North Korean hackers, associated with the Democratic People’s Republic of Korea and often discussed in the context of the Lazarus Group, APT38, and Kimsuky, stole $643 million in cryptocurrency in the first six months of 2026. According to TRM Labs, this accounts for 66.2% of the global losses from hacker thefts of digital assets, which reached $972 million.
Image source: Kevin Horvat/
Who Is Behind North Korean Cyberattacks
North Korean hackers usually refers to cyber groups linked to the interests of the DPRK. Globally, they are known for attacks on crypto services, financial organizations, and IT infrastructure, and their reputation is built on a combination of technical hacks, phishing, and social engineering.
- The Lazarus Group is most often mentioned alongside major crypto thefts and attacks on digital assets.
- APT38 is associated with financially motivated operations against banks, payment systems, and crypto platforms.
- Kimsuky is known for operations where intelligence gathering, information collection, and targeted social engineering are important.
Candidates for such operations are usually selected from strong students with good math, programming, and language skills. Further training focuses on computer networks, operating systems, vulnerability discovery, malware development, and methods of deceiving employees or users.
TRM Labs: Lower Amount Does Not Mean Reduced Threat
TRM Labs analysts emphasize: the reduction in the amount of stolen funds should not be seen as a sign that North Korean cyber groups have become less dangerous. In their assessment, there were simply fewer truly large-scale attacks in 2026 than the previous year.
Cryptocurrency remains an attractive target for such operations: a single successful hack of an online digital currency exchange service, exchange, or decentralized finance protocol can bring attackers hundreds of millions of US dollars. For platforms like Binance and Bybit, such incidents have long been not only a matter of user trust but also a computer security challenge for the entire industry.
The Largest Attacks Last Year Targeted DeFi Projects
In 2025, a significant portion of the funds stolen by North Korean hackers was linked to two April attacks on decentralized finance. The key episodes of 2025 can be quickly compared by targets and amounts:
- 2025 — Drift; attack target: decentralized derivatives exchange on Solana; platform type: DeFi project; $285 million stolen.
- 2025 — KelpDAO; attack target: Ethereum liquid restaking protocol; platform type: DeFi project; $292 million stolen.
Amid ongoing cyberwar, such crimes in the field of information technology concern not only the crypto industry but also government agencies: in the United States, such threats are handled, in particular, by the Federal Bureau of Investigation. The risks affect the global digital asset market, including companies and users in China and other countries.
The risk is also practical for Russia: crypto services, fintech companies, IT contractors, and users working with digital assets may be targeted. The likelihood is higher where there is access to crypto wallets, exchange infrastructure, or corporate accounts, and attacks can occur through phishing, malware, and social engineering.
Criminal Revenues Are Not Limited to Direct Hacks
TRM Labs clarifies that the amounts cited reflect only cryptocurrency thefts directly linked to hacker activity. Such groups have other illegal sources of income:
- Phishing.
- Cryptocurrency scam schemes.
- Using North Korean IT specialists posing as foreign employees.
In attacks, such groups may combine malware, hacks through vulnerabilities, fake emails, fake employee profiles, and pressure on people with access to money or internal systems.
Basic protection is built on simple but essential measures:
{
“@context”: “https://schema.org”,
“@type”: “Article”,
“about”: [
{
“@type”: “Organization”,
“name”: “Lazarus Group”
},
{
“@type”: “Place”,
“name”: “Democratic People’s Republic of Korea”
},
{
“@type”: “Organization”,
“name”: “TRM Labs”
},
{
“@type”: “Organization”,
“name”: “Binance”
},
{
“@type”: “Organization”,
“name”: “Bybit”
},
{
“@type”: “Organization”,
“name”: “Federal Bureau of Investigation”
},
{
“@type”: “Place”,
“name”: “United States of America”
},
{
“@type”: “Place”,
“name”: “China”
},
{
“@type”: “Thing”,
“name”: “cryptocurrency”
},
{
“@type”: “Thing”,
“name”: “computer security”
}
]
}
- Enable multi-factor authentication for crypto wallets, exchange accounts, and corporate email.
- Screen employees and contractors, especially if they get access to code, finances, or infrastructure.
- Update systems and quickly patch known vulnerabilities.
- Train employees to recognize phishing, fake job postings, attachments, and links.
- Separate access, store keys separately, and regularly check for suspicious operations.
