/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Group-IB report: $882M worth of cryptocurrency has been stolen from exchanges since Jan. 2017; $571M was allegedly stolen by North Korea-linked Lazarus group

David Canellis / The Next Web :

The Next Web David Canellis

Context & Ripple Effects

Group-IB's tally is one of the earliest attempts to size exchange theft as a single problem rather than a string of incidents — and its headline finding is attribution: of $882M taken since January 2017, $571M is pinned on North Korea-linked Lazarus. That reframes exchange hacking from opportunistic crime to a sanctions-evasion revenue stream for a sanctioned state.

The years since have validated the report's scale and sharpened its focus. Chainalysis later counted a record $3.8B stolen in 2022 alone, largely by North Korea-tied hackers (2022's record hacking year), the Treasury tied Lazarus to the $600M+ Ronin bridge theft, and Bybit's 2025 cold-wallet breach reached an estimated $1.5B (Bybit's $1.5B hack) — with Elliptic noting Lazarus now shifting toward centralized services.

First-order effects

  • Exchanges are directly in the crosshairs: Group-IB's numbers make them the primary target class, forcing immediate investment in custody architecture and withdrawal controls at every named and unnamed venue.
  • Attribution to Lazarus converts each breach into a geopolitical event — US Treasury action against North Korea-linked actors becomes the enforcement channel, as later seen with the Ronin case.

Second-order effects

  • Security vendors and blockchain-analytics firms gain a durable market: Chainalysis, CipherTrace, Elliptic, and Group-IB all built tracking franchises on exactly this attribution work, and exchanges become their captive customers.
  • As exchange defenses harden, attackers migrate along the asset chain — toward bridges like Ronin and DeFi protocols, then back to centralized services per Elliptic's 2023 finding — keeping the whole ecosystem on a defensive treadmill.

Third-order effects

  • If the pattern holds, state-directed crypto theft becomes institutionalized as a sanctions-evasion budget line: North Korea reportedly stands up dedicated units like Research Center 227 for AI-based hacking, meaning the threat scales with state investment rather than criminal opportunity.
  • Structurally, the industry drifts toward regulated, insured custody concentrated in fewer hands, because repeated nine-figure losses make self-run hot wallets commercially untenable — while laundering channels like Tornado Cash draw their own regulatory crackdowns.

The trend: Cryptocurrency theft is consolidating from scattered criminal hacks into a state-funded industry, with North Korea-linked groups scaling from exchange breaches toward bridges, DeFi, and laundering infrastructure faster than defenses or sanctions can close the gap.