Case
North Korean cryptocurrency theft campaign (2017-present)
The North Korean cryptocurrency theft campaign (2017-present) is a state-attributed revenue operation conducted through repeated cyber intrusions and laundering. Competent authorities have linked incidents to units associated with the Reconnaissance General Bureau and to clusters labelled Lazarus Group, APT38 or TraderTraitor. The campaign is not ordinary private crime or merely sanctions evasion. It uses offensive cyber operations to obtain assets for a sanctioned state.
Attribution, sanctions and recovery record current to 29 July 2026. Live sources require rechecking within 24 hours of publication.
Attribution and operation
North Korean operators have targeted exchanges, custodians, bridge protocols, decentralised-finance services and cryptocurrency holders. Methods include social engineering, compromised developer or employee access, malware, exploitation of smart contracts and attacks on wallet infrastructure. Laundering then uses cross-chain transfers, mixers, brokers and exchanges.
Attribution remains incident-specific. Government statements, malware resemblance, cluster labels, blockchain paths and judicial records answer different questions. A Lazarus label in one source does not prove that every wallet or operator described as APT38 or TraderTraitor is coextensive.
The Federal Bureau of Investigation attributed the February 2025 Bybit compromise to TraderTraitor actors associated with the Democratic People's Republic of Korea and described the theft as approximately USD 1.5 billion. That establishes the United States attribution and approximate value at theft. It does not prove how much the state ultimately realised or how proceeds were allocated.
Measurement and monitoring
Every incident requires a ledger separating the date of compromise, asset and value at theft, attribution source, laundering path, amount frozen or recovered and unresolved balance. Stolen, moved, laundered, frozen, recovered and realised value are not interchangeable. Asset-price changes can also make later valuations diverge from the amount taken at compromise.
The United Nations Panel of Experts reported on cyber theft before its mandate ended in 2024. Russia's veto prevented renewal of the Panel mandate, but it did not terminate Security Council resolution 1718 or the sanctions committee. Participating governments created the Multilateral Sanctions Monitoring Team in October 2024. The MSMT is not a United Nations body.
The MSMT's second report, published on 22 October 2025, is the latest comprehensive official multilateral review. It covers cyber and information-technology worker activity from January 2024 to September 2025. Cryptocurrency theft and fraudulent overseas technology work are different operations and datasets. Their values cannot be added without testing for overlap. No authoritative public full-year 2026 theft aggregate was identified at the audit date.
Legal response and assessment
Responders have used sanctions, criminal charges, forfeiture, seizure, blockchain tracing and private freezes. These legal states must remain distinct. A Treasury designation is an administrative finding. A complaint contains allegations unless adjudicated. Seized or frozen funds must be subtracted from gross theft before any estimate of realised revenue.
The Fifth Circuit held in Van Loon v Department of the Treasury that the immutable smart contracts in the administrative record were not sanctionable property under IEEPA. Treasury removed Tornado Cash from the sanctions list in March 2025. The judgment did not immunise mixers, founders or every decentralised protocol from other law.
The campaign has repeatedly obtained digital assets and imposed direct losses and service disruption on victims. Its net return, realised state revenue and programme-level allocation remain incompletely observed. Claims that proceeds displaced North Korean civilian welfare or funded a particular weapon require transaction-level or official evidence.
See also
Bangladesh Bank heist (2016) · Offensive cyber tools against financial infrastructure · Cross-chain bridges and decentralised-finance protocols · Cryptocurrency mixers and tumblers (Tornado Cash, Blender.io) · Cryptocurrency and stablecoin sanctions evasion · Lazarus Group · Blockchain analytics platforms (Chainalysis, Elliptic, TRM) · Digital economic warfare · Chokepoint effect
Sources
- United Nations Security Council, 'Resolution 1718 (2006)', S/RES/1718 (14 October 2006).
- United Nations Panel of Experts established pursuant to resolution 1874, Final report, S/2024/215 (7 March 2024).
- United Nations Security Council, meeting record (28 March 2024).
- Governments participating in the Multilateral Sanctions Monitoring Team, founding joint statement (16 October 2024).
- Multilateral Sanctions Monitoring Team, The DPRK's Violation and Evasion of UN Sanctions through Cyber and Information Technology Worker Activities, MSMT/2025/2 (22 October 2025).
- Australian Mission to the United Nations, 'Launch of the MSMT Second Report' (12 January 2026).
- Federal Bureau of Investigation, 'North Korea Responsible for $1.5 Billion Bybit Hack' (26 February 2025).
- Federal Bureau of Investigation, 'FBI Identifies Cryptocurrency Funds Stolen by DPRK' (22 August 2023).
- United States Department of Justice, 'Justice Department Announces Nationwide Actions to Combat Illicit North Korean Government Revenue Generation' (30 June 2025).
- United States Department of the Treasury, 'Treasury Sanctions First Virtual Currency Mixer' (6 May 2022).
- United States Department of the Treasury, 'Treasury Removes Tornado Cash from Sanctions List' (21 March 2025).
- Van Loon v Department of the Treasury, 122 F.4th 549 (5th Cir. 2024).
- United States Department of the Treasury, Office of Foreign Assets Control, Cyber-related Designations and Sanctions List Search (records checked 29 July 2026).
- Japan Ministry of Foreign Affairs, 'Publication of the Second Report of the Multilateral Sanctions Monitoring Team' (22 October 2025).
- United States Department of Justice, cryptocurrency seizure and forfeiture complaints linked to DPRK thefts (2020-2026).
- Jason Bartlett, 'North Korea's Cryptocurrency Obsession', Center for a New American Security (2022), and subsequent peer-reviewed cyber-finance scholarship.
Recommended citation
Cite this entry
Tennant, James J., ed. 'North Korean cryptocurrency theft campaign (2017-present).' The Encyclopedia of Economic Statecraft, version 2.0.0-alpha, last reviewed 29 July 2026. https://jamesjtennant.com/entries/north-korean-cryptocurrency-theft-campaign-2017-2026/.
Suggest an edit