North Korea’s State-Sponsored Cyber Theft: How a Country Funds Itself Through Hacking

On February 21, 2025, the CEO of Bybit—a Dubai-based cryptocurrency exchange—approved what appeared to be a routine transaction. The user interface showed the correct destination address. The multi-signature security system required multiple executives to sign off, and they did. The transaction looked legitimate at every layer of verification a human being could perform. It wasn’t. North Korea’s Lazarus Group had compromised the interface of Safe{Wallet}, a third-party wallet tool that Bybit used for transfers between cold storage and hot wallets. The interface displayed one address. The code sent funds to another. By the time anyone noticed, 400,000 Ethereum—worth approximately $1.5 billion—had been transferred to wallets controlled by Pyongyang’s military intelligence apparatus. It was the largest cryptocurrency theft in history, executed through a fake button on a screen.

Within 48 hours, at least $160 million had been laundered. By March 20—less than a month later—Bybit’s CEO confirmed that attackers had converted 86 percent of the stolen Ethereum to Bitcoin. The money was gone, distributed across a laundering infrastructure that blockchain analysts describe as industrialized, following a structured 45-day pipeline from theft to usable currency. According to Chainalysis’s Crypto Crime Report, North Korean hackers stole $2.02 billion in cryptocurrency in 2025 alone—a 51 percent increase over the $1.3 billion stolen in 2024. The cumulative total since 2017 exceeds $6.75 billion. United Nations monitors estimate that cryptocurrency theft now constitutes approximately 13 percent of North Korea’s GDP.

This is not a criminal enterprise. This is a national economy.

How a country became a hacking operation

The Lazarus Group is affiliated with North Korea’s Reconnaissance General Bureau—the regime’s primary intelligence agency. According to a North Korean defector, the unit is known internally as the 414 Liaison Office. It first gained international attention in 2014 by destroying Sony Pictures’ network infrastructure in retaliation for The Interview, a film depicting the assassination of Kim Jong-un. The hackers deployed wiper malware that erased data across Sony’s systems while publicly leaking internal communications—a political operation, not a financial one.

The pivot to financial crime came in 2016 with the Bangladesh Bank heist. Lazarus issued 35 fraudulent instructions through the SWIFT international banking network to transfer nearly $1 billion from the Federal Reserve Bank of New York’s account belonging to Bangladesh’s central bank. Thirty of the transactions were blocked when a misspelled word in one instruction triggered a review. Five got through. The group escaped with $81 million—a figure that, by current standards, would be a slow Tuesday.

The cryptocurrency era transformed the operation’s scale. Traditional banking systems have compliance departments, transaction limits, correspondent bank oversight, and regulatory checkpoints. Cryptocurrency has smart contracts, multi-signature wallets, and decentralized exchanges with varying levels of security, operated by companies headquartered in jurisdictions with inconsistent enforcement. For a nation-state hacking operation, the cryptocurrency ecosystem is a softer target than the SWIFT network by orders of magnitude.

The progression since 2017: Banco del Austro in Ecuador ($12 million), Vietnam’s Tien Phong Bank ($1 million), Taiwan’s Far Eastern International Bank ($60 million), then the escalation into crypto—KuCoin ($275 million in 2020), the Ronin Network powering Axie Infinity ($625 million in 2022), Atomic Wallet ($100 million in 2023), WazirX in India ($235 million in 2024), and then Bybit ($1.5 billion in February 2025). The trajectory is exponential, and the operational tempo is accelerating: by mid-2025, Lazarus was executing major heists roughly every 20 days.

How they actually get in

The Lazarus Group’s primary weapon is not technical sophistication. It’s patience. Their attack methodology targets humans, not code.

The Ronin Network hack—$625 million—started with a fake job offer. A Lazarus operative, posing as a recruiter, contacted an engineer at Sky Mavis (the company behind Axie Infinity) through LinkedIn with a fabricated employment opportunity. The engineer downloaded a document that contained malware. That single compromised machine gave the attackers access to the validator nodes that secured the Ronin bridge, and from there, access to the funds.

