{"investigation":{"slug":"dprk","entity_name":"DPRK","trust_score":0,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"The Democratic People's Republic of Korea (DPRK), operating primarily through state-sponsored hacking units designated as the Lazarus Group, TraderTraitor, and APT38, has stolen an estimated $6.75 billion in cryptocurrency since 2016 across dozens of major exploits. These operations are attributed by the FBI, OFAC, CISA, and allied governments to North Korea's Reconnaissance General Bureau and are conducted to fund the regime's weapons of mass destruction and ballistic missile programs in circumvention of international sanctions. DPRK-linked hackers are responsible for the largest single crypto theft in history — the $1.5 billion Bybit hack in February 2025 — and continue to operate at unprecedented scale and sophistication.","sections":[{"content":"The DPRK (Democratic People's Republic of Korea) conducts state-sponsored cyber operations targeting cryptocurrency infrastructure through several threat actor clusters. The primary designations used by U.S. intelligence and law enforcement are: Lazarus Group (the umbrella designation), APT38 (financial crime subgroup), BlueNoroff (cryptocurrency-focused subgroup), and TraderTraitor (the FBI's operational name for the group responsible for the Bybit hack and related supply-chain attacks). All groups have been attributed by the U.S. government to North Korea's Reconnaissance General Bureau (RGB), the country's primary intelligence directorate. OFAC placed Lazarus Group on the Specially Designated Nationals (SDN) List under North Korea Sanctions Regulations. The UN Panel of Experts investigated 58 suspected North Korean cryptocurrency heists between 2017 and 2023 generating an estimated $3 billion. The lower-bound cumulative total for DPRK cryptocurrency theft through early 2026 is estimated at $6.75 billion.","heading":"Entity Overview and Attribution","sources":[],"severity":"medium"},{"content":"The DPRK has been officially attributed with a series of high-profile cryptocurrency heists. The Bybit hack (February 21, 2025) is the largest: TraderTraitor actors compromised a Safe system administrator via phishing, injected malicious code into Safe's web interface, and tricked a Bybit employee into authorizing a transaction that drained approximately 499,000 ETH valued at $1.5 billion. The FBI attributed the attack to TraderTraitor within days and issued an advisory with 51 Ethereum addresses used in laundering. The Ronin Bridge hack (March 2022) saw Lazarus Group gain access to five of nine validator private keys via a fraudulent job offer PDF delivered to a Sky Mavis employee, enabling theft of 173,600 ETH and 25.5 million USDC totaling approximately $625 million — at the time the largest DeFi hack on record. OFAC subsequently sanctioned an Ethereum wallet linked to Lazarus and added the address to the SDN List. The Harmony Horizon Bridge hack (June 2022) resulted in $100 million stolen across multiple assets including ETH, BNB, USDC, USDT, and DAI. The FBI confirmed Lazarus Group responsibility in January 2023. Over $60 million was later laundered via RAILGUN privacy protocol and Tornado Cash. WazirX (July 18, 2024) lost $234.9 million when attackers altered a multisig smart contract during a signing session. ZachXBT traced test transactions beginning July 10, 2024 — eight days before the drain — and noted use of Tornado Cash to fund attacker addresses. DMM Bitcoin (May 2024) lost $308 million via a supply-chain attack: a TraderTraitor operative posed as a recruiter and lured a Ginco developer into executing a malicious Python script, enabling access to DMM Bitcoin's internal systems. The FBI and Japan's NPA jointly attributed this attack. Atomic Wallet (June 2023) saw over $100 million stolen from users. Additional attributed hacks include CoinEx ($31M, 2023), Stake.com ($41M, 2023), Alphapo ($60M, 2023), and Upbit ($50M, 2020, confirmed 2024). Total theft by DPRK-affiliated actors in 2024 reached $1.3 billion across 47 incidents; in 2025 the figure exceeded $2 billion.","heading":"Major Hacks and Exploits","sources":[],"severity":"medium"},{"content":"DPRK-affiliated actors employ a multi-stage laundering process designed to rapidly obfuscate the origin of stolen funds. Stage one involves exchanging stolen ERC-20 tokens for native