North Korean state-linked hackers have stolen more than $2 billion in cryptocurrency in 2025, setting a new annual record for the total value of digital assets siphoned by the regime’s cyber operations, according to new analysis from blockchain intelligence firm Elliptic. The figure surpasses the previous high of $1.35 billion set in 2022, and it comes as security researchers observe a marked shift in tactics: attackers are now targeting high-net-worth individuals alongside major exchanges, relying increasingly on social engineering rather than technical exploits.
Bybit Heist Alone Accounts for $1.5 Billion in Losses
The single largest contributor to 2025’s staggering total is the January breach of the Bybit exchange, which Elliptic confirms as the largest heist in digital asset history. That incident alone resulted in the theft of approximately $1.5 billion. Combined with more than 30 other North Korea-linked attacks documented this year—including hacks against Seedify, LND.fi, and WOOX—the cumulative volume of stolen funds has exceeded the $2 billion threshold. Elliptic’s attribution relies on a combination of blockchain analytics, observed money-laundering patterns, and intelligence sources, acknowledging that pinning precise figures to North Korean activity is not an exact science but that the evidence across multiple incidents is robust.
Attacks Increasingly Exploit Human Weakness, Not Code
The report from Elliptic underscores a concerning evolution in North Korean hackers’ operational playbook. In most of the major thefts recorded in 2025, attackers did not break through technically sophisticated exchange defenses. Instead, they relied on social engineering strategies designed to manipulate cryptocurrency holders into voluntarily disclosing access credentials or granting account control. “The weak point in cryptocurrency security is increasingly human, rather than technical,” the researchers noted. This represents a direct challenge to the prevailing industry focus on securing smart contract code and exchange infrastructure. The targeting of high-net-worth individuals—a growing trend in 2025—compounds the risk, as these victims often manage substantial personal wallets outside of institutional custody protections.
IT Worker Infiltration Scheme Continues Under Investigation
Beyond direct cryptocurrency theft, Elliptic’s findings align with broader investigations into a separate but parallel North Korean illicit activity stream: the remote IT worker scheme. In this operation, individuals using stolen or fabricated identities have posed as American and other Western IT professionals to secure remote employment at major technology companies. While not a direct crypto theft method, the scheme generates revenue for the regime and provides a potential beachhead for future network intrusions. U.S. authorities have publicly sanctioned individuals connected to this network, and the scheme remains a focus of ongoing law enforcement scrutiny in the U.S., UK, and Australia.
How Are North Korean Hackers Stealing Over $2 Billion in Crypto?
The primary method in 2025 has been targeted social engineering, often executed through persistent, personalized contact. Attackers study their victims—both exchange employees and private holders—to craft believable scenarios that compel a specific action, such as approving a transaction, sharing a recovery phrase, or installing a seemingly legitimate application that grants remote access. Once inside, the hackers use their understanding of blockchain infrastructure to move funds rapidly through mixing services and cross-chain bridges, obscuring the trail. The Bybit hack, while unique in scale, followed a similar pattern of exploiting human trust and procedural weaknesses rather than a previously unknown software vulnerability.
Implications for Cryptocurrency Users and Exchanges
The record theft total for 2025 carries clear implications for both institutional and individual stakeholders. For exchanges, the findings argue for enhanced operational security protocols, including stricter verification for privileged access, mandatory phishing-resistant hardware security keys for all employees, and behavioral monitoring for anomalous account activity. For individual holders, particularly those with significant portfolios, the lesson is that technical safeguards are only as strong as the user’s resistance to manipulation. Even cold storage solutions can be compromised if an attacker convinces a victim to connect their hardware wallet to a compromised interface or share a seed phrase under a false premise.
What Affected Users and Holders Should Do Now
For anyone who suspects they may have been targeted or who simply wants to harden their defenses, immediate steps are essential. Change all passwords associated with cryptocurrency accounts and enable two-factor authentication (2FA) using an authenticator app or a hardware security key—SMS-based 2FA is not sufficient against determined adversaries. Review account activity for any unauthorized or unfamiliar transactions. For high-value holdings, consider moving assets to a reputable, multi-signature cold storage solution, and never share seed phrases or private keys with anyone under any circumstance. On public Wi-Fi networks or when accessing sensitive financial accounts, use a reputable no-log VPN service with a verified no-logs policy, AES-256 encryption, and a built-in kill switch to prevent data interception. The most critical defense is a hardened sense of skepticism: no legitimate exchange or wallet provider will ever ask for your private keys or request that you approve a transaction outside of your normal interface. Assume any unsolicited request is a social engineering attempt until proven otherwise.