banking did not: borderless, largely anonymous, and technically complex enough to steal at scale while making recovery nearly impossible.
The Complete Theft Timeline — $6.75 Billion and Counting
| Year | Amount Stolen | Notable Incidents |
|---|---|---|
| 2017–2020 | ~$1.5 billion | Multiple exchange hacks |
| 2021 | ~$400 million | Various DeFi protocols |
| 2022 | ~$1.7 billion | Ronin Network ($625M), Horizon Bridge ($100M) |
| 2023 | ~$600 million | Multiple attacks |
| 2024 | ~$1.3 billion | 47 incidents — record volume |
| 2025 | $2.02 billion | Bybit ($1.5B) — record single theft |
| 2026 (Jan-Apr) | $577 million | Drift ($285M), KelpDAO ($290M) |
| Total | ~$6.75 billion | Since 2017 |
The trajectory is not declining. It is accelerating. While the number of incidents fell 74% in 2025 compared to 2024, the value stolen per attack skyrocketed — North Korea is getting more efficient, not less active.
The Bybit Hack — February 2025 ($1.5 Billion)
The largest single crypto theft in history began with one compromised laptop.
How it happened: A contractor working with Bybit was socially engineered — tricked into installing malware on their computer. North Korean operatives used access gained through this contractor to infiltrate Bybit’s signing infrastructure — the system that authorizes large transfers from cold wallets.
Over the following days, they mapped the system, understood the signing process, and waited.
On February 21, 2025 — they struck. In a single transaction, they drained $1.5 billion in Ethereum from Bybit’s cold wallet.
The aftermath:
- CEO Ben Zhou confirmed the hack within hours
- Bybit covered all user losses from its own funds — no user lost money
- Within 17 days, attackers converted 86.29% of stolen ETH to Bitcoin via THORChain
- North Korea laundered funds through hundreds of wallet addresses
The scale in context: $1.5 billion is more than the annual GDP of nations like Tonga, Samoa, and Vanuatu. It was stolen in a single transaction.
The WazirX Hack — India’s Biggest Crypto Security Incident ($234.9 Million)
North Korea’s Lazarus Group was attributed with the WazirX hack of July 2024 — India’s largest crypto security incident.
What happened: Attackers manipulated WazirX’s multisig signing process — replacing the safe wallet implementation with a malicious contract to drain $234.9 million from India’s largest exchange at the time.
Impact on India:
- Withdrawals frozen for months
- 6.6 million Indian users affected
- ₹1,900+ crore in user funds at risk
- Restructuring plan and legal battles followed
For the complete WazirX story: WazirX Hack Explained
April 2026 — The Most Devastating Month
April 2026 became the most damaging single month in DeFi hack history:
Drift Protocol — $285 Million (April 2026)
Lazarus exploited Solana-based Drift Protocol — one of the largest DEXs on Solana — draining $285 million in what became the largest Solana hack in history.
The stolen funds:
- Converted to USDC via Jupiter (Solana DEX)
- Bridged to Ethereum
- Swapped into ETH
- Distributed across fresh wallets
- Gone dormant — the classic North Korean patience play
KelpDAO — $290 Million (April 18, 2026)
Four days later — Lazarus struck again.
KelpDAO is a DeFi protocol that allows users to earn yield on crypto deposits. On April 18, attackers exploited a vulnerability in the LayerZero cross-chain bridge infrastructure — forging a cross-chain message to drain approximately $290 million in ETH.
LayerZero issued a statement: “Preliminary indicators suggest attribution to a highly sophisticated state actor, likely DPRK’s Lazarus Group.”
The laundering operation: Approximately $175 million in ETH moved through THORChain — converting ETH to BTC — after Arbitrum’s Security Council froze a portion of the stolen funds. The speed and efficiency of the laundering operation demonstrated increasing sophistication.
