76 % of the cryptocurrency stolen in 2026 was found in North Korea
Cryptocurrency Heists of 2026: How North Korea Became the “Key Player”
What’s Happening
- The bulk of stolen funds (since the start of 2026) ends up in the hands of cyberwarriors from the DPRK.
- Hackers from this country carry out not only annual but sometimes weekly “historic” heists, reports Dark Reading.
Why It’s So Easy
1. Lack of state support for crypto assets makes them vulnerable – owners usually protect their money themselves.
2. As a result, each year an amount comparable to the GDP of an entire country is stolen:
* In 2025, the FBI recorded over $11 billion in stolen crypto assets in the U.S. (these are only known cases).
DPRK – The “King” of Heists
- According to TRM Labs, North Korean hackers are responsible for at least a third of all financial losses related to cryptocurrency over the past six years.
- In 2026 their activity intensified: 76 % of stolen funds since the beginning of the year ended up in Pyongyang.
- It’s not just the number of attacks – DPRK specializes in rare but high‑yield hacks. From January to April there were only two large‑scale incidents:
- Drift Protocol – $285 million
- KelpDAO – $292 million
Technological Factor
- Cryptocurrencies are convenient for cyberattacks: sanctions limit Pyongyang’s access to traditional financial instruments, but recovering stolen funds is almost impossible.
- Blockchain projects often lack mechanisms that allow a transfer to be reversed – this attracts investors looking for freedom of action.
History of Heists
Year % of stolen funds attributed to DPRK
2017–18 ~33 %
2020 sharply fell
2023 rebounded to pre‑COVID levels
2025 two thirds of all stolen funds
Examples:
- February 2025 – a group linked to the DPRK stole $1.5 million in Ethereum on ByBit.
- April 2025 – another group took almost $300 million from Drift; later that month the first group returned and stole ~$300 million from Kelp.
Role of Artificial Intelligence
- DPRK hackers use AI to improve technical attacks and social engineering:
- Removing language barriers, speeding up the creation of convincing materials, personalization.
- Over the past year, the number of AI‑driven fraud schemes has increased by 500 % (according to experts).
- Smart contracts are no longer considered reliable even for “ordinary” attackers; AI cuts attack execution time to minutes.
What Needs to Be Done
- Reevaluate the architecture of decentralized services: implement multisignatures and other mechanisms that require several hours or days to confirm a transaction.
- Slow down transaction speeds to reduce the risk of instant theft.
Thus, North Korea has become a key player in global cryptocurrency crime, and the growing use of AI only amplifies the threat. To protect yourself, it is essential to rethink the fundamentals of security in decentralized ecosystems.
Comments (0)
Share your thoughts — please be polite and stay on topic.
Log in to comment