Share this article

North Korea Was Responsible for Over $600M in Crypto Thefts Last Year: TRM Labs

U.S. national security officials have raised concerns about North Korea's use of stolen crypto to develop nuclear weapons.

Updated Mar 8, 2024, 7:24 p.m. Published Jan 5, 2024, 2:00 p.m.
Ari Redbord (TRM Labs)
Ari Redbord (TRM Labs)

North Korea-affiliated hackers were involved in a third of all crypto exploits and thefts last year, making off with some $600 million in funds, according to a report from TRM Labs.

The sum brings the Democratic People's Republic of Korea's (DPRK) total take from crypto projects to almost $3 billion over the past six years, the blockchain analytics firm said Friday.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the State of Crypto Newsletter today. See all newsletters

Still, the figure is about 30% less than in 2022, TRM's head of legal and government affairs, Ari Redbord, said. That year, DPRK-affiliated actors made off with around $850 million, "a huge chunk" of which came from the Ronin Bridge exploit, Redbord told CoinDesk in an interview. In 2023, most of the stolen funds were taken in the last few months; TRM attributed about $200 million in stolen funds to North Korea in August 2023.

"They're clearly attacking the crypto ecosystem at a really unprecedented speed and scale and continue to take advantage of sort of weak cyber controls," he said.

Many of the attacks continue to use so-called social engineering, allowing the perpetrators to acquire private keys for projects, he said.

Overall, the amount stolen in hacks in 2023 was roughly half that taken the previous year – $1.7 billion compared with $4 billion.

Redbord attributed the drop to several factors. There were fewer major hacks like 2022's Ronin theft, and other factors include successful law enforcement actions, better cybersecurity controls and, to a limited extent, price volatility over the past year.

What makes North Korean attacks stand out is that proceeds go toward the development of weapons of mass destruction, raising national security concerns.

"North Korean hackers are different, because it's not for greed or money or the typical hacker mentality; it's about taking those funds and using them for weapons proliferation and other types of destabilizing activity, which is a global threat," he said. "And that's why there's such a focus on it from a national security perspective."

National security officials in the U.S., Republic of Korea and Japan have directly mentioned these concerns in a recent trilateral meeting about North Korea's WMD efforts.

"Ronin really changed that conversation to a national security conversation," Redbord said. "Ronin was the first time we saw U.S. Treasury designate North Korea-related addresses, and it was the addresses that the original funds went off to ... and then the next two addresses. This is what started the whole Tornado Cash [sanctions], and then Blender.io and now Sinbad, so it's a whole-of-government approach to go after this issue."

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

Key U.S. Senator on Crypto Bill, Lummis, Negotiating Dicey Points With White House

Senators Cynthia Lummis and Kirsten Gillibrand (Nikhilesh De/CoinDesk)

The Republican lawmaker who is among the core negotiators on the U.S. market structure bill said the White House has rejected some ethics language.

What to know:

  • Sen. Cynthia Lummis (R-Wyo.) said she is negotiating with the White House on behalf of Senate Democrats trying to insert ethics provisions into Congress' market structure legislation.
  • Lawmakers should reveal a new draft market structure bill by the end of the week and hold a markup hearing next week, she said.