North Korean hackers stole a record $2.02B in crypto in 2025, a 51% YoY rise that takes its cumulative stolen total to $6.75B; individual wallet hacks hit 158K
TL;DR — North Korean hackers stole $2.02 billion in cryptocurrency in 2025, a 51% year-over-year increase …
Context & Ripple Effects
The reported 2025 total follows a first half in which the DPRK-linked Bybit theft alone reached $1.5 billion, within more than $2.17 billion taken from crypto services overall. That exceptionally large first-half breach had already pushed annual crypto-security losses beyond the prior year’s full-year level.
It also extends a longer concentration of crypto theft linked to North Korea: Chainalysis had put the group’s decade-long total above $6 billion and said it accounted for more than 60% of 2024 theft losses. The new cumulative figure and 158,000 compromised wallets indicate both large-service attacks and broad retail exposure remain material.
First-order effects
- Crypto users tied to the 158,000 compromised wallets face immediate asset-loss and account-security consequences, while affected platforms must investigate, contain, and support recovery efforts.
- North Korea-linked operators’ reported 2025 haul rises to $2.02 billion, cementing the already dominant share of 2024 crypto theft losses as an escalating risk for the sector.
Second-order effects
- Exchanges, wallet providers, and DeFi services are likely to prioritize stronger transaction monitoring, wallet-security controls, and incident response around attack paths associated with large thefts and individual-wallet compromises.
- The scale of losses raises the cost of serving higher-risk transactions: compliance and security vendors gain urgency, while platforms may impose more friction on transfers or account access to limit exposure.
Third-order effects
- If repeated, concentrated state-linked theft will make security resilience and traceability a more central competitive requirement for crypto intermediaries, rather than a back-office compliance function.
- The mix of major service breaches and widespread wallet compromises suggests the industry’s risk model must cover both institutional custody failures and end-user security; the relative importance of each remains unclear from this report alone.
The trend: Crypto’s security challenge is shifting toward persistent, state-linked adversaries whose attacks span both major platforms and individual users.