Get alerts on this situation
We’ll email you as it develops, and you can follow the whole thread from day one.
Unsubscribe anytime.
[SITUATION] · [ACTIVE]
4 clusters · 17 sources · 27 days · First seen · Last updated
Categories: TECHNOLOGY · CRIME
North Korean cryptocurrency hacking and supply‑chain attacks
Entities: Amazon Threat Intelligence · North Korean state‑sponsored hacking groups · axios (npm package) · chalk (npm package) · debug (npm package)
Overview
In early July 2026 a TRM Labs analysis linked North Korean‑affiliated groups to about $643 million in crypto theft during the first half of 2024, roughly two‑thirds of global crypto‑hacking losses. The bulk of the loss stemmed from breaches of two DeFi platforms. Around the same time Fireblocks disclosed critical “BitForge” vulnerabilities in threshold‑signature schemes used by custodial wallets, demonstrating how nation‑state actors could extract private keys from multi‑party computation systems.
Late July saw a rare domestic crackdown: on 12 July North Korean authorities detained a cadre of former military hackers from the Reconnaissance and Intelligence General Bureau, accusing them of breaching the Central Bank and the Foreign Trade Bank, moving state‑owned foreign‑currency funds into overseas crypto wallets and laundering the proceeds through Chinese brokers. Equipment was seized and officials warned of severe repercussions for the suspects’ families.
A separate development emerged on 29 July when Amazon Threat Intelligence uncovered a coordinated North Korean supply‑chain operation that compromised popular npm packages such as axios, debug and chalk. Using AI‑generated identities and a “distributed payload” technique, the group inserted malicious code to steal cryptocurrency and fund the DPRK’s weapons programs. The campaign builds on earlier 2025 rehearsals and reflects an expanding toolkit that targets global software ecosystems alongside direct crypto‑theft.
Together, these events illustrate a persistent pattern of large‑scale cryptocurrency theft by North Korean actors, evolving technical tactics that now include open‑source software supply‑chain compromise, and an internal law‑enforcement response aimed at curbing both external and internal illicit cyber activities.
Timeline
-
about 13 hours ago
[TECHNOLOGY] 4 sourcesNorth Korean hackers compromise npm packages axios, debug, and chalkNorth Korean state‑sponsored hackers used AI‑enhanced social engineering and distributed payloads to compromise npm packages axios, debug and chalk, aiming to steal cryptocurrency and fund DPRK weapons programs
-
5 days ago
[CRIME] 5 sourcesNorth Korea arrests former military hackers accused of stealing state bank funds via cryptocurrencyNorth Korea arrested former military hackers on July 12, accusing them of breaching state banks and laundering stolen funds via cryptocurrency, though the claims are unverified.
-
7 days ago
[TECHNOLOGY] 6 sourcesNorth Korean Crypto Threats Spur Security Reveal and ArrestsFireblocks revealed “BitForge” crypto wallet flaws that could aid nation‑state attackers like North Korea’s Lazarus group, while North Korean officials reportedly arrested a team accused of hacking state banks
-
27 days ago
[CRIME] 2 sourcesNorth Korea-linked hackers seize $643 million in crypto, 66% of H1 global lossNorth Korean-linked hackers stole about $643 million in crypto in H1 2024, representing 66 % of the $972 million global crypto‑hacking loss, mainly from two DeFi platform breaches.
Sources
abmedia.io · cointelegraph.com · crypto-news-flash.com · cryptobriefing.com · cryptopolitan.com · cyberscoop.com · cybersecuritynews.com · en.coin-turk.com · flagthis.com · livecoins.com.br · news-krypto.de · news.donga.com · opensourceforu.com · police.cz · spacemoney.com.br · stv.seoul.co.kr · tokenpost.com
This summary has been updated 1 time: see revision history