Case

North Korean cryptocurrency theft campaign (2017-present)

The North Korean cryptocurrency theft campaign (2017-present) is a state-attributed revenue operation conducted through repeated cyber intrusions and laundering. Competent authorities have linked incidents to units associated with the Reconnaissance General Bureau and to clusters labelled Lazarus Group, APT38 or TraderTraitor. The campaign is not ordinary private crime or merely sanctions evasion. It uses offensive cyber operations to obtain assets for a sanctioned state.

Attribution, sanctions and recovery record current to 29 July 2026. Live sources require rechecking within 24 hours of publication.

Attribution and operation

North Korean operators have targeted exchanges, custodians, bridge protocols, decentralised-finance services and cryptocurrency holders. Methods include social engineering, compromised developer or employee access, malware, exploitation of smart contracts and attacks on wallet infrastructure. Laundering then uses cross-chain transfers, mixers, brokers and exchanges.

Attribution remains incident-specific. Government statements, malware resemblance, cluster labels, blockchain paths and judicial records answer different questions. A Lazarus label in one source does not prove that every wallet or operator described as APT38 or TraderTraitor is coextensive.

The Federal Bureau of Investigation attributed the February 2025 Bybit compromise to TraderTraitor actors associated with the Democratic People's Republic of Korea and described the theft as approximately USD 1.5 billion. That establishes the United States attribution and approximate value at theft. It does not prove how much the state ultimately realised or how proceeds were allocated.

Measurement and monitoring

Every incident requires a ledger separating the date of compromise, asset and value at theft, attribution source, laundering path, amount frozen or recovered and unresolved balance. Stolen, moved, laundered, frozen, recovered and realised value are not interchangeable. Asset-price changes can also make later valuations diverge from the amount taken at compromise.

The United Nations Panel of Experts reported on cyber theft before its mandate ended in 2024. Russia's veto prevented renewal of the Panel mandate, but it did not terminate Security Council resolution 1718 or the sanctions committee. Participating governments created the Multilateral Sanctions Monitoring Team in October 2024. The MSMT is not a United Nations body.

The MSMT's second report, published on 22 October 2025, is the latest comprehensive official multilateral review. It covers cyber and information-technology worker activity from January 2024 to September 2025. Cryptocurrency theft and fraudulent overseas technology work are different operations and datasets. Their values cannot be added without testing for overlap. No authoritative public full-year 2026 theft aggregate was identified at the audit date.

Responders have used sanctions, criminal charges, forfeiture, seizure, blockchain tracing and private freezes. These legal states must remain distinct. A Treasury designation is an administrative finding. A complaint contains allegations unless adjudicated. Seized or frozen funds must be subtracted from gross theft before any estimate of realised revenue.

The Fifth Circuit held in Van Loon v Department of the Treasury that the immutable smart contracts in the administrative record were not sanctionable property under IEEPA. Treasury removed Tornado Cash from the sanctions list in March 2025. The judgment did not immunise mixers, founders or every decentralised protocol from other law.

The campaign has repeatedly obtained digital assets and imposed direct losses and service disruption on victims. Its net return, realised state revenue and programme-level allocation remain incompletely observed. Claims that proceeds displaced North Korean civilian welfare or funded a particular weapon require transaction-level or official evidence.

See also

Bangladesh Bank heist (2016) · Offensive cyber tools against financial infrastructure · Cross-chain bridges and decentralised-finance protocols · Cryptocurrency mixers and tumblers (Tornado Cash, Blender.io) · Cryptocurrency and stablecoin sanctions evasion · Lazarus Group · Blockchain analytics platforms (Chainalysis, Elliptic, TRM) · Digital economic warfare · Chokepoint effect

Sources

Recommended citation

Cite this entry

Tennant, James J., ed. 'North Korean cryptocurrency theft campaign (2017-present).' The Encyclopedia of Economic Statecraft, version 2.0.0-alpha, last reviewed 29 July 2026. https://jamesjtennant.com/entries/north-korean-cryptocurrency-theft-campaign-2017-2026/.

Suggest an edit