North Korea-Linked Crypto Theft Estimates Revised Downward
Data analysis indicates a $7.1 billion total for illicit activity, refuting previous claims of $7.8 billion in assets.
Updated on Oct. 1, 2026 in Cybersecurity

Live Poll
Do you trust that cryptocurrency exchanges can adequately protect user funds from state-sponsored hackers?
Verified records indicate that total losses linked to North Korean cyber actors have reached approximately $7.10 billion, falling short of claims suggesting $7.8 billion. This revised figure incorporates the $351.6 million moved from Bitget wallets on September 24, 2026, though North Korea's role in that specific incident remains unconfirmed.
Why it matters
Discrepancies in tracking illicit cryptocurrency movements complicate international efforts to sanction state-sponsored actors and secure digital assets. Precise attribution remains essential for distinguishing between criminal syndicates and the specific state-sanctioned operations of the North Korean Reconnaissance General Bureau.
Current data tracks $6.75 billion in cumulative thefts through the end of 2025, with $690 million attributed to North Korean hackers in 2026 as of September 16. These figures contrast with individual breaches, such as the $1.5 billion Bybit theft from 2025.
The players
Lazarus Group
A state-sponsored cyber-warfare group operating under the authority of North Korea's Reconnaissance General Bureau.
FBI
The United States federal agency responsible for attributing cyber-attacks and investigating international digital financial crimes.
The details
State-sponsored units such as the Lazarus Group, Bluenoroff, and Andariel execute thefts using methods including spear-phishing—a targeted email attack designed to deceive recipients—and malicious applications. Once assets are acquired, the groups utilize centralized exchanges, mixers—tools designed to obfuscate transaction trails—and cross-chain bridges to launder funds. These operations are managed as part of the Reconnaissance General Bureau’s strategic intelligence infrastructure.
Timeline
2018: Actors allegedly stole nearly $250 million from an exchange.
March 23, 2022: $620 million was taken from the Sky Mavis Ronin Bridge.
February 21, 2025: $1.5 billion was stolen from Bybit.
September 16, 2026: Official cutoff date for 2026 theft estimates.
September 24, 2026: $351.6 million was moved from Bitget wallets.
The Tech Race
Tracking North Korea-linked illicit activity serves as a primary benchmark for assessing global cybersecurity defense efficacy against state-sponsored actors. The constant recalibration of these loss figures highlights the ongoing race between forensic investigators and state-aligned actors utilizing increasingly complex obfuscation tactics.
The volatility and risk associated with centralized crypto-exchanges underscore the importance of securing assets in cold storage or non-custodial wallets. Users should remain vigilant against spear-phishing attempts, as current threat actors frequently leverage social engineering to compromise private keys.
The takeaway
The gap between claimed and verified theft figures highlights the difficulty of definitive attribution in decentralized finance. Readers should monitor upcoming FBI threat reports to see how the total confirmed loss figure shifts as investigations into the September 2026 incidents conclude.
Further reading
For more on the methodologies used to track digital infrastructure threats, visit Cybersecurity.
Live Poll
Do you trust that cryptocurrency exchanges can adequately protect user funds from state-sponsored hackers?






