North Korean Hackers Stole $2.02 Billion in Cryptocurrency (2025)
What North Korean Hacking Groups Are Stealing Billions?
Primary Group: FAMOUS CHOLLIMA (DPRK state-sponsored)
Total Theft: $2.02 billion in digital assets (2025)
Market Share: 47% of all state-sponsored tech intrusions
North Korean state-sponsored hacking operations have evolved from opportunistic cybercrime into a sophisticated, AI-enhanced revenue generation engine that directly funds the regime's weapons programs. CrowdStrike's 2026 report reveals that DPRK-nexus actors stole an estimated $2.02 billion in digital assets during 2025, representing a 51% year-over-year increase and making them the largest collective digital asset thieves among all tracked adversaries.
FAMOUS CHOLLIMA, the most prolific North Korean hacking unit, was responsible for 47% of all state-sponsored "hands-on-keyboard" intrusions targeting the technology sector in 2025. This group has pioneered the use of AI-generated personas and fraudulent front companies to infiltrate Western technology firms as remote IT workers, channeling illicit earnings directly to North Korea's military-industrial complex.
Other active DPRK groups include:
- PRESSURE CHOLLIMA: Executed the largest single financial theft ($1.46 billion via trojanized software) - STARDUST CHOLLIMA: Tripled operational tempo targeting fintech platforms across North America, Europe, and Asia - KIM SU KYUNG: Specializes in cryptocurrency exchange infiltration
How Do North Korean Hackers Use AI to Steal Cryptocurrency?
Tactic: AI-generated fake identities for remote IT positions
Method: Trojanized software and supply chain compromises
Revenue Stream: Direct theft + salary fraud from fake employment
North Korean hacking operations have adopted artificial intelligence at an unprecedented scale, using AI tools to enhance both the sophistication and volume of their attacks. The most innovative tactic involves creating entirely fictitious IT professionals using AI-generated headshots, voice synthesis for video interviews, and fabricated work histories.
The attack methodology operates on two parallel tracks:
Track 1: Remote Worker Infiltration - Identity Creation: AI generates realistic personas with complete digital footprints (LinkedIn profiles, GitHub repositories, professional references). - Employment Acquisition: Operatives secure remote software engineering or DevOps positions at U.S. technology firms, earning salaries between $100,000-$300,000 annually. - Access Exploitation: Once employed, operatives use legitimate credentials to access internal systems, source code repositories, and cryptocurrency wallets. - Fund Diversion: Salaries are laundered through cryptocurrency mixers and funneled back to North Korea via intermediaries in China and Southeast Asia. Track 2: Technical Cyber Operations - Reconnaissance: Automated scanning of cryptocurrency exchanges, DeFi protocols, and blockchain bridges for vulnerabilities. - Weaponization: Development of custom malware trojanized into legitimate software updates or developer tools. - Deployment: Distribution through compromised package managers (npm, PyPI) or fake security patches. - Extraction: Immediate liquidation of stolen assets through privacy coins and mixer services to obscure the money trail.
In the first four months of 2026 alone, North Korean hackers stole approximately $577 million, accounting for 76% of all crypto hack losses through just two major attacks: Drift Protocol and KelpDAO.
When Did North Korean Crypto Theft Reach Record Levels?
Peak Period: 2025 (April 2025 - March 2026)
Growth Rate: 51% increase from previous year
Q1 2026 Losses: $577 million (76% of global crypto hack total)
The dramatic 51% surge in North Korean digital asset theft during 2025 reflects both increased operational capability and heightened desperation as international sanctions tighten around the Kim Jong Un regime. With traditional revenue streams constrained, the DPRK has doubled down on cyber-enabled theft as a critical source of foreign currency.
CrowdStrike data shows that FAMOUS CHOLLIMA doubled its operational tempo using AI-generated identities to infiltrate cryptocurrency exchanges and fintech platforms. Meanwhile, STARDUST CHOLLIMA tripled its activities, expanding beyond traditional targets in South Korea and Japan to aggressively pursue North American and European victims.
The technology sector remains particularly vulnerable, with North America-based technology organizations accounting for 45% of all sector intrusions in Q1 2026. "Hands-on-keyboard" intrusions against technology entities constituted 20% of all interactive intrusions, indicating that human operatives—not just automated malware—play a central role in these campaigns.
Frequently Asked Questions
How much money did North Korean hackers steal in 2025?
North Korean state-sponsored actors stole an estimated $2.02 billion in digital assets during 2025, representing a 51% year-over-year increase and making them the largest collective digital asset thieves globally.
What is FAMOUS CHOLLIMA?
FAMOUS CHOLLIMA is a prominent North Korean hacking unit responsible for 47% of all state-sponsored "hands-on-keyboard" intrusions targeting the technology sector. The group specializes in AI-enhanced personas and front company operations to secure remote IT roles within Western technology firms.
How do North Korean hackers use AI in their operations?
North Korean operatives use AI to generate fake identities (headshots, voice synthesis, work histories) for remote job applications, automate vulnerability scanning of cryptocurrency platforms, and create sophisticated phishing campaigns that mimic legitimate communications.
What percentage of crypto hacks are attributed to North Korea?
In Q1 2026, North Korean hackers accounted for 76% of all cryptocurrency hack losses, stealing approximately $577 million through just two major attacks (Drift Protocol and KelpDAO).
Where does the stolen money go?
Cryptocurrency theft proceeds are laundered through mixer services, privacy coins, and intermediaries in China and Southeast Asia before being funneled directly to North Korea's military-industrial complex to fund weapons development programs, including ballistic missiles and nuclear research.
How can cryptocurrency platforms defend against DPRK attacks?
CrowdStrike recommends implementing rigorous identity verification for remote employees, conducting enhanced due diligence on contractor backgrounds, deploying multi-signature wallet requirements, monitoring for unusual transaction patterns, and using blockchain analytics tools to trace fund movements through mixer services.






