logo
Why are North Korean hackers such good crypto-thieves?

Why are North Korean hackers such good crypto-thieves?

Mint26-05-2025
FEBRUARY 21st was a typical day, recalls Ben Zhou, the boss of ByBit, a Dubai-based cryptocurrency exchange. Before going to bed, he approved a fund transfer between the firm's accounts, a 'typical manoeuvre" performed while servicing more than 60m users around the world. Half an hour later he got a phone call. 'Ben, there's an issue," his chief financial officer said, voice shaking. 'We might be hacked…all of the Ethereum is gone."
Independent investigators and America's Federal Bureau of Investigations (FBI) soon pointed the finger at a familiar culprit: North Korea. Hackers from the hermit kingdom have established themselves as one of the biggest threats to the crypto-industry—and as a crucial source of revenue for Kim Jong Un's regime, helping it to weather international sanctions, to pamper its elites and to fund its missile and nuclear-weapons programmes.
In 2023 North Korean hackers made away with a total of $661m, according to Chainalysis, a crypto-investigations firm; they doubled the sum in 2024, racking up $1.34bn across 47 separate heists, an amount equivalent to more than 60% of the global total of stolen crypto. The ByBit operation indicates a growing degree of skill and ambition: in a single hack, North Korea swiped the equivalent of $1.5bn from the exchange, the largest-ever heist in the history of cryptocurrency.
North Korea's plunder is the payoff from a decades-long effort. The country's first computer-science schools date back to at least the 1980s. The Gulf War helped the regime recognise the importance of networked technology for modern warfare. Talented maths students were put into special schools and given reprieves from mandatory annual countryside labour, says Thae Yong Ho, a senior North Korean diplomat who defected in 2016. Originally envisaged as a tool for espionage and sabotage, North Korea's cyber-forces began to focus on cybercrime in the mid-2010s. Mr Kim is said to call cyberwarfare 'an all-purpose sword".
Stealing crypto involves two main phases. The first is breaching a target's systems—the digital equivalent of finding an underground passageway to a bank's vaults. Phishing emails can insert malicious code. North Korean operatives pose as recruiters and entice software developers to open infected files during fake job interviews. Another approach involves using fake identities to get hired at remote IT jobs with foreign companies, which can be a first step to accessing accounts. 'They've become really good at finding vulnerabilities through social engineering," says Andrew Fierman of Chainalysis. In the ByBit case, hackers compromised the computer of a developer working for a provider of digital wallet software.
Once stolen, the cryptocurrency has to be laundered. Dirty money is spread across multiple digital wallets, combined with clean funds and transferred between different cryptocurrencies, processes known in the industry as 'mixing" and 'chain hopping". 'They're the most sophisticated crypto launderers we've ever come across," says Tom Robinson of Elliptic, a blockchain-analytics firm. Finally, the stolen funds need to be cashed out.
A growing array of underground services, many linked to Chinese organised crime, can help with this. Fees and interdictions by law enforcement reduce the overall take, but North Korea can expect to receive 'definitely 80%, maybe 90%" of the funds it steals, says Nick Carlsen, a former FBI analyst now with TRM Labs, a blockchain-intelligence firm.
North Korea has several strengths. One is talent. This could appear counterintuitive: the country is desperately poor and ordinary citizens have severely restricted access to the internet or even computers. But 'North Korea can take the best minds and tell them what to do," says Kim Seung-joo of the school of cybersecurity at Korea University in Seoul. 'They don't have to worry about them going to work at Samsung." At the International Collegiate Programming Contest in 2019, a team from a North Korean university came eighth, beating those from Cambridge, Harvard, Oxford and Stanford.
Those talents are also exploited. North Korean hackers work around the clock. They are unusually brazen when they strike. Most state actors seek to avoid diplomatic blowback and 'operate like they're in Ocean's 11: white gloves, get in without anyone noticing, steal the crown jewel, get out without being noticed," says Jenny Jun of the Georgia Institute of Technology. North Korea does not 'place a premium on secrecy—they're not afraid to be loud."
For the North Korean regime, stolen crypto has become a lifeline, especially as international sanctions and the covid-19 pandemic crimped their already limited trade. Crypto-thievery is a more efficient way to earn hard currency than traditional sources, such as overseas labourers or illegal drugs. The United Nations Panel of Experts (UNPE), a monitoring body, reported in 2023 that cyber-theft accounted for half of North Korea's foreign-currency revenue. North Korea's digital plunder last year was worth more than three times the value of its exports to China, its main trade partner. 'You take what took millions of labourers, and you can replicate that with the work of a few dozen people," says Mr Carlsen.
Those funds prop up the regime. Hard currency is used to purchase luxury goods to keep elites in line. It also probably funds weapons. The majority of North Korea's stolen crypto is thought to flow into its missile and nuclear-weapons programmes.
Cryptocurrency investigators are getting better at tracking stolen funds along the blockchain. Mainstream cryptocurrency exchanges and stable-coin issuers often co-operate with law enforcement to freeze stolen funds. In 2023 America, Japan and South Korea announced a joint effort aimed at countering North Korean cybercrime. America has sanctioned several 'mixing" service providers that North Korea has used.
Yet authorities remain a step behind. After America sanctioned North Korea's favoured mixers, the hackers switched to others offering similar services. Tackling the problem requires multilateral efforts across governments and the private sector, but such collaboration has been fraying. Russia used its UN veto to gut the UNPE last year. President Donald Trump's cuts to American development aid have hit programmes aimed at building cyber-security capacity in vulnerable countries.
By contrast, the North Korean regime is throwing ever more resources at cybercrime. South Korea's intelligence services reckon its cybercrime force grew from 6,800 people in 2022 to 8,400 last year. As the crypto-industry expands in countries with weaker regulatory oversight, North Korea has an increasingly 'rich target environment", says Abhishek Sharma of the Observer Research Foundation, an Indian think-tank. Last year, Mr Sharma notes, North Korea attacked exchanges based in India and Indonesia.
North Korea is already known to be making use of artificial intelligence in its operations. AI tools can help make phishing emails more convincing and easier to produce at scale across many languages. They can also make it easier to infiltrate companies as remote tech workers. Bad days like Mr Zhou's may become increasingly typical.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Cryptocurrency Live News & Updates : Ethereum Surges as Institutions Diversify Investments
Cryptocurrency Live News & Updates : Ethereum Surges as Institutions Diversify Investments

