TRM Labs: North Korea-affiliated hackers were responsible for almost a third of all crypto thefts in 2023, stealing $600M+, which is ~30% less than in 2022
Context & Ripple Effects
TRM’s estimate follows a 2022 record for crypto hacking, when Chainalysis reported $3.8B stolen, chiefly from DeFi protocols and North Korea-tied actors. The decline in the attributed amount does not remove the significance of one actor group accounting for such a large share of losses.
The report makes actor attribution—not just aggregate theft totals—a central risk signal for crypto businesses, law enforcement, and the blockchain-monitoring firms serving them.
First-order effects
- TRM Labs’ attribution concentrates immediate attention on North Korea-affiliated groups as a leading source of crypto-theft risk, rather than treating losses as a diffuse cybercrime problem.
- Exchanges, protocols, and investigators gain a more defined basis for prioritizing transaction tracing and incident response around wallets and laundering routes associated with those actors.
Second-order effects
- A concentrated, state-linked threat increases the value of blockchain-intelligence providers and of information-sharing between platforms and law enforcement.
- DeFi protocols and other crypto services face stronger incentives to make security controls and suspicious-fund monitoring part of their operating model, not solely a post-hack recovery task.
Third-order effects
- If theft remains concentrated among a small set of state-linked actors, crypto security risk becomes a persistent infrastructure and compliance cost that can widen the sector’s legitimacy gap.
- Later coverage of North Korea’s growing share of 2024 theft losses and a record attributed haul in 2025 suggests that a one-year decline in 2023 may not by itself indicate a durable reduction in the threat.
The trend: Crypto is moving toward an operating model in which on-chain transparency and monitoring partnerships are essential defenses against recurring, state-linked theft.