Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
On January 14, 2025, the United States, Japan and the Republic of Korea issued a joint warning saying DPRK-linked cyber actors stole approximately $660 million in cryptocurrency during 2024. The five incidents listed in the statement total $659.13 million: DMM Bitcoin ($308 million), Upbit ($50 million), Rain Management ($16.13 million), WazirX ($235 million) and Radiant Capital ($50 million).
This was a coordinated government attribution and industry warning—not a criminal indictment or court judgment. The figure covers the selected 2024 incidents identified in that statement, not every North Korean-linked theft ever. Later reporting attributed an approximately $1.5 billion Bybit theft in February 2025 to DPRK actors, so the $660 million figure is historical rather than a current cumulative total.
What the trilateral statement said
The joint statement warned the blockchain industry that North Korean cyber actors continue to target organizations and individuals worldwide. The governments said the activity threatens financial-system integrity and stability and called on exchanges, custodians, blockchain companies and freelance-work platforms to improve defenses and information sharing.
Free tools Windows power users keep installed
One-click scans. No signup required.
They said their cooperation aims to prevent theft, recover stolen assets, impose sanctions and deny Pyongyang revenue that the governments assess supports North Korea’s unlawful weapons-of-mass-destruction and ballistic-missile programs. That is an official assessment; public evidence does not establish that every stolen coin was traced to a particular weapons purchase.
#1 Best Overall
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Enjoy Bluetooth connectivity, iOS access, and hours of battery use with this mobile-first, secure backup signer. Freedom you can depend on.
- Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.
- Protect your signer: keep it in mint condition at all times with a bespoke Pod or Case to avoid scratches and everyday wear and tear.
The $660 million headline, shown precisely
| Incident | Amount attributed | Attribution wording |
|---|---|---|
| DMM Bitcoin | $308 million | Attributed by the three governments |
| Upbit | $50 million | Attributed by the three governments |
| Rain Management | $16.13 million | Attributed by the three governments |
| WazirX | $235 million | Additionally attributed by the United States and South Korea, based on detailed industry analysis |
| Radiant Capital | $50 million | Additionally attributed by the United States and South Korea, based on detailed industry analysis |
| Total | $659.13 million | Rounded in coverage to approximately $660 million |
The arithmetic is $308 million + $50 million + $16.13 million + $235 million + $50 million = $659.13 million. Crypto-loss estimates can change with valuation dates, asset prices, recovery amounts and the treatment of subsequent wallet movements, so the statement’s dollar figures should be read as reported virtual-asset values, not immutable accounting totals.
What happened in the named incidents?
DMM Bitcoin: $308 million
Japan’s DMM Bitcoin was the largest theft in the list. The trilateral statement attributed it to DPRK actors; the FBI also publicly attributed the incident to North Korea in contemporaneous reporting. The statement itself does not provide a complete technical incident report, so mechanics should not be presented as settled government findings.
Upbit: $50 million
South Korean exchange Upbit was included among the attributed 2024 incidents. The amount can vary in other accounts depending on when the stolen assets were valued.
Rank #2
- Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
- Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
- Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
- Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
- Trusted by 6 million users worldwide (4.9 App Store, 4.8 Google Play) - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets
Rain Management: $16.13 million
Rain Management was included in the first group of incidents attributed in the joint statement. The document supplies the amount and attribution but not a detailed public chronology of the attack.
WazirX: $235 million
The statement uses narrower wording here: the United States and South Korea additionally attributed the theft, relying on detailed industry analysis. It should not be written as though Japan independently endorsed this incident in exactly the same evidentiary manner.
Radiant Capital: $50 million
The same U.S.–South Korean attribution language applies to Radiant Capital. Radiant and investigators described a sophisticated October 2024 attack, but those technical descriptions should remain attributed to the company or investigators rather than treated as findings in the trilateral statement.
Rank #3
- Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
- Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
- Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
- Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
- Trusted by 6 million users worldwide - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets
What “attributed to North Korea” means
Attribution has levels. A government attribution is a formal assessment by a state, supported by intelligence and technical evidence, but it is not automatically a judicial verdict. Industry investigators may identify links through wallet movements, malware, infrastructure, coding patterns or known operational behaviors. A victim may publish its own assessment. A criminal prosecution or court finding is a different standard again.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →The statement names “DPRK-affiliated threat groups, including Lazarus Group.” Lazarus is a broad threat-intelligence label, not necessarily one legal entity or one permanently unified team. Security companies and governments may use overlapping names such as TraderTraitor and AppleJeus for different layers of activity. Those labels should not be treated as interchangeable proof that one unit conducted every listed theft.
How the attacks work
The governments specifically warned about well-disguised social engineering, malware including TraderTraitor and AppleJeus, and North Korean IT-worker schemes. A common high-level sequence is:
Rank #4
- EAL5+ CERTIFIED SECURE ELEMENT + FINGERPRINT PROTECTION — Your private keys stay encrypted offline on a certified EAL5+ chip, the same security tier used in EMV bank cards. Built by DCENT, securing crypto since 2018. Fingerprint authentication adds a second layer no PIN-only wallet can match.
