Elliptic: North Korean hackers stole $2.3B in crypto from businesses from 2017 to 2022, including $721M from Japan, $497M from the US, and $281M from Hong Kong
Study finds Japan's $721m loss accounts for 30% of global total since 2017 — According to the Japan External Trade Organization …
Context & Ripple Effects
This Elliptic study, compiled with the [[a:none|Japan External Trade Organization]], established the baseline that later coverage keeps measuring against: between 2017 and 2022 North Korean actors took $2.3B from crypto businesses, with Japan alone absorbing $721M — 30% of the global loss. The country breakdown matters because it maps the victims onto the exact jurisdictions that later coordinated a diplomatic response.
What came after shows the problem compounded rather than receded: TRM Labs logged a temporary dip to roughly $600M in 2023, but Chainalysis and TRM both report the totals climbing to records by 2024-2025 — making this 2017-2022 figure the floor of an escalating arc, not the peak.
First-order effects
- Businesses holding crypto in Japan, the US ($497M), and Hong Kong ($281M) were the direct victims, and the JETRO-linked finding gives Japanese regulators a domestic-loss number to justify action rather than treating theft as a foreign abstraction.
- Security teams at exchanges and custodians in those three markets now face country-attribution pressure: the concentration of losses in Japan makes local compliance and custody standards the immediate battleground.
Second-order effects
- The geographic pattern in this data is what made trilateral coordination viable — the US, Japan, and South Korea later issued a joint statement attributing $659M+ of 2024 heists to Pyongyang, including the WazirX hack, turning a chain-analytics finding into shared policy ground.
- Exchanges and wallet providers competing for institutional business in these markets face pricing power shifting toward vendors who can demonstrate attribution-aware security, since a third of global losses traced to one state actor becomes a procurement criterion.
Third-order effects
- If the trajectory holds — cumulative stolen totals reaching $6.75B by 2025 per Chainalysis/TRM tracking, with single months like April 2026 accounting for 76% of hack losses — crypto theft hardens into a sanctions-and-cyber-policy problem where exchange security posture is effectively national infrastructure.
- The persistent gap between reported thefts and recovered funds pushes regulators in the hardest-hit jurisdictions (Japan foremost) toward custody rules that treat self-hosted and exchange-held assets asymmetrically, reshaping which platforms can operate there.
The trend: North Korea's crypto theft has scaled from a chain-analytics reporting problem into a recurring geopolitical flashpoint, with Japan, the US, and South Korea coordinating responses as annual losses set successive records.