October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

North Korea-linked hackers stole an estimated $2 billion in cryptocurrency during 2025

North Korea-linked cyber actors stole an estimated $2.02 billion in cryptocurrency during 2025, with the $1.46 billion Bybit exploit driving roughly 72% of the total.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

North Korea-linked cyber actors stole an estimated $2.02 billion in cryptocurrency during 2025, according to a Chainalysis figure reported in January 2026. Elliptic had already estimated more than $2 billion by October 7, 2025, while three months remained. These are analytical estimates of cryptoassets attributed to North Korean operations—not audited government accounts, and not proof that the full amount was converted to spendable cash.

What the $2 billion estimate measures

The total is the estimated dollar value of cryptoassets taken in attacks that investigators attributed to North Korea-linked actors. Valuation can change as token prices move and as analysts revise incident totals. “Stolen” also differs from “laundered,” “cashed out,” or “spent.” Some assets may be frozen, abandoned, recovered, or still moving through intermediaries.

Elliptic’s October estimate covered more than 30 hacks and warned that undiscovered or unattributed incidents could make the true total higher. Its methodology combines blockchain tracing with indicators from earlier North Korean operations. Elliptic’s October 2025 analysis should therefore be read as an informed industry estimate, not a precise national-accounts figure.

Bybit made up most of the record

The February 21, 2025, Bybit attack dominates the annual number. Approximately $1.46 billion in cryptocurrency was stolen, making it about 72% of the later $2.02 billion estimate. Elliptic called it the largest confirmed crypto theft in history, and the FBI attributed the operation to North Korea.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Ledger Nano X - Classic Crypto Wallet with Bluetooth
  • Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
  • Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
  • Enjoy Bluetooth connectivity, iOS access, and hours of battery use with this mobile-first, secure backup signer. Freedom you can depend on.
  • Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.
  • Protect your signer: keep it in mint condition at all times with a bespoke Pod or Case to avoid scratches and everyday wear and tear.

The scale matters: the record year was driven by one exceptionally large exchange compromise plus many smaller incidents, not by thousands of similarly sized wallet attacks. Elliptic’s Bybit investigation details the loss and attribution.

A broader campaign included dozens of incidents

Elliptic named losses involving LND.fi, WOO X and Seedify and said it had attributed more than 30 additional 2025 hacks to North Korea-linked activity. The available evidence does not provide a complete incident-by-incident list or a separate total for each named victim. An unattributed crypto theft should not be added to the North Korean total merely because it resembles an earlier Lazarus Group pattern.

Measure Amount or finding Qualification
Elliptic estimate More than $2 billion Published October 7, 2025, with roughly three months left in the year
Chainalysis estimate Approximately $2.02 billion Reported in January 2026 as the full-year 2025 figure; 51% higher than 2024
Bybit theft Approximately $1.46 billion February 21, 2025; about 72% of the $2.02 billion estimate
Previous Elliptic annual record Approximately $1.35 billion 2022
Known cumulative theft since 2017 More than $6 billion Elliptic accounting; totals can change as cases are revised

Why investigators attribute attacks to North Korea

Attribution is built from several clues rather than a single identifying signature:

Rank #2
Sale
TANGEM Crypto Wallet Pack of 3 – Trusted Cold Storage Hardware Wallet
  • Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
  • Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
  • Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
  • Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
  • Trusted by 6 million users worldwide (4.9 App Store, 4.8 Google Play) - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets
  • Blockchain movements and recurring laundering patterns.
  • Reuse of wallets or links to addresses previously associated with North Korean operations.
  • Malware, infrastructure and coding overlaps.
  • Similar tactics to earlier Lazarus-linked campaigns.
  • Intelligence assessments and, in the Bybit case, the FBI’s public conclusion.

These evidence levels are not identical. A government attribution, a commercial analytics assessment and a probable identification carry different confidence. “North Korea-linked” or “investigators attributed to North Korea” is more accurate than claiming that every theft was personally conducted by the North Korean government.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The attackers increasingly target people, not just code

Elliptic said social engineering accounted for most 2025 losses, marking a shift from attacks focused primarily on technical flaws in crypto infrastructure. High-value individuals were targeted alongside exchanges.

Common approaches

  • Fake employment, recruitment or investment approaches carrying malicious “technical tests.”
  • Impersonation of colleagues, investors, vendors or business partners.
  • Phishing that captures credentials or causes a user to connect and approve a wallet.
  • Manipulation of developers, traders or signing personnel into authorizing transfers.
  • Malware aimed at a workstation used to manage keys or transactions.

A blockchain can be secure while a person is deceived into signing a harmful transaction. That is why employee verification, device hygiene and approval procedures matter as much as smart-contract security.

Rank #3
TANGEM Crypto Wallet Pack of 2 – Trusted Cold Storage Hardware Wallet
  • Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
  • Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
  • Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
  • Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
  • Trusted by 6 million users worldwide - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets

How the Bybit proceeds moved

Elliptic’s investigations found the stolen assets rapidly distributed across many wallets and converted among tokens, including Ether and Bitcoin. Investigators observed decentralized exchanges, cross-chain bridges, mixers, privacy services and less-covered blockchains. A “refund address” manipulation scheme and trades involving worthless tokens also obscured the trail. Suspected over-the-counter brokers provided another route toward conversion.

By August 2025, Elliptic estimated that more than $1 billion of the Bybit proceeds had been laundered. It also estimated that more than $200 million passed through eXch, a no-KYC service later reported as shut down. The six-month Bybit analysis and eXch report describe those findings without establishing that every dollar reached fiat markets.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Crypto is traceable, but tracing does not guarantee recovery

Public blockchains preserve transaction histories, allowing analysts to follow funds across addresses and, sometimes, identify service providers that can freeze them. The same transparency helps connect new attacks to old ones.