- 10,000+ ASSETS NATIVE ON 100+ BLOCKCHAINS — Hold Bitcoin, Ethereum, XRP, Solana, Cardano, popular stablecoins (USDT, USDC), and NFTs in one wallet. No third-party apps, no fragmented setup — every supported asset works straight out of the box.
- TAP-TO-SIGN MOBILE EXPERIENCE — Pair your wallet with the DCENT mobile app over Bluetooth. Manage tokens, review transactions, and access in-app swap features directly from your phone — no cables, no desktop required.
- WEB3 & dAPP ACCESS VIA METAMASK — Connect to MetaMask and other browser extension wallets to manage NFTs, claim airdrops, and access dApps. A large screen and intuitive 4-button interface keep every transaction clearly visible before you sign.
- SEAMLESS FIRMWARE UPDATES & 30-DAY MONEY-BACK GUARANTEE — Apply security updates without resetting your wallet or migrating funds. Backed by Amazon's 30-day money-back guarantee — your purchase is risk-free.
- Reconnaissance identifies a valuable exchange, custodian, developer, trader, employee or contractor.
- Attackers personalize contact through a fake job, investment, technical-support or business scenario.
- The target is persuaded to run malicious code, open a booby-trapped file, disclose credentials, approve a transaction or connect a wallet.
- Attackers move assets through wallets and laundering infrastructure, often across chains and services.
Not every operation follows this exact chain. Incidents can involve compromised private keys, transaction manipulation, insider access, malware or failures in exchange and custody controls. “Hack” is therefore a convenient umbrella term, not a description of one universal technique.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.The insider threat from fake IT workers
The warning also addressed companies that hire through freelance and remote-work platforms. A worker using a false identity can obtain privileged access, influence code or deployment pipelines, exfiltrate credentials, or create an internal path to signing systems. Hiring and contractor verification are therefore part of the security perimeter.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Companies should independently verify identity documents, references, work history, payment details and location; limit privileges; require peer review; and monitor unusual access or data-transfer patterns. No single screening step is sufficient.
Best Value
- Dual-chip architecture for maximum protection: The next-gen, fully auditable TROPIC01 chip works alongside a certified EAL6+ Secure Element—completely NDA-free—to deliver radically transparent, industry-leading defense against physical attacks.
- Quantum-ready security: Get protection against future threats with the first-ever hardware wallet designed with quantum-ready architecture.
- See every detail with confidence: Our largest high-resolution color touchscreen makes it easy to navigate your assets, review transactions and manage your coins with clarity.
- Wireless freedom with encrypted Bluetooth control: Manage, buy, swap and stake securely using Trezor Suite on desktop or mobile. Qi2-compatible wireless charging keeps your Trezor powered up. No cables required—security meets convenience.
- Works seamlessly with Android, iOS and desktop: Connect wirelessly or via USB-C to your phone or computer. Manage your crypto anywhere with our companion Trezor Suite app.
Practical defenses for crypto businesses
- Use phishing-resistant, hardware-backed multifactor authentication for privileged accounts.
- Keep signing systems isolated from ordinary laptops and developer workstations.
- Require dual approval, allowlists, velocity limits and policy checks for withdrawals and treasury transfers.
- Apply least privilege to employees, contractors and automation keys, with rapid revocation.
- Sandbox downloaded repositories, interview exercises and third-party code before execution.
- Monitor unusual address creation, transaction destinations, timing and access behavior.
- Maintain an incident plan covering exchanges, custodians, blockchain-analytics firms and law enforcement.
- Preserve endpoint images, authentication logs, wallet records and transaction histories for investigation and recovery.
The statement points organizations toward public-private mechanisms including Illicit Virtual Asset Notification (IVAN), Crypto-ISAC and Security Alliance (SEAL), as well as U.S.–South Korean symposiums and Japanese Financial Services Agency and industry self-inspection initiatives.
What individual users should take from the warning
Individuals are also named targets, particularly through fake investment offers, employment approaches and malware. Use a separate device or browser profile for sensitive wallet activity, never install trading software or code from an unsolicited contact, verify URLs and recruiters independently, and use hardware security keys where a service supports them. Treat any request to share a seed phrase or private key as fraudulent. These steps reduce personal exposure but cannot protect an exchange if the exchange’s own custody or signing systems are compromised.
What changed after January 2025?
The January statement is a dated account of five 2024 incidents. Later trilateral reporting from the South Korean foreign ministry described the February 2025 Bybit theft as nearly $1.5 billion and discussed additional DPRK-linked incidents. Accordingly, “$660 million” should not be presented as North Korea’s latest total crypto theft or as the total for all of 2024 unless a source expressly defines it that way.
For the original wording and incident list, read the U.S. Department of State statement. Japan’s issuance notice is available from its Ministry of Foreign Affairs, and later context appears in South Korean government reporting.
The Bottom Line
The accurate takeaway is that the United States, Japan and South Korea jointly attributed $659.13 million—rounded to $660 million—in five selected 2024 cryptocurrency thefts to DPRK-linked actors. It was a government attribution and security warning, not a court judgment, and it is no longer a complete measure of North Korea’s crypto-theft activity after larger incidents were reported in 2025.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

