North Korean crypto hackers are getting more sophisticated

Source Cryptopolitan

Crypto firm Paradigm warns in a report titled “Demystifying the North Korean Threat” that North Korean cyberwarfare attacks on the cryptocurrency industry are growing in sophistication, and the number of groups involved in such criminal activity is increasing.

Over the years, North Korea has been tied to high-profile cyberattacks on cryptocurrency exchanges, with stolen money believed to be used to finance the country’s military and nuclear programs.

The United Nations estimated North Korea stole about $3 billion in crypto hacks from 2017 to 2023. However, in just 2024 and 2025 alone, they have already plundered a record $1.7 billion from two of the largest exchanges, WazirX and Bybit.

Hackers use fake job offers to steal crypto, putting millions of users at risk

There are several factions of North Korean hackers, each specializing in different kinds of cyberattacks. The most infamous one is the Lazarus Group, which has a history of targeting financial institutions and digital asset exchanges.

Other groups, such as AppleJeus, Dangerous Password, and Spinout, use different methods (e.g., phishing attacks, fake job offers, malware masquerading as genuine software).

The most shocking attack to date took place in February 2025, when crypto exchange Bybit was hacked for $1.5 billion — the largest cryptocurrency hack to date. While it was first considered to be a phishing scheme, an in-depth investigation revealed that the exploit was based on a much more advanced strategy.

The hackers, from North Korea’s Reconnaissance General Bureau, had stealthily compromised Safe{Wallet}, a digital wallet system used by many Bybit users, rather than launching an attack directly against the exchange. They infiltrated a backdoor into the software, letting them siphon cash without immediately being noticed.

This method was far more sophisticated. Rather than targeting exchanges, it targeted the infrastructure supporting crypto exchanges.

Once they steal the cryptocurrency, the hackers launder it and evade detection using off-the-shelf, well-established techniques. They first divide the loot into smaller amounts, pass them through hundreds of digital wallets, and eventually turn them into Bitcoin (BTC).

This tactic makes it harder for authorities to trace the money. According to the security firm Chainalysis, Lazarus Group tends to hold stolen money for months, years, and even before spending it, maximizing its chances of avoiding detection.

The FBI has identified three alleged members of the Lazarus Group and accused them of cybercrimes. In February 2021, the US Justice Department indicted two of those members for involvement in global cybercrimes. Yet, despite such efforts, North Korean hackers and cybercriminals have continued to adapt and find new methods for interfering with financial systems.

Cryptopolitan Academy: Want to grow your money in 2025? Learn how to do it with DeFi in our upcoming webclass. Save Your Spot

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
ADP Employment Change projected to show US job growth slowing in FebruaryThe US labor market is set to take center stage this week as fresh concerns mount that the economy may be losing its momentum — a sentiment echoed by recent slower growth and worrisome fundamental data.
Author  FXStreet
Mar 05, Wed
The US labor market is set to take center stage this week as fresh concerns mount that the economy may be losing its momentum — a sentiment echoed by recent slower growth and worrisome fundamental data.
placeholder
Nvidia stock sinks 4% as Trump’s tariff plans rattle AI tradeNvidia shares fell over 4% early Monday after US President Donald Trump delivered a stern message about trade tariffs. Trump said on Sunday that no country would be given any special treatment regarding tariffs. He also signed new trade policies into effect on April 2, which he calls “Liberation Day.” This frightened investors, who had […]
Author  NewsBTC
Yesterday 01: 15
Nvidia shares fell over 4% early Monday after US President Donald Trump delivered a stern message about trade tariffs. Trump said on Sunday that no country would be given any special treatment regarding tariffs. He also signed new trade policies into effect on April 2, which he calls “Liberation Day.” This frightened investors, who had […]
placeholder
XRP Price Set For ‘Hot’ April With Low Fibonacci Levels And High $5-$8 TargetThe past 24 hours have been challenging for XRP holders. A sharp 5.8% decline in price has brought the asset close to testing critical support around $2, with selling pressure currently dominating XRP’s trading volume. The sentiment is turning bearish, but one analyst is confident in the cryptocurrency’s long-term trajectory, predicting that the altcoin is […]
Author  NewsBTC
Yesterday 01: 54
The past 24 hours have been challenging for XRP holders. A sharp 5.8% decline in price has brought the asset close to testing critical support around $2, with selling pressure currently dominating XRP’s trading volume. The sentiment is turning bearish, but one analyst is confident in the cryptocurrency’s long-term trajectory, predicting that the altcoin is […]
placeholder
Gold price hits new all-time high ahead of Trump’s reciprocal tariffsGold price (XAU/USD) edges higher again for a second day this week and for the first day of the second quarter of 2025.
Author  FXStreet
Yesterday 10: 38
Gold price (XAU/USD) edges higher again for a second day this week and for the first day of the second quarter of 2025.
placeholder
Gold price remains close to record high amid concerns over Trump’s reciprocal tariffsGold price (XAU/USD) attracts some dip-buyers during the Asian session on Wednesday and stalls the previous day's modest retracement slide from a fresh record high.
Author  FXStreet
6 hours ago
Gold price (XAU/USD) attracts some dip-buyers during the Asian session on Wednesday and stalls the previous day's modest retracement slide from a fresh record high.
goTop
quote