Economic Times

time14 minutes ago

  • Economic Times

Cryptocurrency Live News & Updates : Ethereum Surges as Institutions Diversify Investments

07 Aug 2025 | 01:15:11 AM IST Ethereum's value has surged 64.38% in 90 days, driven by rising institutional interest, while Bitcoin's growth remains modest at 10.72%. Major firms are diversifying their crypto holdings beyond Bitcoin, with BitMine emerging as a significant Ethereum holder. In recent developments, Ethereum has outperformed Bitcoin, rising 64.38% over the past 90 days, largely due to increasing institutional interest. Notably, firms are diversifying their crypto portfolios, with BitMine becoming the largest corporate holder of Ethereum at $2.9 billion. Meanwhile, the IBIT ETF, linked to Bitcoin, has seen a decline in inflows, reflecting a broader trend in the market. The ETF recorded a net outflow of $77 million, despite being the most successful ETF launch in history. In the legal arena, Roman Storm, associated with Tornado Cash, was convicted of operating an unlicensed money transmitter, although jurors could not agree on more serious charges, highlighting the complexities of applying traditional laws to decentralized technologies. Additionally, the Ethereum Foundation is making strides in Layer 1 scaling efforts, aiming to enhance the network's capacity and efficiency. As these developments unfold, the crypto landscape continues to evolve, with Ethereum gaining traction as a preferred asset among institutional investors. Show more

Trump administration sanctions Mexican rapper over allegations of cartel ties
Trump administration sanctions Mexican rapper over allegations of cartel ties

