Illustration of an institutional building representing large scale, organized cryptocurrency theft operations

Most cryptocurrency theft is opportunistic, carried out by individuals or small groups chasing a payout. A smaller but disproportionately damaging category of theft is different in kind, not just scale. It is carried out by hacking groups publicly linked by government agencies to a nation state, operating with the patience, resourcing, and operational discipline of an intelligence apparatus rather than an ordinary criminal enterprise. Public reporting from the FBI, the US Treasury, and blockchain analytics firms has focused overwhelmingly on North Korea in this category, and the documented scale of that activity is now large enough to represent a meaningful share of all cryptocurrency theft worldwide.

Who is behind these attacks

The FBI has publicly attributed the February 2025 Bybit theft, the largest cryptocurrency heist ever recorded, to a group it tracks as TraderTraitor, which it identifies as part of the broader Lazarus Group apparatus associated with North Korea. The FBI has also named specific individuals, including Park Jin Hyok, on its public most wanted materials in connection with related cyber activity. These attributions are not informal industry labels. They are formal findings published by a federal law enforcement agency, distinct from speculation about attackers that sometimes circulates after a breach with no such backing.

The scale of the activity

According to the Chainalysis 2026 Crypto Crime Report, North Korean linked actors stole approximately two billion dollars in cryptocurrency during 2025 alone, a fifty one percent increase over the prior year, pushing their publicly tracked cumulative total to roughly six and three quarters billion dollars. The same reporting found that North Korean linked theft accounted for a majority of all cryptocurrency stolen through hacks and exploits in the period measured. Activity has continued into 2026, with roughly three hundred nine million dollars stolen across a dozen incidents in the first quarter alone, including a share of the Drift Protocol exploit covered in our guide on how DeFi exploits happen.

Key Point

Public attribution of this scale comes from formal findings by the FBI and Treasury, and from independent analysis published by blockchain intelligence firms, not from informal speculation, which is why it can be reported with confidence rather than treated as a rumor.

Signature techniques documented in public reporting

Targeting the humans, not just the code

The Bybit theft illustrates a broader pattern documented across multiple incidents: rather than attacking a target's blockchain infrastructure directly, these groups have repeatedly compromised developer machines, third party software supply chains, and the humans responsible for approving transactions, using the access gained to manipulate what a legitimate signer sees before they approve a transfer.

A structured, patient laundering cycle

Public reporting describes a distinct laundering pattern associated with North Korean linked theft, moving funds in tranches typically kept under five hundred thousand dollars each across a roughly forty five day cycle, and relying heavily on Chinese language money movement services, cross chain bridges, and mixing protocols rather than moving stolen funds directly and visibly toward a single cash out point. Our guides on cross chain laundering and mixing services cover these mechanisms in more technical depth.

Reusing proven infrastructure across multiple heists

The mixer Sinbad.io, for example, was documented by Chainalysis and the US Treasury as having processed funds not just from one theft but from multiple major Lazarus Group linked incidents, including the Horizon Bridge and Axie Infinity heists, before it was seized and sanctioned. This pattern of reusing the same laundering infrastructure across separate operations is one of the ways analysts and investigators are able to link seemingly unrelated incidents back to the same actors.

Beyond hacking: the fraudulent IT worker scheme

Not all state linked crypto theft happens through a technical exploit at all. The US Department of Justice has documented a separate, extensively prosecuted scheme in which North Korea dispatches trained IT workers to pose as freelance software developers and get hired remotely by companies, including cryptocurrency and blockchain firms, using stolen or borrowed American identities, proxy computers, and witting or unwitting facilitators based inside the United States. According to DOJ announcements, one such scheme used the stolen identities of at least eighty US persons and generated more than five million dollars in revenue for the North Korean government over several years, leading to guilty pleas from US based facilitators in 2025.

In June 2025, a federal grand jury indicted North Korean nationals directly, marking the first US charges brought against the fraudulent workers themselves rather than only their domestic facilitators. According to that indictment, the individuals infiltrated a blockchain firm based in Atlanta and a separate crypto company based in Serbia by obtaining legitimate developer access, then abused that access to steal approximately nine hundred fifteen thousand dollars in cryptocurrency, laundering the proceeds through mixing services and shell accounts consistent with the broader laundering patterns described above. The scheme illustrates that for a sufficiently patient, state resourced actor, gaining developer level trust inside a target organization can be just as effective an entry point as a technical vulnerability, and considerably harder for a hiring manager to detect during a standard remote interview process.

