Bitget CEO Gracy Chen said a preliminary investigation found IP addresses matching VPN choices associated with a DPRK hacking group. Update (Sept. 25 at 4:30 am UTC): This article has been updated to add new comments from Bitget CEO Gracy Chen and preliminary analysis from onchain researcher Specter. Bitget CEO Gracy Chen said North Korean hackers may be behind the exchange’s $351.6 million security breach on Thursday, citing preliminary findings linking IP addresses to VPN services used by a North Korean group. Speaking during a live Q&A following the incident on X, Chen said security investigators had flagged similarities with previous North Korean attacks. She said the exchange did not believe the breach was an inside job. Read more
North Korea and Iran account for the majority of onchain malware, while Malaysia has been named among the most crypto curious Islamic nations. North Korean and Iran linked hackers were responsible for the majority of the 420% increase this year in malware on public blockchains according to a Chainalysis report. State-linked hackers accounted for roughly two-thirds of new activity whereby attackers stored malware instructions or infrastructure information on public blockchains. Chainalysis also identified UNC5342, a North Korea linked group, to previously unattributed activity spanning Tron, Aptos and BNB Smart Chain. Read more
The DPRK has turned to third-country IT workers to pass job interviews, after which, the positions are usually taken over by North Korean operatives. North Korea (DPRK) is now using remote workers from third countries, including Iran and Lebanon, to aid its efforts to infiltrate US companies and obtain money to fund its weapons programs, NBC reported on Friday. An alert issued in July by the US government and several foreign agencies said North Korean IT workers “seek out contracts with the intent of remitting their salaries to their parent North Korean agencies. They also pose an insider threat to companies and are involved in data exfiltration, cryptocurrency theft, and theft of sensitive information.” As the US and other governments have moved to counter North Korea’s efforts, the DPRK has turned increasingly to third-country IT workers to pass job interviews, the report said. After work contracts are obtained, the positions are usually taken over by North Korean operatives. Read more
Expedited discovery allows the exchange to seek account identities, balances and transaction histories from platforms with US operations. United States court records unsealed on Thursday show that a federal judge backed crypto exchange Bybit’s effort to trace assets stolen in the $1.5 billion North Korea-linked hack by granting the company expedited discovery. According to the records, Bybit filed the lawsuit under seal on June 18 against North Korea, its Reconnaissance General Bureau, the Lazarus Group and 20 unidentified defendants. The court granted Bybit’s request for expedited discovery on June 19. The discovery authority gives Bybit a practical route to identify alleged intermediaries and pursue a small portion of stolen assets that remains traceable, rather than relying solely on a judgment against North Korea. Read more
Daily NK reported that North Korea arrested former state cyber operators accused of hacking two state banks and laundering funds through crypto. North Korean authorities have reportedly arrested a group of former state cyber operators and IT specialists accused of hacking two state banks and laundering stolen funds through cryptocurrency. South Korean outlet Daily NK reported Thursday, citing an anonymous source in Pyongyang, that the group allegedly hacked the internal networks of North Korea’s central bank and the Foreign Trade Bank, converting stolen state funds into cryptocurrency before laundering them through China-based brokers. Cointelegraph could not independently verify the report. Read more
The cybersecurity threats from North Korea are perpetrated by a myriad of small hacker groups deploying malware and executing social engineering scams. North Korea (DPRK) state-affiliated hackers and threat actors were responsible for more than $2 billion in crypto losses in 2025, a 51% year-over-year increase, despite fewer attacks carried out by the group, according to cybersecurity company CrowdStrike. DPRK hackers represent the “largest” threat group targeting cryptocurrency users, as measured by the dollar amount of assets stolen, according to the company’s 2026 Financial Services Threat Landscape report. Crowdstrike added: The DPRK hackers and scammers focused on targeting Web3 projects and cryptocurrency exchanges because the stolen funds could be “cashed out” and transferred with a greater degree of anonymity than in the traditional financial system, CrowdStrike said. Read more
North Korea-linked hackers stole about $2.06 billion of the $3.4 billion lost in crypto hacks in 2025 and are moving from phishing to physical infiltration, CertiK’s new report finds. CertiK says North Korea-linked hackers stole about 60% of the value lost to crypto hacks in 2025, with proceeds used to help fund the regime’s nuclear and ballistic missile programs, highlighting the country's growing reliance on digital assets to generate hard currency. The findings, shared with Cointelegraph on Tuesday, come from a new Skynet report that attributes roughly $2.06 billion of an estimated $3.4 billion in 2025 crypto security losses to groups tied to the Democratic People’s Republic of Korea, or DPRK, across 79 of 656 incidents documented that year. Between 2016 and early 2026, DPRK-linked actors stole an estimated $6.75 billion in cryptocurrency across 263 documented incidents, the report says, citing findings by independent onchain researcher Taylor Monahan. Read more
A Manhattan judge modified a restraining notice to let Arbitrum DAO move $71 million in frozen Ether to Aave, while preserving terrorism victims’ legal claim on the funds. A Manhattan federal judge has allowed Arbitrum DAO to move $71 million in frozen Ether to Aave, clearing the path for the DeFi protocol’s recovery effort following a North Korea-linked exploit. Judge Margaret Garnett of the Southern District of New York issued the order on Friday, modifying a restraining notice that had locked the assets inside Arbitrum DAO. The modification permits an onchain governance vote to send the funds to a wallet controlled by Aave LLC, and explicitly protects anyone who participates in the transfer from being held in violation of the freeze. The order still keeps the terrorism victims’ legal claim on the funds, meaning Aave can’t use the funds freely and could be forced to hand them over if the court ultimately rules in the terrorism victims’ favor. Read more
DPRK-linked crypto theft topped $578M in April after the Kelp DAO exploit, as attacks continue to expand across protocols, companies and end users. Kelp DAO suffered a $292 million hack on Saturday, overtaking Drift as the largest crypto exploit of the year so far. North Korea-linked hackers are suspected to be behind the attack. Kelp DAO said Monday that the exploit stemmed from a failure of cross-chain messaging protocol LayerZero’s infrastructure. LayerZero said the breach was enabled by Kelp DAO’s use of a single verifier configuration to approve cross-chain messages. LayerZero said that “preliminary indicators” attributed the exploit to TraderTraitor, a subgroup of North Korea’s state-backed hacking unit known as Lazarus Group. Read more