TLDR
North Korean state groups are now using advanced AI tools to scale and automate crypto attacks, and they account for most of the worlds hacked digital asset losses.
- Hackers such as Kimsuky are running their own local AI systems to write malware, analyze stolen data, and generate highly convincing crypto-themed phishing documents.
- DPRK-linked groups have stolen billions in cryptocurrency, including a $1.5 billion Bybit hack, and recently made up about two thirds of global hacking losses.
- The rise of AI-driven attacks shifts the risk toward social engineering and operational weakness, pushing exchanges and firms to adopt AI-based defenses and stricter identity controls.
Deep Dive
1. How AI Is Used In DPRK Crypto Attacks
South Korean firm Genians reports that the Kimsuky group has built three local large language model environments (using tools like Ollama and GPT4All) to support malware development, data analysis, and attack automation without relying on cloud AI services. These systems are combined with AI coding assistants such as Cursor and speech-to-text tools to speed up exploit creation and operational workflows.
Investigators have also found Kimsuky using generative AI to produce polished phishing documents about digital assets, investment strategies, and fintech, closely mimicking legitimate business materials from real platforms. These AI-authored lures make emails and documents look professionally drafted, increasing the odds that targets at crypto and finance firms open malicious attachments or links.
Other DPRK-linked units such as BlueNoroff have used fake Zoom and Microsoft Teams meetings, with AI-generated headshots and video, to profile crypto users before delivering malware and scanning for wallets and browser extensions.
2. Scale Of North Korean Crypto Theft
A recent analysis cited by TRM Labs shows that North Korea-linked hackers stole around $643 million in cryptocurrency in the first half of 2026, roughly 66% of global digital asset losses to hacking in that period. Separate research from CertiK estimates about $2.06 billion stolen in 2025, and roughly $6.75 billion across 263 hacks since 2016.
Major incidents include the February 2025 Bybit breach, where around $1.5 billion in Ether and staked Ether was stolen and later traced across mixers and cross-chain protocols, prompting Bybit to sue North Korea and the Lazarus Group and secure asset-freezing court orders. April 2026 was described as the most hacked month in crypto history, with KelpDAO and Drift Protocol each losing over $250 million in attacks attributed to DPRK-linked actors.
Confidence: high, based on multiple independent security firm and court filings from 20252026.
3. What Crypto Firms And Users Should Watch
Experts warn that AI is mainly amplifying existing attack patterns: social engineering, fake job offers, compromised IT staff, and realistic phishing documents aimed at exchanges, protocols, and crypto investors. As a result, email filtering and endpoint security alone are not enough.
Security firms recommend measures such as video interviews with liveness checks for remote hires, stricter zero trust access to internal systems, withdrawal cooling-off periods, and AI-driven anomaly detection on documents and user behavior. Exchanges are also turning to external security audits and attack simulations, and regulators are starting to treat DPRKs crypto operations as a national security issue rather than just financial crime.
the biggest risk is not a single exploit, but an ongoing, AI-enhanced campaign targeting people and processes around crypto infrastructure, so monitoring social engineering exposure and identity controls is as important as smart contract audits.
Conclusion
North Koreas adoption of AI in crypto attacks shows how quickly offensive cyber capabilities can absorb frontier tools, turning them into scalable phishing, malware, and laundering operations. For the crypto ecosystem, the impact is already visible in the share of global losses tied to DPRK-linked hacks and in landmark legal actions such as the Bybit suits. The practical takeaway is that defenses must evolve at the same pace, with more attention on human-factor security, AI-supported detection, and coordinated responses when sophisticated, state-level actors target digital assets.