blockchain assets (primarily ETH or BTC) that cannot be frozen by issuers. Stage two involves layering through a combination of: cross-chain bridges (THORChain was used to convert 83% of Bybit proceeds — approximately $1 billion in ETH — into Bitcoin, distributed across 6,954 wallets within 10 days of the hack); decentralized exchanges; cryptocurrency mixers including Tornado Cash (sanctioned by OFAC May 2022), Blender.io (sanctioned May 2022, used in processing $20.5 million of Ronin proceeds), Sinbad.io (sanctioned November 2023, used in Ronin and Horizon Bridge laundering), Kruw.io (used to mix approximately $14.3 million in DPRK-stolen funds and actively used for Bybit proceeds), and YoMix; and the eXch anonymous exchange service. Within 48 hours of the Bybit hack, at least $160 million had been funneled through illicit channels, surpassing $400 million by February 26, 2025. By March 2025, the Lazarus Group had allegedly laundered the full $1.4 billion in stolen Bybit ETH. As of reporting, approximately 20-28% of Bybit funds had been fully anonymized and rendered untraceable, while 77% remained traceable. Funds are dispersed across thousands of intermediary wallets on multiple blockchains before eventual conversion to fiat.","heading":"Money Laundering Techniques","sources":[],"severity":"medium"},{"content":"Beyond direct protocol exploits, DPRK operates two additional sustained campaigns targeting the crypto sector. The Contagious Interview campaign (also tracked as CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, UNC5342) lures software developers with fake job interview opportunities. Victims are directed to a fraudulent interview site, prompted to record a video answer, and when a fabricated camera error appears, are instructed to run a terminal command that instead downloads and executes malware — typically a JavaScript backdoor (DEV#POPPER RAT) or the OmniStealer information stealer. SentinelOne documented threat actors abusing cyber intelligence platforms to scout targets and coordinate operations. The campaign has targeted AI, cryptocurrency, financial services, and software development sectors across Europe, South Asia, the Middle East, and Central America, with 3,136 individual IP addresses identified as likely targets across 20 victim organizations. The related IT Worker Fraud scheme involves DPRK operatives obtaining remote employment at Western companies using stolen identities, AI-generated personas, and falsified credentials. ZachXBT uncovered a coordinated operation in which North Korean IT workers generated over $3.5 million through nearly 390 accounts, with records exposed after a compromised internal payment server was accessed. OFAC sanctioned six individuals and two entities in March 2026 for IT worker fraud, with one facilitator — Nguyen Quang Viet — converting approximately $2.5 million into cryptocurrency for the regime between mid-2023 and mid-2025.","heading":"Contagious Interview and IT Worker Fraud Campaigns","sources":[],"severity":"medium"},{"content":"OFAC designated Lazarus Group on the SDN List under North Korea Sanctions Regulations (section 510.214). Following the Ronin Bridge hack, OFAC added Ethereum wallet addresses linked to Lazarus Group to the SDN List in April 2022. OFAC issued the first-ever sanctions on a virtual currency mixer in May 2022, targeting Blender.io for processing over $20.5 million of Ronin hack proceeds. OFAC sanctioned Sinbad.io in November 2023 for laundering funds from multiple Lazarus heists. A March 2026 OFAC action sanctioned six individuals and two entities involved in IT worker fraud schemes, designating 21 cryptocurrency addresses across multiple blockchains. CISA issued advisory AA22-108A jointly with the FBI and U.S. Treasury in April 2022 (TraderTraitor advisory), warning blockchain companies of targeting by DPRK state-sponsored actors. The FBI's IC3 issued PSA250226 in February 2025 attributing the Bybit hack to TraderTraitor and releasing a list of 51 Ethereum addresses used in laundering. The FBI separately identified cryptocurrency funds stolen by the DPRK across multiple exchanges and requested that virtual asset service providers, RPC node operators, bridges, and DeFi services block transactions derived from designated addresses. In January 2025, the United States, Japan, and South Korea issued a joint public statement — for the first time jointly — warning about DPRK cryptocurrency theft activities, citing over $659 million stolen in 2024 alone.","heading":"Regulatory Actions and Sanctions","sources":[],"severity":"medium"},{"content":"Independent on-chain investigator ZachXBT has played a significant role in publicly attributing multiple DPRK hacks in real time. For the Bybit hack, ZachXBT linked attacker wallets and addresses to prior Lazarus Group operations and provided attribution evidence to Arkham Intel Exchange, for which he was awarded a $50,000 ARKHAM bounty. ZachXBT attributed the WazirX breach to Lazarus within hours of the incident on July 18, 2024, by tracing test transactions that had begun eight days earlier on July 10, 2024, and noting that Tornado Cash was used to fund the attacker addresses. ZachXBT published a comprehensive analysis tracing how Lazarus allegedly laundered over $200 million in hacked cryptocurrency funds into fiat currency across more than 25 hacks and multiple blockchains over three years (August 2020 to October 2023), including coin mixers and exchange activity. ZachXBT also exposed a law firm (Gerstein Harrow) that had allegedly received $71 million in frozen Lazarus funds. ZachXBT additionally uncovered the North Korean IT worker network generating $3.5 million across ~390 accounts by obtaining access to an exposed internal payment server with supporting chat logs and falsified identity documents.","heading":"On-Chain Investigator Attribution (ZachXBT)","sources":[],"severity":"medium"},{"content":"Cryptocurrency theft is assessed by U.S., UN, and allied government analysts to be a primary revenue mechanism for the DPRK regime to circumvent international sanctions and fund its weapons of mass destruction and ballistic missile programs. The UN Panel of Experts — before its dissolution — investigated 58 suspected North Korean cryptocurrency heists between 2017 and 2023 generating an estimated $3 billion. North Korean cryptocurrency heists accounted for approximately one-third of the DPRK's total foreign currency revenue in 2024, according to analysts cited by NK News. The demise of the UN Panel of Experts has created a more permissive enforcement environment. North Korea's deepening alliance with Russia has complicated multilateral sanctions coordination. According to 38 North and CYFIRMA, DPRK is evolving its operational tradecraft by integrating AI into attack methods and deception campaigns, and is described as having transitioned from a 'digital kleptocracy' to a 'rogue crypto-superpower.' DPRK operatives are assessed to be laundering cryptocurrency at unprecedented speed, with the Bybit proceeds largely laundered within 10 days — a velocity that exceeds the response capacity of most blockchain compliance systems.","heading":"Geopolitical Context and Weapons Financing","sources":[],"severity":"medium"}],"timeline":[{"date":"2018","event":"Lazarus Group designated on OFAC Specially Designated Nationals List under North Korea Sanctions Regulations","source":"","source_url":"https://home.treasury.gov/news/press-releases/sm924","date_original":"2018-01-01"},{"date":"2022-03-23","event":"Ronin Network (Axie Infinity) bridge hacked; 173,600 ETH and 25.5M USDC stolen (~$625M). Attack later attributed to Lazarus Group by U.S. Treasury","source":"","source_url":"https://www.coindesk.com/policy/2022/04/14/us-officials-tie-north-korean-hacker-group-to-axies-ronin-exploit"},{"date":"2022-04-14","event":"U.S. Treasury (OFAC) sanctions Lazarus Group Ethereum wallet linked to Ronin Bridge hack; FBI and OFAC jointly attribute attack to DPRK","source":"","source_url":"https://cyberscoop.com/ronin-bridge-hack-lazarus-group-north-korea-treasury-sanctions/"},{"date":"2022-04-22","event":"CISA, FBI, and U.S. Treasury issue joint advisory AA22-108A on TraderTraitor, warning blockchain companies of DPRK targeting","source":"","source_url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-108a"},{"date":"2022-05-06","event":"OFAC issues first-ever sanctions on a virtual currency mixer — Blender.io — for processing over $20.5M in Ronin hack proceeds","source":"","source_url":"https://home.treasury.gov/news/press-releases/jy0768"},{"date":"2022-06-24","event":"Harmony Horizon Bridge hacked; $100M in crypto assets stolen. FBI later confirms Lazarus Group