Instrument

State-directed cryptocurrency theft

State-directed cryptocurrency theft is cyber intrusion by a state or state-directed unit to obtain virtual assets for governmental benefit. It becomes economic statecraft when the operation is attributable to a state and the proceeds support regime finance, sanctions evasion, procurement or weapons development. The source set establishes North Korea as the strongest documented case; it does not establish a comparable programme by another state.

Mechanism

The instrument has 6 evidentiary stages: compromise of an exchange, bridge, wallet provider, supplier or authorised employee; diversion of assets; attribution of the intrusion and addresses; dispersion through services or wallets; attempted conversion into usable value; and state receipt or benefit.

Each stage requires separate evidence. Value at theft does not establish the amount laundered, converted, received or spent. Cross-chain dispersion establishes movement, not cash-out. Official attribution states an authority's assessment; it is not a criminal judgment against every associated person.

Public blockchains create opportunity and exposure. Rapid settlement can move value without a correspondent bank, while persistent transaction records support tracing, freezing, blocking and seizure. Virtual assets can complicate sanctions enforcement; they are not anonymous, untraceable or sanctions-proof.

Statecraft use

The Federal Bureau of Investigation attributed the theft of approximately US$1.5bn in virtual assets from Bybit on 21 February 2025 to North Korean actors it tracks as TraderTraitor. The figure was the FBI's approximate value at the time of the theft. Its alert reported that the actors converted some assets to Bitcoin and other virtual assets and dispersed them across thousands of addresses. It expected further laundering and eventual conversion; it did not establish the amount ultimately realised.

The FBI and Japan's National Police Agency attributed the May 2024 theft of 4,502.9 Bitcoin from DMM Bitcoin to TraderTraitor and valued the loss at US$308m at the time. The FBI attributed the June 2022 Harmony Horizon Bridge theft to Lazarus Group and APT38 actors associated with North Korea. The United States Treasury linked a designated address to the March 2022 Ronin bridge theft and later designated the Sinbad mixer for supporting Lazarus Group laundering.

The final United Nations Panel of Experts report in March 2024 investigated 58 suspected North Korean cyberattacks on cryptocurrency-related companies between 2017 and 2023, valued at approximately US$3bn. Later multilateral reporting documents cyber and information-technology worker activity used to generate revenue and laundering through mixers, bridges, decentralised exchanges, stablecoins and unhosted wallets. These assessments support the regime-finance connection at programme level; they do not trace every stolen asset to a specific weapon expenditure.

State nexus and roles

The state principal supplies the purpose and receives or benefits from revenue. The operational unit conducts intrusion, theft and laundering. TraderTraitor, Lazarus Group and APT38 overlap in some official accounts but are not interchangeable in every incident. Victims and intermediaries also differ: asset owners, exchanges, bridges, custodians, suppliers, mixers, brokers, stablecoin issuers and mule accounts have distinct functions and control rights.

Intelligence attribution, sanctions designation, civil complaint, seizure, plea and final judgment carry different weight. A complaint alleges and a designation applies administrative authority; neither alone proves criminal liability. Address control, state receipt and programme finance remain separate propositions.

Effects, limits and countermeasures

The immediate effect is victim loss and assets the operator can attempt to realise. Strategic effect depends on how much value survives price movement, fees, tracing, freezing, seizure and conversion, then reaches a state beneficiary. Private estimates require a coverage period, valuation basis, attribution method and overlap treatment.

Cybersecurity and transaction controls reduce theft. Analytics support tracing and attribution. Exchanges, bridges, issuers and other providers can screen or block addresses where their powers allow. Sanctions restrict named actors; legal process can freeze, seize or recover assets. Disruption does not prove that all value is recoverable.

The instrument primarily generates state revenue and evades isolation. It does not ordinarily compel the immediate victim to change policy. Its effectiveness therefore turns on realised state benefit and the value of the capability preserved, not the headline value stolen.

