North Korea Crypto Theft Totals Have Been Challenged
Data shows estimates of North Korea-linked cryptocurrency thefts are lower than the widely cited $7.8 billion figure.
Updated on Oct. 1, 2026 in Cybersecurity

Live Poll
Do you trust that cryptocurrency exchanges can adequately protect user funds from state-sponsored hackers?
Reported totals for North Korea-linked cryptocurrency thefts have reached approximately $7.10 billion when accounting for the recent Bitget incident, falling short of common $7.8 billion claims. Official U.S. government attributions confirm more than $3.1 billion in losses directly linked to these state-sponsored actors.
Why it matters
Determining accurate theft figures is essential for understanding the scale of illicit financing used to support state operations. Discrepancies in data highlights the difficulty in tracking digital assets as hackers utilize complex networks of mixers and bridges.
Hackers utilize malicious applications, spear-phishing, and compromised software to execute thefts. These actors subsequently move and launder stolen funds through a sophisticated network of exchanges, mixers, and bridges.
The players
FBI
The Federal Bureau of Investigation is the primary U.S. agency responsible for attributing major cyber thefts to foreign state actors.
Lazarus Group
This is a state-sponsored cyber unit subordinate to North Korea's Reconnaissance General Bureau known for large-scale financial attacks.
The details
State-sponsored groups such as Lazarus Group, Bluenoroff, and Andariel operate under the Reconnaissance General Bureau to conduct these digital heists. Previous major incidents include the $1.5 billion Bybit theft in 2025 and the $620 million breach of Sky Mavis' Ronin Bridge in 2022.
Timeline
In 2018, actors allegedly stole nearly $250 million from an exchange.
On March 23, 2022, $620 million was taken from Sky Mavis' Ronin Bridge.
On February 21, 2025, $1.5 billion was stolen from Bybit.
Through September 16, 2026, roughly $690 million in thefts were attributed to North Korean hackers.
On September 24, 2026, $351.6 million was moved from Bitget wallets.
The Tech Race
The ongoing series of digital heists demonstrates a shift toward state-sponsored cyber operations targeting decentralized finance infrastructure. This represents a marked departure from traditional espionage as nations increasingly utilize cryptocurrency theft to bypass international sanctions.
The prevalence of these attacks underscores significant security vulnerabilities within cryptocurrency exchanges and bridge protocols that can threaten user assets. Investors should remain cautious regarding the security measures employed by platforms utilizing third-party bridges or mixers.
The takeaway
The persistent targeting of digital platforms suggests that cryptocurrency remains a high-value target for state-linked actors seeking to circumvent global financial restrictions. Vigilance regarding personal security settings and the use of reputable, audited platforms remains the best defense for individual crypto holders.
Further reading
For more information on digital threats, visit the Cybersecurity section.
Source note: This article includes information reported by TokenPost.
Live Poll
Do you trust that cryptocurrency exchanges can adequately protect user funds from state-sponsored hackers?