Total April 2026 damage: 12 Lazarus attacks in a single month → $635 million stolen → $13 billion drop in DeFi’s Total Value Locked → North Korea responsible for 95% of that month’s crypto losses.
How North Korea Actually Steals Crypto — The Playbook
Understanding how Lazarus operates is essential for understanding why they are so difficult to stop:
Step 1 — Target Selection
Lazarus conducts months of reconnaissance — identifying targets with the highest value and most accessible attack surface. They particularly target:
- Crypto exchanges with large cold wallets
- Cross-chain bridges (historically the most vulnerable infrastructure)
- DeFi protocols with complex smart contract interactions
- Contractors and employees of target companies
Step 2 — Initial Access
The most common entry point: social engineering. Lazarus is sophisticated at:
- Fake job offers — sending “job opportunity” messages to crypto employees with malware-laden documents
- LinkedIn phishing — impersonating recruiters from legitimate companies
- Supply chain attacks — compromising contractors or software dependencies
Step 3 — Infrastructure Mapping
After gaining initial access, Lazarus spends weeks or months mapping the target’s systems — identifying signing keys, cold wallet procedures, and security controls. Patience is a key differentiator.
Step 4 — The Strike
When ready, they execute in a single coordinated attack — often in minutes. The signing infrastructure is compromised, a single transaction is crafted to drain the maximum possible amount, and the funds are moved.
Step 5 — Laundering
This is where North Korea is particularly sophisticated:
Stolen crypto
↓
Convert to ETH or USDC via DEX
↓
Bridge across chains via THORChain
↓
Convert ETH → BTC
↓
Distribute across hundreds of fresh wallets
↓
Hold dormant for months or years
↓
Gradually cash out through exchanges in
non-cooperative jurisdictions
The dormancy period is deliberate — law enforcement attention fades, tracing becomes harder. Funds stolen in 2022 are still being gradually laundered in 2026.
Why Can’t Anyone Stop Them?
This is the frustrating reality of North Korean crypto theft:
Decentralization Works Against Recovery
DeFi protocols and cross-chain bridges are designed to be censorship-resistant and permissionless. When Lazarus moves funds through THORChain, THORChain’s developers argue they have no central ability to reject transactions.
This is the double-edged sword of decentralization — the same property that makes DeFi resistant to government censorship makes it useful for laundering stolen funds.
Jurisdictional Complexity
North Korea operates outside the international legal framework. There is no extradition treaty, no cooperative law enforcement relationship, no diplomatic channel. US indictments of named Lazarus operatives have zero practical effect.
Sophistication is Increasing
Early North Korean crypto hacks were relatively unsophisticated — basic phishing and exchange compromises. The Bybit hack (compromising signing infrastructure through a contractor) and the KelpDAO hack (exploiting complex cross-chain bridge logic) represent genuine technical sophistication that rivals the best private security research.
Scale of Resources
North Korea operates crypto theft as a government program — with full state resources, intelligence gathering capabilities, and long-term planning horizons that no criminal organization can match.
The Nuclear Connection — Why This Matters Beyond Crypto
The funds stolen by North Korea are not going to personal enrichment. They are going directly to:
- Nuclear weapons development — North Korea’s ICBM program
- Ballistic missile testing — programs condemned by the UN Security Council
- Sanctions evasion — circumventing the international financial isolation designed to prevent these programs
The United Nations estimated that North Korean crypto theft directly funds approximately 40% of the country’s weapons of mass destruction program.
This makes every crypto hack by Lazarus not just a financial crime — but a direct contribution to nuclear proliferation.
How This Affects Indian Crypto Investors
North Korea’s hacking operations have direct consequences for Indian crypto users:
WazirX: India’s most direct experience — $234.9 million stolen, millions of Indian investors affected, restructuring ongoing.
Exchange security premiums: Every major exchange has increased security spending specifically because of North Korean threats — costs that are partially passed to users through fees.