responsible","source":"","source_url":"https://www.fbi.gov/news/press-releases/fbi-confirms-lazarus-group-cyber-actors-responsible-for-harmonys-horizon-bridge-currency-theft"},{"date":"2023-01-13","event":"North Korean actors use RAILGUN protocol to launder over $60M in ETH from Harmony Horizon Bridge hack; funds also routed through Tornado Cash","source":"","source_url":"https://www.bleepingcomputer.com/news/security/fbi-north-korean-hackers-stole-100-million-in-harmony-crypto-hack/"},{"date":"2023-06","event":"Atomic Wallet breached; over $100M stolen from users. Blockchain analytics firms attribute attack to Lazarus Group","source":"","source_url":"https://hacken.io/discover/lazarus-group/","date_original":"2023-06-01"},{"date":"2023-11","event":"OFAC sanctions Sinbad.io virtual currency mixer for laundering Lazarus Group funds from Ronin Bridge and Horizon Bridge heists","source":"","source_url":"https://home.treasury.gov/news/press-releases/jy1933","date_original":"2023-11-01"},{"date":"2024-05-31","event":"DMM Bitcoin (Japan) loses $308M in Bitcoin via supply-chain attack traced to TraderTraitor operative posing as recruiter to compromise Ginco developer. FBI and Japan NPA jointly attribute the attack","source":"","source_url":"https://2021-2025.state.gov/office-of-the-spokesperson/releases/2025/01/joint-statement-on-cryptocurrency-thefts-by-the-democratic-peoples-republic-of-korea-and-public-private-collaboration/"},{"date":"2024-07-18","event":"WazirX (India) loses $234.9M; Lazarus Group manipulates multisig smart contract during signing session. ZachXBT traces test transactions to July 10 and notes Tornado Cash funding of attacker addresses","source":"","source_url":"https://finance.yahoo.com/news/north-korean-lazarus-groups-200m-041020035.html"},{"date":"2025-01-14","event":"United States, Japan, and South Korea issue first-ever trilateral joint statement on DPRK cryptocurrency theft, citing over $659M stolen in 2024","source":"","source_url":"https://2021-2025.state.gov/office-of-the-spokesperson/releases/2025/01/joint-statement-on-cryptocurrency-thefts-by-the-democratic-peoples-republic-of-korea-and-public-private-collaboration/"},{"date":"2025-02-21","event":"Bybit exchange hacked; ~499,000 ETH (~$1.5B) stolen via Safe wallet supply-chain attack. TraderTraitor actors inject malicious code targeting Bybit-specific transactions","source":"","source_url":"https://www.ic3.gov/psa/2025/psa250226"},{"date":"2025-02-26","event":"FBI issues IC3 PSA250226 attributing Bybit hack to North Korean TraderTraitor; releases 51 Ethereum addresses used in laundering. ZachXBT independently identifies Lazarus Group via wallet linkage and receives $50K Arkham bounty","source":"","source_url":"https://www.ic3.gov/psa/2025/psa250226"},{"date":"2025-03-05","event":"Lazarus Group alleged to have laundered 83% of stolen Bybit ETH (~$1B) through THORChain, converting to Bitcoin distributed across 6,954 wallets; THORChain earns ~$5.5M in fees. Several THORChain developers resign after community votes against blocking laundering","source":"","source_url":"https://securityonline.info/bybit-hack-lazarus-group-launders-1-4-billion-in-ethereum-through-thorchain/"},{"date":"2025-12","event":"North Korea-linked hackers confirmed to have stolen over $2.02 billion in 2025 — a 51% year-over-year increase — representing the worst annual total on record","source":"","source_url":"https://thehackernews.com/2025/12/north-korea-linked-hackers-steal-202.html","date_original":"2025-12-01"},{"date":"2026-03-12","event":"OFAC sanctions six individuals and two entities for DPRK IT worker fraud schemes; designates 21 cryptocurrency addresses across multiple blockchains","source":"","source_url":"https://www.chainalysis.com/blog/ofac-targets-north-korean-it-workers-crypto-march-2026/"},{"date":"2026-04","event":"Drift Protocol compromised in elaborate social engineering operation; North Korean proxies met Drift employees in person at conferences and made deposits over $1M to appear as legitimate partners before exploiting the protocol for $285M","source":"","source_url":"https://thehackernews.com/2026/04/285-million-drift-hack-traced-to-six.html","date_original":"2026-04-01"}],"sources_used":[],"source_tags":["etherscan","zachxbt"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet","created_at":"2026-05-04T16:04:57.058156+00:00","updated_at":"2026-08-29T01:35:00.47+00:00"}}