TLDR
North Korea-linked hackers stole about $2.02 billion in crypto in 2025, bringing their all-time haul to roughly $6.75 billion since 2016 per a recent report (Chainalysis summary).
- The years biggest single incident was the Bybit breach at about $1.4$1.5 billion (report).
- DPRK accounted for about 76% of service-level hacks in 2025 (analysis).
- Laundering tends to follow a ~45-day window using brokers, bridges, and mixers (details).
Deep Dive
1. Record Year and Running Total
North Korea set a new annual record with about $2.02 billion stolen in 2025.
- The same report pegs the all-time total at roughly $6.75 billion since 2016, highlighting fewer incidents but larger, targeted breaches (report).
- Multiple media recaps corroborate the 2025 figure, describing a shift to precision attacks that maximize impact (overview).
The risk is concentrated in fewer but larger events, so single points of failure at custodians or service providers matter more than ever.
2. Largest Single Heist
The Bybit incident was the standout event and reportedly contributed about $1.4$1.5 billion of 2025s losses.
- Coverage indicates it was the largest crypto exchange theft to date, making up a large share of the years total (recap).
- Follow-on reporting notes how funds moved across wallets and mixers in waves in the weeks after the breach (context).
Centralized service compromises can dominate the yearly loss tally. Monitoring custody controls and key management is critical.
3. Methods and Laundering Patterns
DPRK groups leaned on human-centric infiltration and sophisticated post-theft laundering.
- Analysts describe infiltration via hired IT workers and recruiter impersonation, alongside social engineering such as fake Zoom workflows tied to hundreds of millions stolen across victims (expert interview, campaign details).
- Laundering typically unfolds over about 45 days, split into smaller tranches and routed through mixers, OTC brokers, bridges, and guarantee services (analysis).
People, processes, and remote work vectors are prime targets. Verification outside chat apps, strict access gating, and multi-operator checks reduce the odds of compromise.
Conclusion
In 2025, DPRK-linked actors stole about $2.02 billion, driven by fewer but larger breaches like the Bybit case. Their $6.75 billion cumulative tally underscores how human-centric infiltration and coordinated laundering can overwhelm technical defenses. The practical takeaway is to focus on centralized custody controls, vigilant identity and access management, and stronger social engineering countermeasures.
