0x222045f72220…222045f4
Bitget Breach Lifts North Korea's 2025 Crypto Theft Past $1 Billion
The Bitget exchange breach has pushed North Korean-linked crypto theft past $1 billion in 2025, Bloomberg reports, matching the pace of record prior years.
Outputs
The Bitget hack pushed North Korean-linked crypto theft past $1 billion in 2025, according to Bloomberg.
North Korean actors stole an estimated $1.3 billion in crypto in 2024, per Chainalysis, after a record $1.7 billion in 2022.
The February Bybit breach of roughly $1.5 billion in ether and stSTETH remains the largest single crypto theft on record.
The hack of cryptocurrency exchange Bitget has pushed the total value of digital assets stolen by North Korean-linked actors this year past the $1 billion mark, Bloomberg reported.
The milestone underscores the scale and persistence of state-sponsored cryptocurrency theft as a revenue channel for the Pyongyang regime. United Nations sanctions monitors and blockchain forensic firms, including Chainalysis and TRM Labs, have repeatedly documented that the Democratic People's Republic of Korea funds its weapons programs in part through proceeds from exchange breaches, cross-chain laundering and the conversion of stolen tokens into privacy assets and fiat.
Bitget has not fully detailed the exploit vector publicly. Attacks attributed to North Korean actors — most commonly the Lazarus Group and its affiliates tracked by Microsoft as Diamond Sleet, and by other researchers under names including APT38 and TraderTraitor — typically begin with socially engineered compromise of exchange employees, the injection of signed malicious transactions, or the drainage of multi-signature custody wallets. In prior incidents, including the Bybit breach in February, attackers hijacked the signing interface of a Safe{Wallet} front end to trick authorized signers into approving a malicious delegate call, draining roughly $1.5 billion in ether and stETH in the largest crypto theft on record.
For Bitget, the operational consequences are immediate. The exchange, which is incorporated offshore and serves a global retail base, must now reconcile customer balances, absorb or socialize losses, and manage withdrawal pressure. Industry practice after major breaches has split between covering losses from corporate treasuries — as Bitget itself did after a separate incident involving a market maker in 2024 — and passing shortfalls to users through proportional balance cuts. The exchange's handling of proof-of-reserves disclosures and reimbursement timelines will likely determine whether institutional counterparties and market makers reduce exposure to its venues.
The $1 billion figure for 2025 puts North Korean-linked theft on pace with recent years. Chainalysis estimated that the DPRK stole approximately $1.3 billion in cryptocurrency in 2024, down from a record $1.7 billion in 2022. TRM Labs projected in a January report that 2025 could rival or exceed those totals if the pace of the first quarter held. The Bybit breach alone accounted for the bulk of this year's stolen value before the Bitget incident.
The laundering pattern that follows such thefts is well established and operationally significant for compliance teams. Stolen funds typically move through mixers such as Tornado Cash on Ethereum, or Sinbad and successor services on Bitcoin, before conversion to privacy coins or cross-chain bridges. In the Bybit case, on-chain analysts observed the attackers converting ether to the DAI stablecoin and routing assets through ThorChain, a cross-chain protocol that lacks the licensing and screening controls of regulated venues. That laundering pipeline complicates recovery and creates secondary exposure for exchanges and protocols that unwittingly process the funds, triggering sanctions-risk reviews under US Treasury Office of Foreign Assets Control rules.
Regulators are responding. The US Department of Justice and the Federal Bureau of Investigation have increasingly treated exchange hacks as national-security matters rather than pure financial crimes, filing seizure actions and indictments against North Korean IT workers who infiltrate crypto firms under false identities. The United Nations Panel of Experts monitoring DPRK sanctions has warned that North Korean nationals placed in crypto and Web3 companies continue to generate revenue for weapons development.
For the industry, the Bitget breach reinforces a structural problem: centralized exchange custody remains a single point of failure regardless of trading volume or market share. Cold-storage ratios, multi-signature governance, and the hardening of signing infrastructure against supply-chain attacks have become the deciding factors in how much an exchange loses when, not if, an intrusion occurs.
Expect intensified scrutiny in the months ahead. OFAC and DOJ enforcement windows around laundering infrastructure tied to DPRK proceeds continue to widen, and exchanges face growing pressure to demonstrate verifiable custody controls to both regulators and institutional clients as the industry heads into a period of heightened security audits and proof-of-reserves verification.
via Google News - Crypto Hack Exploit (Source)