North Korean crypto attacks rising in sophistication, actors — Paradigm
North Korean cyberwarfare attacks on the cryptocurrency industry are growing in sophistication and in the number of groups involved in such criminal activity, crypto firm Paradigm warns in report titled “Demystifying the...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
North Korean cyberwarfare attacks on the cryptocurrency industry are growing in sophistication and in the number of groups involved in such criminal activity, crypto firm Paradigm warns in report titled “Demystifying the North Korean Threat.”
North Korea-originated cyberattacks range from assaults on exchanges and social engineering attempts to phishing attacks and complex supply chain hijacks, the report says. In some cases, the attacks take a year to play out, with North Korean operatives biding their time.
The United Nations estimates that between 2017 and 2023, North Korean hackers have netted the country $3 billion. The total haul has skyrocketed in 2024 and this year, with successful attacks against crypto exchanges WazirX and Bybit, which together netted attackers around $1.7 billion.
Paradigm writes that the North Korean organizations orchestrating these attacks number at least five: Lazarus Group, Spinout, AppleJeus, Dangerous Password, and TraitorTrader. There is also a coalition of North Korean operatives who pose as IT workers, infiltrating tech companies around the world.
Related: Typosquatting in crypto, explained: How hackers exploit small mistakes
High-profile attacks and predictable laundering methodsLazarus Group, the most well-known North Korean hacking team, is given credit for some of the most high-profile cyberattacks since 2016. According to Paradigm, the group hacked Sony and the Bank of Bangladesh in 2016 and helped orchestrate the WannaCry 2.0 ransomware attack in 2017.
It has also taken aim at the cryptocurrency industry, sometimes to great effect. In 2017, the group hit two crypto exchanges — Youbit and Bithumb. In 2022, Lazarus Group exploited the Ronin Bridge, resulting in hundreds of millions in lost assets. And in 2025, it infamously stole $1.5 billion from Bybit, sending shock throughout the crypto community. The group may be behind some Solana memecoin scams.
As Chainalysis and other organizations have explained, Lazarus Group also has predictable money laundering methods after securing a haul. It breaks up the stolen amount into smaller and smaller pieces, sending them to countless other wallets.
It then swaps the more illiquid coins for those with higher liquidity and converts much of it to Bitcoin (BTC). After that, the group may sit on the stolen money for a long period of time until the attention from law enforcement dies down.
The FBI has so far identified three alleged members of the Lazarus Group, accusing them of cybercrimes. In February 2021, the US Justice Department indicted two of those members for involvement in global cybercrimes.
Magazine: Lazarus Group’s favorite exploit revealed — Crypto hacks analysis
Why this matters
This cryptocurrency story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on CointelegraphRelated market context
Coinbase pushes beyond crypto with retail access to $2.2 billion Oura IPO
Coinbase has expanded its push beyond crypto by giving eligible US customers access to IPO shares at the offer price before public...
Jameson Lopp launches interactive dashboard mapping 360 physical Bitcoin attacks worldwide
The dashboard highlights the urgent need for enhanced physical security measures in the crypto industry, influencing future safety...
Bitcoin hits $86,000 putting ETF investors back in profit after $86 billion wipeout
Bitcoin’s rally toward $86,000 has pushed US spot exchange-traded fund (ETF) investors back into profit after months underwater. D...
Russian Crypto Industry Could Be Operating Legally by Year-End: Central Bank
Bitcoin Magazine Russian Crypto Industry Could Be Operating Legally by Year-End: Central Bank Russia’s crypto industry may have al...
Binance faces second probe over Iran-linked billions
US officials are probing Binance again as they try to uncover whether or not the Dubai-based crypto exchange knowingly allowed Ira...
Infosys partners with Chainlink to bring onchain finance to 1.7 billion bank accounts
This partnership could significantly accelerate blockchain adoption in global finance, enhancing transparency, interoperability, a...