See also

North Korean cryptocurrency theft campaign (2017-present) · Lazarus Group · Bangladesh Bank heist (2016) · Cryptocurrency and stablecoin sanctions evasion · Cryptocurrency mixers and tumblers (Tornado Cash, Blender.io) · Blockchain analytics platforms (Chainalysis, Elliptic, TRM) · Cross-chain bridges and decentralised-finance protocols · Financial warfare

Sources

  1. Federal Bureau of Investigation, 'North Korea Responsible for $1.5 Billion Bybit Hack', 26 February 2025. https://www.fbi.gov/investigate/cyber/alerts/2025/north-korea-responsible-for-1-5-billion-bybit-hack
  2. Multilateral Sanctions Monitoring Team, The DPRK's Violation and Evasion of UN Sanctions through Cyber and Information Technology Worker Activities, MSMT/2025/2 (2025). https://msmt.info/Publications/detail/MSMT%20Report/4221
  3. United Nations Security Council Panel of Experts, Final report submitted pursuant to resolution 2680 (2023), S/2024/215, 7 March 2024. https://digitallibrary.un.org/record/4041323/files/S_2024_215-EN.pdf?version=1
  4. Financial Action Task Force, Complex Proliferation Financing and Sanctions Evasion Schemes, 20 June 2025. https://www.fatf-gafi.org/en/publications/Financingofproliferation/complex-proliferation-financing-sanction-evasion-schemes.html
  5. Financial Action Task Force, Targeted Report on Stablecoins and Unhosted Wallets: Peer-to-Peer Transactions, 3 March 2026. https://www.fatf-gafi.org/en/publications/Virtualassets/targeted-report-stablecoins-unhosted-wallets.html
  6. Federal Bureau of Investigation, 'FBI, DC3, and NPA Identification of North Korean Cyber Actors, Tracked as TraderTraitor, Responsible for Theft of $308 Million USD from Bitcoin.DMM.com', 23 December 2024. https://www.fbi.gov/news/press-releases/fbi-dc3-and-npa-identification-of-north-korean-cyber-actors-tracked-as-tradertraitor-responsible-for-theft-of-308-million-from-bitcoindmmcom
  7. Federal Bureau of Investigation, 'FBI Confirms Lazarus Group Cyber Actors Responsible for Harmony's Horizon Bridge Currency Theft', 23 January 2023. https://www.fbi.gov/news/press-releases/fbi-confirms-lazarus-group-cyber-actors-responsible-for-harmonys-horizon-bridge-currency-theft
  8. US Department of the Treasury, Office of Foreign Assets Control, 'North Korea Designations and Designation Update', 14 April 2022. https://ofac.treasury.gov/recent-actions/20220414
  9. US Department of the Treasury, 'Treasury Sanctions Mixer Used by the DPRK to Launder Stolen Virtual Currency', 29 November 2023. https://home.treasury.gov/news/press-releases/jy1933
  10. US Department of Justice, 'Department Files Civil Forfeiture Complaint Against Over $7.74M Laundered on Behalf of the North Korean Government', 5 June 2025. https://www.justice.gov/opa/pr/department-files-civil-forfeiture-complaint-against-over-774m-laundered-behalf-north-korean
  11. US Department of Justice, 'Justice Department Announces Nationwide Actions to Combat Illicit North Korean Government Revenue Generation', 14 November 2025. https://www.justice.gov/opa/pr/justice-department-announces-nationwide-actions-combat-illicit-north-korean-government
  12. Financial Action Task Force, Targeted Update on Implementation of the FATF Standards on Virtual Assets and Virtual Asset Service Providers (2025). https://www.fatf-gafi.org/content/dam/fatf-gafi/recommendations/2025-Targeted-Upate-VA-VASPs.pdf.coredownload.pdf

Recommended citation

Cite this entry

Tennant, James J., ed. 'State-directed cryptocurrency theft.' The Encyclopedia of Economic Statecraft, version 2.0, last reviewed 29 July 2026. https://jamesjtennant.com/entries/cryptocurrency-theft-as-state-finance/.

Suggest an edit