The Bybit hack started with a compromised developer laptop. On February 4, 2025, a developer at Safe{Wallet} received what appeared to be a routine request. Their Apple MacBook became the entry point. Within 17 days, the attackers had manipulated the wallet’s front-end interface to redirect a legitimate-looking transaction. The multi-signature security system—designed specifically to prevent single-point-of-failure theft—approved the fraudulent transfer because the fraud existed at the visual layer, not the cryptographic layer. The keys were valid. The signatures were authentic. The destination was wrong.

Beyond direct hacking, North Korea has deployed what researchers call the “Wagemole” strategy—embedding covert IT workers inside legitimate companies worldwide. Operatives obtain remote technical positions using fraudulent identities or through front companies, function as normal employees while providing intelligence to hacking teams, and in some cases directly facilitate theft by providing credentials or disabling security systems. In 2024 alone, more than a dozen cryptocurrency companies were infiltrated by North Korean operatives posing as IT contractors. A Maryland man was sentenced in December 2025 to 15 months in prison for allowing North Korean nationals in Shenyang, China, to use his identity for employment at U.S. companies—including a contract at the Federal Aviation Administration. He was paid over $970,000 for software development work performed by overseas conspirators.

Why they can’t be stopped (yet)

North Korea has no extradition treaties. No Interpol cooperation. No financial system to freeze. The Lazarus Group operates from Pyongyang with functional impunity. The U.S. Treasury has sanctioned over 100 Lazarus-linked wallet addresses, but the group creates new ones. The FBI issues arrest warrants for operators it will never arrest. International sanctions on North Korea are among the most comprehensive ever imposed—and cryptocurrency theft is the mechanism by which the regime circumvents them.

The laundering infrastructure is equally resilient. Chainalysis analysis reveals a structured, multi-wave pipeline: within hours of a theft, stolen funds begin moving through DeFi protocols and mixing services. Funds from separate heists are blended together—money from Stake.com ends up in wallet addresses used for Atomic Wallet laundering, CoinEx proceeds flow through addresses tied to previous operations. This intentional commingling creates noise that makes individual theft attribution nearly impossible. Analysts can trace fragments, but only about 15 percent of stolen funds are ever recovered. The stolen cryptocurrency is converted to Bitcoin (highest liquidity, global acceptance, resistance to devaluation), moved through privacy-enhancing mixers, and eventually converted to fiat currency through intermediaries in jurisdictions with weak enforcement.

The Center for Strategic and International Studies calls this “cyber-enabled state terrorism.” The label is accurate. Every dollar stolen funds North Korea’s nuclear weapons and ballistic missile programs. Every Bitcoin heist buys missile fuel. The February 2025 Bybit theft alone—$1.5 billion—exceeded the entire annual GDP of several sovereign nations, extracted through a single manipulated interface in 81 seconds of approved transactions.

What it means for the concept of a heist

North Korea’s cryptocurrency operation redefines what a heist is. The Gardner Museum theft required two men in police uniforms, 81 minutes inside a building, and the physical removal of 13 canvases. The Bybit theft required a compromised laptop, a manipulated interface, and a CEO clicking a button he’d been designed to trust. The Gardner paintings are worth $500 million and are unsellable. The Bybit Ethereum was worth $1.5 billion and was 86 percent laundered within a month.

The traditional heist is constrained by physical access, physical removal, and physical fencing of stolen goods. The North Korean model removes all three constraints. Access is digital. Removal is instantaneous. And cryptocurrency—unlike a Vermeer—can be laundered into fungible currency through automated infrastructure that operates 24 hours a day across every jurisdiction on earth. The heist of the century is no longer a once-in-a-generation event. It’s a quarterly revenue target for a nuclear-armed state that has turned theft into a line item on its national budget.

We cover North Korea’s cyber operations alongside the Gardner Museum theft, the economics of stolen property, and the full history of audacious theft across our Greatest Heists course—including why the most successful heist crew in history doesn’t wear masks, carry guns, or leave the building. They sit at keyboards in Pyongyang and steal more in an afternoon than most bank robbers dream of in a lifetime.