India Today

time41 minutes ago

  • India Today

Trump administration sanctions Mexican rapper over allegations of cartel ties

The Trump administration announced on Wednesday that it was sanctioning Mexican musician Ricardo Hernndez, known as 'El Makabelico,' over allegations that the artist was laundering money for a drug move comes after the administration stripped the visas of some of Mexico's most famous musicians, targeting those whose genres often explore themes related to US Treasury Department has taken action against the musician who is also identified as a "narco-rapper," for his alleged ties to the Cartel del Noreste (CDN), which evolved from the Zetas Cartel. The musician, named Hernndez, is accused of laundering money for the criminal organisation through his concerts and events. The CDN is among several Latin American crime groups designated as foreign terrorist organisations by the Trump According to the Treasury Department's allegations, Hernndez has been sanctioned because he is believed to be acting for or on behalf of the CDN. The department claims that half of his streaming royalties are funnelled directly to the cartel. The sanctions also extend to leaders of the has however, not been an official response from the rapper about the sanctions imposed on FROM THE TREASURY DEPARTMENT'CDN depends on these alternative revenue streams and money laundering methods to boost their criminal enterprise, diversifying their income beyond criminal activity like drug trafficking, human smuggling, and extortion," wrote the Treasury Department in a news release."The Treasury Department will continue to be relentless in its effort to put America First by targeting terrorist drug cartels. These cartels poison Americans with fentanyl and conduct human smuggling operations along our southwest border," said U.S. Treasury Secretary Scott US Treasury Department also took it to their social media handle on X to announce the sanctions on the rapper along with three high-ranking members of the Treasury's Office of Foreign Assets Control sanctioned three high-ranking members of the Mexico-based terrorist organization Cartel del Noreste (CDN), along with narco-rapper El narco-rapper's concerts and events are used to launder money on behalf of CDN,— Treasury Department (@USTreasury) August 6, 2025THE SANCTIONThe sanctions imposed will result in blocking the rapper's properties in US and freeze financial transactions with any businesses owned by those sanctioned, and threaten secondary sanctions against foreign financial institutions that do business with recent years, emerging artists like Peso Pluma have propelled Mexican music genres onto the global stage by blending traditional sounds with trap and other contemporary influences, rivalling international stars such as Taylor Swift and Bad Bunny on streaming genres — particularly 'narco-corridos' — have sparked much controversy, as many performers reference drug cartels and the broader 'narco culture.' While some tracks glorify criminal figures, others reflect the difficult realities faced by youth in cartel-dominated regions, drawing parallels to themes often explored in American style of music has been at the heart of ongoing debates over the boundaries between free artistic expression and censorship, with several Mexican states previously prohibiting live performances of certain ADMINISTRATION'S PREVIOUS STEPSadvertisementIn recent months, the Trump administration has taken action by revoking visas for several artists associated with the genre. In May, the well-known northern Mexican group Grupo Firme, which has worked to move away from cartel-related content, announced the cancellation of a planned California concert due to visa April, the administration said it was revoking the visas of the band Alegres de Barranco after they flashed the face of a cartel boss behind them at a concert, prompting a controversy and even criminal investigations in Mexico.- EndsWith inputs from agencies

Manipur: Thadou, Meitei groups meet in Imphal to restore peace
Manipur: Thadou, Meitei groups meet in Imphal to restore peace

Time of India

time42 minutes ago

  • Time of India

Manipur: Thadou, Meitei groups meet in Imphal to restore peace

In a significant step towards restoring peace in Manipur , a civil society organisation representing the Thadou tribe held a closed-door meeting with prominent Meitei-based civil groups in Imphal on Wednesday, officials said. Over 13 representatives of the Thadou Inpi Manipur met members of the Coordination Committee on Manipur Integrity, Arambai Tenggol, All Manipur United Clubs Organisation, and other groups at a hotel in Imphal. Productivity Tool Zero to Hero in Microsoft Excel: Complete Excel guide By Metla Sudha Sekhar View Program Finance Introduction to Technical Analysis & Candlestick Theory By Dinesh Nagpal View Program Finance Financial Literacy i e Lets Crack the Billionaire Code By CA Rahul Gupta View Program Digital Marketing Digital Marketing Masterclass by Neil Patel By Neil Patel View Program Finance Technical Analysis Demystified- A Complete Guide to Trading By Kunal Patel View Program Productivity Tool Excel Essentials to Expert: Your Complete Guide By Study at home View Program Artificial Intelligence AI For Business Professionals Batch 2 By Ansh Mehra View Program

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store