TLDR
The U.S. Department of Justice said it seized about $15.1 million in Tether (USDT) tied to North Korean hackers, with forfeiture proceedings underway to return funds to victims, per a recent report. See the report.
- The funds are linked to APT38, North Koreas hacking unit, and 2023 crypto platform breaches.
- The FBI seized the USDT in March 2025, and DOJ is pursuing forfeiture.
- Separate from a Thai and U.S. Secret Service case that seized an additional $12 million USDT in Southeast Asia scams (case).
Deep Dive
1. APT38 Link
The confiscated USDT is tied to APT38, a North Korean state-backed hacking group, and traced back to four overseas crypto platform breaches in 2023. Coverage notes the DOJ connected the funds to those incidents and ongoing laundering activity by APT38 across bridges, mixers, and OTC routes. See a policy brief.
The amount is modest versus historical hacks, but it signals persistent, targeted tracing of APT38 flows.
2. Seizure vs Forfeiture
According to the report above, the FBI seized the USDT in March 2025. The DOJ has now filed civil forfeiture actions seeking court approval to permanently forfeit the assets so they can be returned to victims. This distinction matters: seizure is the law enforcement hold, while forfeiture finalizes government custody for restitution.
Expect a lag between technical seizure and final disposition. For victims, the forfeiture step is what enables repayment.
3. Other Seizures Not DOJ
There are parallel actions not led by DOJ that involve USDT. For example, Thai authorities with the U.S. Secret Service seized about $12 million USDT in a transnational scam case, aided by analytics from Tether. That operation is documented in a case update.
Headlines can blur different agencies and jurisdictions. The DOJs action is the $15.1 million USDT case; other USDT seizures may be separate operations and should not be conflated.
Conclusion
Answering your question directly, the DOJ action refers to about $15.1 million USDT tied to North Korean-linked hacks, seized earlier and now in forfeiture proceedings to return to victims. The broader takeaway is steady progress in tracking and clawing back stablecoins used in cybercrime, with multiple agencies conducting distinct operations that may appear similar but are separate in scope and jurisdiction.
