< Back to situation

[REVISION HISTORY]

North Korean cryptocurrency hacking and supply‑chain attacks

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-07-26 03:17 UTC → 2026-07-30 04:33 UTC · added removed

North Korean cryptocurrency hacking and supply‑chain attacks

In early July 2026, 2026 a TRM Labs report estimated that analysis linked North Korean‑linked Korean‑affiliated groups stole roughly to about $643 million in cryptocurrency crypto theft during the first half of 2024, accounting for about roughly two‑thirds of global crypto‑hacking losses. The bulk of the theft came loss stemmed from breaches of two DeFi platforms, underscoring platforms. Around the scale of Pyongyang’s illicit earnings. Later that month, same time Fireblocks revealed a set of disclosed critical “BitForge” vulnerabilities affecting in threshold‑signature schemes used by more than 15 custodial wallets. Demonstrated at Black Hat USA 2023, the flaws could allow wallets, demonstrating how nation‑state actors such as the Lazarus group to could extract private keys from multi‑party computation systems. In parallel, Late July saw a rare domestic crackdown: on 12 July North Korean authorities announced the arrest detained a cadre of former state‑run cyber operators—identified as former military hackers from the Reconnaissance and Intelligence General Bureau—who allegedly hacked Bureau, accusing them of breaching the Central Bank and the Foreign Trade Bank, funneled the proceeds moving state‑owned foreign‑currency funds into overseas crypto wallets, wallets and laundered laundering the assets proceeds through China‑based Chinese brokers. Equipment was seized and officials warned of severe repercussions for the suspects’ families. A separate development emerged on 29 July when Amazon Threat Intelligence uncovered a coordinated North Korean supply‑chain operation that compromised popular npm packages such as axios, debug and chalk. Using AI‑generated identities and a “distributed payload” technique, the group inserted malicious code to steal cryptocurrency and fund the DPRK’s weapons programs. The detentions, reported by Daily NK campaign builds on earlier 2025 rehearsals and other outlets, signal reflects an internal crackdown on cyber‑crime expanding toolkit that previously targeted external victims. targets global software ecosystems alongside direct crypto‑theft. Together, these developments trace events illustrate a persistent pattern of large‑scale crypto cryptocurrency theft attributed to by North Korean actors, new defensive disclosures exposing systemic wallet risks, evolving technical tactics that now include open‑source software supply‑chain compromise, and a rare domestic an internal law‑enforcement response aimed at curbing both external and internal cryptocurrency‑linked illicit cyber operations. activities.

Versions

  1. 2026-07-30 04:33 UTC North Korean cryptocurrency hacking and supply‑chain attacks
  2. 2026-07-26 03:17 UTC North Korean cryptocurrency hacking

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.