Group-IB report: $882M worth of cryptocurrency has been stolen from exchanges since Jan. 2017; $571M was allegedly stolen by North Korea-linked Lazarus group
David Canellis / The Next Web :
Context & Ripple Effects
Group-IB's tally is one of the earliest attempts to size exchange theft as a single problem rather than a string of incidents — and its headline finding is attribution: of $882M taken since January 2017, $571M is pinned on North Korea-linked Lazarus. That reframes exchange hacking from opportunistic crime to a sanctions-evasion revenue stream for a sanctioned state.
The years since have validated the report's scale and sharpened its focus. Chainalysis later counted a record $3.8B stolen in 2022 alone, largely by North Korea-tied hackers (2022's record hacking year), the Treasury tied Lazarus to the $600M+ Ronin bridge theft, and Bybit's 2025 cold-wallet breach reached an estimated $1.5B (Bybit's $1.5B hack) — with Elliptic noting Lazarus now shifting toward centralized services.
First-order effects
- Exchanges are directly in the crosshairs: Group-IB's numbers make them the primary target class, forcing immediate investment in custody architecture and withdrawal controls at every named and unnamed venue.
- Attribution to Lazarus converts each breach into a geopolitical event — US Treasury action against North Korea-linked actors becomes the enforcement channel, as later seen with the Ronin case.
Second-order effects
- Security vendors and blockchain-analytics firms gain a durable market: Chainalysis, CipherTrace, Elliptic, and Group-IB all built tracking franchises on exactly this attribution work, and exchanges become their captive customers.
- As exchange defenses harden, attackers migrate along the asset chain — toward bridges like Ronin and DeFi protocols, then back to centralized services per Elliptic's 2023 finding — keeping the whole ecosystem on a defensive treadmill.
Third-order effects
- If the pattern holds, state-directed crypto theft becomes institutionalized as a sanctions-evasion budget line: North Korea reportedly stands up dedicated units like Research Center 227 for AI-based hacking, meaning the threat scales with state investment rather than criminal opportunity.
- Structurally, the industry drifts toward regulated, insured custody concentrated in fewer hands, because repeated nine-figure losses make self-run hot wallets commercially untenable — while laundering channels like Tornado Cash draw their own regulatory crackdowns.
The trend: Cryptocurrency theft is consolidating from scattered criminal hacks into a state-funded industry, with North Korea-linked groups scaling from exchange breaches toward bridges, DeFi, and laundering infrastructure faster than defenses or sanctions can close the gap.