Rank #4
DCENT Hardware Wallet | Biometric Cold Storage, Bluetooth, Multi-Crypto
  • EAL5+ CERTIFIED SECURE ELEMENT + FINGERPRINT PROTECTION — Your private keys stay encrypted offline on a certified EAL5+ chip, the same security tier used in EMV bank cards. Built by DCENT, securing crypto since 2018. Fingerprint authentication adds a second layer no PIN-only wallet can match.
  • 10,000+ ASSETS NATIVE ON 100+ BLOCKCHAINS — Hold Bitcoin, Ethereum, XRP, Solana, Cardano, popular stablecoins (USDT, USDC), and NFTs in one wallet. No third-party apps, no fragmented setup — every supported asset works straight out of the box.
  • TAP-TO-SIGN MOBILE EXPERIENCE — Pair your wallet with the DCENT mobile app over Bluetooth. Manage tokens, review transactions, and access in-app swap features directly from your phone — no cables, no desktop required.
  • WEB3 & dAPP ACCESS VIA METAMASK — Connect to MetaMask and other browser extension wallets to manage NFTs, claim airdrops, and access dApps. A large screen and intuitive 4-button interface keep every transaction clearly visible before you sign.
  • SEAMLESS FIRMWARE UPDATES & 30-DAY MONEY-BACK GUARANTEE — Apply security updates without resetting your wallet or migrating funds. Backed by Amazon's 30-day money-back guarantee — your purchase is risk-free.

Tracing becomes harder when criminals split transactions, move across chains, use mixers or privacy tools, and rely on offshore or decentralized services. A visible transaction is not automatically recoverable money. Centralized exchanges may cooperate with freezes or seizures, while services outside effective regulatory reach can delay intervention.

What officials say the money supports

U.S. and international officials have repeatedly assessed that North Korea uses cybercrime revenue and other illicit income to evade sanctions and support regime priorities, including ballistic-missile and weapons-of-mass-destruction programs. January 2026 reporting cited a U.S. official who said laundering networks operated through countries including China, Russia, Cambodia and Vietnam. That report describes an official assessment, not a transaction-by-transaction finding that every stolen dollar paid for a particular weapon.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How users and organizations can reduce exposure

For individual holders

  • Keep substantial long-term holdings in a hardware wallet, while recognizing that a hardware device cannot stop a user from approving a malicious transaction.
  • Store seed phrases offline and separately from signing devices; never share them.
  • Do not install software or run code supplied by an unsolicited recruiter, investor or online contact.
  • Check the recipient, network and amount on the signing device itself, not only on a computer screen.
  • Use separate wallets for long-term holdings and experimental DeFi activity.
  • Treat unexpected token approvals and wallet prompts as high risk, and revoke unnecessary approvals through a reputable tool.
  • Use exchange withdrawal allowlists and strong, security-key-based account protection where available.

For exchanges, companies and treasury teams

  • Require multiple approvals and independent, out-of-band verification for high-value transfers.
  • Separate signing devices, administrative accounts and operational funds.
  • Train staff to recognize recruitment, impersonation and malicious-code scenarios.
  • Use transaction monitoring and wallet-screening systems to flag sanctions and laundering exposure.
  • Review policies for bridges, mixers, privacy services and unfamiliar assets before allowing transfers.
  • Maintain an incident plan that includes rapid key rotation, exchange notifications and blockchain tracing.

Multisignature custody reduces the risk of one compromised person, but it can still fail if several signers are socially engineered. Simulation and screening tools also reduce risk without guaranteeing that a transaction or contract is safe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Trezor Safe 7 Crypto Hardware Wallet with Bluetooth for Android/iOS/Desktop
  • Dual-chip architecture for maximum protection: The next-gen, fully auditable TROPIC01 chip works alongside a certified EAL6+ Secure Element—completely NDA-free—to deliver radically transparent, industry-leading defense against physical attacks.
  • Quantum-ready security: Get protection against future threats with the first-ever hardware wallet designed with quantum-ready architecture.
  • See every detail with confidence: Our largest high-resolution color touchscreen makes it easy to navigate your assets, review transactions and manage your coins with clarity.
  • Wireless freedom with encrypted Bluetooth control: Manage, buy, swap and stake securely using Trezor Suite on desktop or mobile. Qi2-compatible wireless charging keeps your Trezor powered up. No cables required—security meets convenience.
  • Works seamlessly with Android, iOS and desktop: Connect wirelessly or via USB-C to your phone or computer. Manage your crypto anywhere with our companion Trezor Suite app.

How to interpret the competing totals

Elliptic’s October figure and Chainalysis’s later $2.02 billion estimate are broadly consistent, but firms can count differently. Differences may reflect attribution thresholds, whether scams are included, the date used to value tokens, when an incident becomes public, and newly discovered historical cases. A later revision would not necessarily mean an earlier analyst was wrong; it may reflect better evidence or changed prices.

The most defensible conclusion is that North Korea-linked actors reached a record level of crypto theft in 2025, with the best available full-year estimate near $2.02 billion and the Bybit exploit responsible for most of it. The number is credible as an industry assessment, but it remains an estimate that can change as attribution and asset tracing develop.

Quick Recap

Bestseller No. 1
Ledger Nano X - Classic Crypto Wallet with Bluetooth
Ledger Nano X - Classic Crypto Wallet with Bluetooth
Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.; Product color may vary slightly from pictures due to manufacturing process.
$99.00

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.