Market impact: The April 2026 attacks caused a $13 billion drop in DeFi TVL — contributing to price pressure across all crypto assets, including those held by Indian investors.
Insurance products: The rise of North Korean threats is one driver of DeFi insurance protocols — a growing sector that Indian DeFi users should be aware of.
What the Crypto Industry is Doing
The industry is not standing still — but progress is slow against such a sophisticated adversary:
Improved cold wallet procedures: Post-Bybit, exchanges have overhauled signing processes — multiple independent verification steps, hardware security modules, and separation of duties.
Cross-chain bridge security: Bridges are the most targeted infrastructure. Major protocols have added circuit breakers, monitoring, and emergency pause mechanisms.
On-chain analytics: TRM Labs, Chainalysis, and Elliptic track Lazarus fund movements in near-real-time — alerting exchanges when stolen funds approach.
Government coordination: The US Treasury, FBI, and Department of Justice have indicted named Lazarus operatives and placed sanctions on specific crypto addresses — though enforcement against North Korea remains practically impossible.
FAQs — North Korea Crypto Theft
How much crypto has North Korea stolen?
Since 2017, North Korea’s Lazarus Group has stolen an estimated $6.75 billion in cryptocurrency — making it by far the most prolific crypto thief in history.
What is the Lazarus Group?
The Lazarus Group is North Korea’s state-sponsored hacking organization, operating under the Reconnaissance General Bureau (RGB) — Kim Jong Un’s intelligence agency. They are government employees whose mission is to steal cryptocurrency to fund North Korea’s weapons programs.
What was the largest North Korean crypto hack?
The Bybit hack of February 2025 — $1.5 billion stolen in a single transaction — is the largest single crypto theft in history, attributed to North Korea’s Lazarus Group.
Did North Korea hack WazirX?
Yes — the WazirX hack of July 2024 ($234.9 million) was attributed to North Korea’s Lazarus Group. It remains India’s largest crypto security incident.
How does North Korea launder stolen crypto?
North Korea converts stolen crypto to ETH and BTC through DEXs and cross-chain bridges (primarily THORChain), distributes across hundreds of fresh wallets, holds dormant for months or years, then gradually cashes out through exchanges in non-cooperative jurisdictions.
Why can’t crypto be recovered after a North Korean hack?
Blockchain transactions are irreversible by design. North Korea operates outside international law — no extradition, no cooperative law enforcement. Funds are rapidly laundered through decentralized protocols that cannot be forced to reverse transactions.
What percentage of 2026 crypto hacks are from North Korea?
According to TRM Labs, North Korea was responsible for approximately 76% of all crypto hack value in the first four months of 2026 — $577 million of $759 million total.
What does North Korea do with stolen crypto?
The funds directly support North Korea’s nuclear weapons and ballistic missile development programs — the UN estimates stolen crypto funds approximately 40% of North Korea’s weapons of mass destruction program.
Conclusion
North Korea’s crypto theft operation is the most consequential single threat to the cryptocurrency industry — and one of the most innovative criminal enterprises in the history of finance.
$6.75 billion stolen. 76% of 2026’s hack losses. A $1.5 billion single-transaction heist. A direct line from stolen Ethereum to Kim Jong Un’s missile program.
The Lazarus Group began as political hacktivists destroying Sony Pictures’ servers. They evolved into the world’s premier cryptocurrency thieves — operating with state resources, intelligence capabilities, and time horizons that no private criminal organization can match.
For Indian crypto investors, the WazirX hack was the most visceral proof of this threat. For the global crypto industry, Bybit and KelpDAO are the latest chapters in a story that shows no signs of ending.
The uncomfortable truth: as long as crypto is valuable, borderless, and technically complex — North Korea will keep stealing it. The question is not whether but how much, and how quickly the industry can raise the cost of each attack.
Disclaimer: This article is for educational and informational purposes only. All figures are based on publicly available research from Chainalysis, TRM Labs, and major news organizations.