Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

US, Japan and South Korea Attribute Nearly $660 Million in 2024 Crypto Theft to North Korea

By TheFinanceBase Team6 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

On January 14, 2025, the United States, Japan and the Republic of Korea issued a joint warning saying DPRK-linked cyber actors stole approximately $660 million in cryptocurrency during 2024. The five incidents listed in the statement total $659.13 million: DMM Bitcoin ($308 million), Upbit ($50 million), Rain Management ($16.13 million), WazirX ($235 million) and Radiant Capital ($50 million).

This was a coordinated government attribution and industry warning—not a criminal indictment or court judgment. The figure covers the selected 2024 incidents identified in that statement, not every North Korean-linked theft ever. Later reporting attributed an approximately $1.5 billion Bybit theft in February 2025 to DPRK actors, so the $660 million figure is historical rather than a current cumulative total.

What the trilateral statement said

The joint statement warned the blockchain industry that North Korean cyber actors continue to target organizations and individuals worldwide. The governments said the activity threatens financial-system integrity and stability and called on exchanges, custodians, blockchain companies and freelance-work platforms to improve defenses and information sharing.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

They said their cooperation aims to prevent theft, recover stolen assets, impose sanctions and deny Pyongyang revenue that the governments assess supports North Korea’s unlawful weapons-of-mass-destruction and ballistic-missile programs. That is an official assessment; public evidence does not establish that every stolen coin was traced to a particular weapons purchase.

#1 Best Overall
Ledger Nano X - Classic Crypto Wallet with Bluetooth
  • Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
  • Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
  • Enjoy Bluetooth connectivity, iOS access, and hours of battery use with this mobile-first, secure backup signer. Freedom you can depend on.
  • Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.
  • Protect your signer: keep it in mint condition at all times with a bespoke Pod or Case to avoid scratches and everyday wear and tear.

The $660 million headline, shown precisely

Incident Amount attributed Attribution wording
DMM Bitcoin $308 million Attributed by the three governments
Upbit $50 million Attributed by the three governments
Rain Management $16.13 million Attributed by the three governments
WazirX $235 million Additionally attributed by the United States and South Korea, based on detailed industry analysis
Radiant Capital $50 million Additionally attributed by the United States and South Korea, based on detailed industry analysis
Total $659.13 million Rounded in coverage to approximately $660 million

The arithmetic is $308 million + $50 million + $16.13 million + $235 million + $50 million = $659.13 million. Crypto-loss estimates can change with valuation dates, asset prices, recovery amounts and the treatment of subsequent wallet movements, so the statement’s dollar figures should be read as reported virtual-asset values, not immutable accounting totals.

What happened in the named incidents?

DMM Bitcoin: $308 million

Japan’s DMM Bitcoin was the largest theft in the list. The trilateral statement attributed it to DPRK actors; the FBI also publicly attributed the incident to North Korea in contemporaneous reporting. The statement itself does not provide a complete technical incident report, so mechanics should not be presented as settled government findings.

Upbit: $50 million

South Korean exchange Upbit was included among the attributed 2024 incidents. The amount can vary in other accounts depending on when the stolen assets were valued.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Sale
TANGEM Crypto Wallet Pack of 3 – Trusted Cold Storage Hardware Wallet
  • Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
  • Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
  • Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
  • Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
  • Trusted by 6 million users worldwide (4.9 App Store, 4.8 Google Play) - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets

Rain Management: $16.13 million

Rain Management was included in the first group of incidents attributed in the joint statement. The document supplies the amount and attribution but not a detailed public chronology of the attack.

WazirX: $235 million

The statement uses narrower wording here: the United States and South Korea additionally attributed the theft, relying on detailed industry analysis. It should not be written as though Japan independently endorsed this incident in exactly the same evidentiary manner.

Radiant Capital: $50 million

The same U.S.–South Korean attribution language applies to Radiant Capital. Radiant and investigators described a sophisticated October 2024 attack, but those technical descriptions should remain attributed to the company or investigators rather than treated as findings in the trilateral statement.

Rank #3
TANGEM Crypto Wallet Pack of 2 – Trusted Cold Storage Hardware Wallet
  • Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
  • Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
  • Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
  • Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
  • Trusted by 6 million users worldwide - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets

What “attributed to North Korea” means

Attribution has levels. A government attribution is a formal assessment by a state, supported by intelligence and technical evidence, but it is not automatically a judicial verdict. Industry investigators may identify links through wallet movements, malware, infrastructure, coding patterns or known operational behaviors. A victim may publish its own assessment. A criminal prosecution or court finding is a different standard again.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The statement names “DPRK-affiliated threat groups, including Lazarus Group.” Lazarus is a broad threat-intelligence label, not necessarily one legal entity or one permanently unified team. Security companies and governments may use overlapping names such as TraderTraitor and AppleJeus for different layers of activity. Those labels should not be treated as interchangeable proof that one unit conducted every listed theft.

