North Korea steals billions in crypto
North Korea steals billions in crypto, MSMT report says
From the start of 2024 through September 2025, North Korean hackers stole an estimated $2.83 billion in cryptocurrencies, according to a new report by the Multilateral Sanctions Monitoring Team (MSMT). That sum is roughly one-third of North Korea’s total foreign income in 2024.
The MSMT — an eleven-country coalition formed in October 2024 to track how Pyongyang circumvents sanctions through cybercrime — found that the pace of theft accelerated in 2025. In the first nine months of 2025 alone, attackers made off with $1.64 billion, about 50% more than all of 2024.
Biggest hit: Bybit breach
The largest single incident occurred in February 2025 and targeted crypto exchange Bybit. The attack has been attributed to a group known as TraderTraitor (also called Jade Sleet or UNC4899). According to the report, the hackers exploited a multi-signature wallet provider called SafeWallet using phishing emails and malware to gain access to internal systems. They then disguised external withdrawals as internal transfers, took control of a smart contract tied to a cold wallet, and siphoned funds without immediate detection.
MSMT notes that North Korean groups more often attack third-party service providers than exchanges directly. Other active groups named in the report include CryptoCore and Citrine Sleet. In one case, the Web3 project Munchables lost $63 million — though much of those funds were later returned after the perpetrators ran into difficulties laundering the money.
How the stolen crypto is laundered
The report maps a nine-step laundering chain commonly used to clean stolen tokens. Typical steps include:
-
Swapping stolen tokens for Ethereum (ETH) on decentralized exchanges.
-
Passing funds through mixers such as Tornado Cash and Wasabi Wallet to obscure transaction trails.
-
Using cross-chain bridges to convert ETH to Bitcoin (BTC), then remixing.
-
Moving funds into cold/offline wallets and converting between chains and tokens (for example to Tron (TRX) and finally to the stablecoin USDT).
-
Selling USDT to OTC brokers, who then provide fiat currency.
Intermediaries in China, Russia and Cambodia
MSMT identifies intermediaries and companies in China, Russia and Cambodia that help turn crypto proceeds into cash. Named individuals from China include Ye Dinrong and Tan Yongzhi of Shenzhen Chain Element Network Technology, and a trader Wang Yicong, who allegedly assisted with transfers and the creation of false identities.
Russian middlemen reportedly converted about $60 million from the Bybit attack into cash through OTC brokers. In Cambodia, the company Huione Pay was used in laundering operations despite not having an active license from the central bank.
Cybercrime as a revenue stream
The MSMT’s findings make clear that cybercrime has become one of North Korea’s most important sources of foreign income amid tight economic sanctions. Organized hacking groups are increasingly effective at combining technical know-how with a sprawling network of regional intermediaries, making it harder for authorities to trace stolen funds or recover assets.