How attribution is actually made

Public attribution of a major theft to a state linked group is not made lightly, and it typically draws on a combination of technical indicators, such as malware code reuse and infrastructure overlap with previously documented campaigns, and financial forensics tracing stolen funds to wallets and laundering services already associated with prior incidents. The FBI has periodically issued public service announcements naming TraderTraitor and Lazarus operators directly and requesting that cryptocurrency service providers block transactions linked to specific addresses associated with a given theft, a practical step intended to slow laundering in the immediate aftermath of an attack.

The global policy response

The US Treasury's Office of Foreign Assets Control has sanctioned a range of individuals, wallet addresses, and services tied to North Korean linked laundering activity, including the Sinbad mixer and, at one point, Tornado Cash. That Tornado Cash sanction was later lifted in 2025 following a court ruling on how autonomous smart contracts can legally be treated, a development covered in more detail in our guide on how mixing services affect an investigation, though the broader sanctions regime targeting state linked actors and the specific addresses they control has continued.

Is North Korea the only state linked actor to watch

Public reporting and formal attribution overwhelmingly concentrate on North Korea when it comes to large scale, sustained cryptocurrency theft, and that concentration is reflected accurately throughout this guide rather than as an assumption about the field as a whole. Security researchers have documented other nation state affiliated groups engaging in cyber espionage and disruptive attacks against a range of targets, but the specific combination of scale, persistence, and direct financial motivation seen in North Korean linked cryptocurrency theft, as measured in the billions of dollars by Chainalysis and formally attributed by the FBI and Treasury, is not matched by comparably documented, publicly attributed activity from other states in the cryptocurrency space specifically. This guide focuses on what credible public reporting actually supports rather than speculating about other actors without that same level of attribution.

What this means for the industry and for victims

A state linked hacking group is a materially different kind of adversary than an individual scammer or a small time exploit hunter. It can afford to spend months infiltrating a target's developer environment before ever attempting a theft, it can absorb the loss of one laundering channel and immediately pivot to another, and it is not deterred by the prospect of an individual arrest in the way an ordinary criminal might be. For exchanges and protocols, this means security has to account for a patient, well resourced adversary, not just opportunistic attackers. For individual victims of a breach later attributed to one of these groups, it generally means recovery efforts depend heavily on rapid tracing and international law enforcement cooperation, since informal negotiation with the attacker, sometimes possible after a smaller, independent exploit, is not a realistic path.

It also means the FBI's public involvement, including named attribution and requests to block specific addresses, is itself a meaningful part of the response, since it mobilizes exchanges and compliance teams across the industry simultaneously rather than leaving each platform to investigate an incident on its own. Victims of an incident later attributed to a state linked group should expect their case to be treated as part of a much larger, ongoing federal investigation rather than an isolated matter, which can mean slower individual updates but also access to a far larger pool of tracing resources and prior case history than a smaller, independent theft would typically receive.

lazarus groupnorth koreastate sponsored hackingsanctionscryptocurrency security

Frequently asked questions

TraderTraitor is a specific cluster that the FBI tracks as part of the broader Lazarus Group apparatus associated with North Korea. Public reporting sometimes uses the two names somewhat interchangeably, but TraderTraitor refers more specifically to the subgroup the FBI has attributed to incidents such as the Bybit theft.

According to the Chainalysis 2026 Crypto Crime Report, publicly tracked cumulative theft attributed to North Korean linked actors has reached approximately six and three quarters billion dollars, with roughly two billion dollars of that stolen during 2025 alone, a fifty one percent increase over the prior year.

Public reporting and sanctions findings from the US Treasury describe North Korean linked cryptocurrency theft as a significant funding mechanism for the state, offering a way to generate large amounts of hard currency outside the traditional banking system that is subject to extensive international sanctions against the country.

Partial recovery has occurred in some cases, generally when funds are frozen at an exchange or service before being fully laundered, or through international law enforcement action. Full recovery is uncommon given the sophistication and patience of the laundering process these groups use, which is why prevention and rapid detection remain the primary defense.


Sources and further reading


Related reading

Lessons From Recent Major Exchange HacksHow Cryptocurrency Mixing Services Affect an InvestigationHow Cross Chain Laundering Complicates Fund TracingCryptocurrency Theft in 2026, What the Numbers Show