How the attacks work

The governments specifically warned about well-disguised social engineering, malware including TraderTraitor and AppleJeus, and North Korean IT-worker schemes. A common high-level sequence is:

Rank #4
DCENT Hardware Wallet | Biometric Cold Storage, Bluetooth, Multi-Crypto
  • EAL5+ CERTIFIED SECURE ELEMENT + FINGERPRINT PROTECTION — Your private keys stay encrypted offline on a certified EAL5+ chip, the same security tier used in EMV bank cards. Built by DCENT, securing crypto since 2018. Fingerprint authentication adds a second layer no PIN-only wallet can match.
  • 10,000+ ASSETS NATIVE ON 100+ BLOCKCHAINS — Hold Bitcoin, Ethereum, XRP, Solana, Cardano, popular stablecoins (USDT, USDC), and NFTs in one wallet. No third-party apps, no fragmented setup — every supported asset works straight out of the box.
  • TAP-TO-SIGN MOBILE EXPERIENCE — Pair your wallet with the DCENT mobile app over Bluetooth. Manage tokens, review transactions, and access in-app swap features directly from your phone — no cables, no desktop required.
  • WEB3 & dAPP ACCESS VIA METAMASK — Connect to MetaMask and other browser extension wallets to manage NFTs, claim airdrops, and access dApps. A large screen and intuitive 4-button interface keep every transaction clearly visible before you sign.
  • SEAMLESS FIRMWARE UPDATES & 30-DAY MONEY-BACK GUARANTEE — Apply security updates without resetting your wallet or migrating funds. Backed by Amazon's 30-day money-back guarantee — your purchase is risk-free.
  1. Reconnaissance identifies a valuable exchange, custodian, developer, trader, employee or contractor.
  2. Attackers personalize contact through a fake job, investment, technical-support or business scenario.
  3. The target is persuaded to run malicious code, open a booby-trapped file, disclose credentials, approve a transaction or connect a wallet.
  4. Attackers move assets through wallets and laundering infrastructure, often across chains and services.

Not every operation follows this exact chain. Incidents can involve compromised private keys, transaction manipulation, insider access, malware or failures in exchange and custody controls. “Hack” is therefore a convenient umbrella term, not a description of one universal technique.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

The insider threat from fake IT workers

The warning also addressed companies that hire through freelance and remote-work platforms. A worker using a false identity can obtain privileged access, influence code or deployment pipelines, exfiltrate credentials, or create an internal path to signing systems. Hiring and contractor verification are therefore part of the security perimeter.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Companies should independently verify identity documents, references, work history, payment details and location; limit privileges; require peer review; and monitor unusual access or data-transfer patterns. No single screening step is sufficient.

Best Value
Trezor Safe 7 Crypto Hardware Wallet with Bluetooth for Android/iOS/Desktop
  • Dual-chip architecture for maximum protection: The next-gen, fully auditable TROPIC01 chip works alongside a certified EAL6+ Secure Element—completely NDA-free—to deliver radically transparent, industry-leading defense against physical attacks.
  • Quantum-ready security: Get protection against future threats with the first-ever hardware wallet designed with quantum-ready architecture.
  • See every detail with confidence: Our largest high-resolution color touchscreen makes it easy to navigate your assets, review transactions and manage your coins with clarity.
  • Wireless freedom with encrypted Bluetooth control: Manage, buy, swap and stake securely using Trezor Suite on desktop or mobile. Qi2-compatible wireless charging keeps your Trezor powered up. No cables required—security meets convenience.
  • Works seamlessly with Android, iOS and desktop: Connect wirelessly or via USB-C to your phone or computer. Manage your crypto anywhere with our companion Trezor Suite app.

Practical defenses for crypto businesses

  • Use phishing-resistant, hardware-backed multifactor authentication for privileged accounts.
  • Keep signing systems isolated from ordinary laptops and developer workstations.
  • Require dual approval, allowlists, velocity limits and policy checks for withdrawals and treasury transfers.
  • Apply least privilege to employees, contractors and automation keys, with rapid revocation.
  • Sandbox downloaded repositories, interview exercises and third-party code before execution.
  • Monitor unusual address creation, transaction destinations, timing and access behavior.
  • Maintain an incident plan covering exchanges, custodians, blockchain-analytics firms and law enforcement.
  • Preserve endpoint images, authentication logs, wallet records and transaction histories for investigation and recovery.

The statement points organizations toward public-private mechanisms including Illicit Virtual Asset Notification (IVAN), Crypto-ISAC and Security Alliance (SEAL), as well as U.S.–South Korean symposiums and Japanese Financial Services Agency and industry self-inspection initiatives.

What individual users should take from the warning

Individuals are also named targets, particularly through fake investment offers, employment approaches and malware. Use a separate device or browser profile for sensitive wallet activity, never install trading software or code from an unsolicited contact, verify URLs and recruiters independently, and use hardware security keys where a service supports them. Treat any request to share a seed phrase or private key as fraudulent. These steps reduce personal exposure but cannot protect an exchange if the exchange’s own custody or signing systems are compromised.

What changed after January 2025?

The January statement is a dated account of five 2024 incidents. Later trilateral reporting from the South Korean foreign ministry described the February 2025 Bybit theft as nearly $1.5 billion and discussed additional DPRK-linked incidents. Accordingly, “$660 million” should not be presented as North Korea’s latest total crypto theft or as the total for all of 2024 unless a source expressly defines it that way.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For the original wording and incident list, read the U.S. Department of State statement. Japan’s issuance notice is available from its Ministry of Foreign Affairs, and later context appears in South Korean government reporting.

The Bottom Line

The accurate takeaway is that the United States, Japan and South Korea jointly attributed $659.13 million—rounded to $660 million—in five selected 2024 cryptocurrency thefts to DPRK-linked actors. It was a government attribution and security warning, not a court judgment, and it is no longer a complete measure of North Korea’s crypto-theft activity after larger incidents were reported in 2025.

Quick Recap

Bestseller No. 1
Ledger Nano X - Classic Crypto Wallet with Bluetooth
Ledger Nano X - Classic Crypto Wallet with Bluetooth
Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.; Product color may vary slightly from pictures due to manufacturing process.
$99.00

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.