TL;DR: North Korean hackers stole $2.06 billion in cryptocurrency in 2025, accounting for 60% of all crypto theft losses and showing how high-value targeting, human manipulation, and rapid laundering now define the threat model, according to SumSub research. Identity programmes fail when trust and verification at the human boundary are easier to impersonate than to prove.
At a glance
What this is: This is a threat analysis of North Korean crypto theft patterns, showing that social engineering and identity manipulation sit at the front of a highly industrialised theft model.
Why it matters: It matters because identity teams must treat human verification, remote access trust, and withdrawal controls as connected defences, not separate checks, when attackers are manufacturing trust to reach crypto assets.
By the numbers:
- North Korean hackers stole $2.06 billion in cryptocurrency in 2025, accounting for 60% of all crypto theft losses that year.
- CertiK estimates that North Korea stole an estimated total of $6.75 billion across 263 documented incidents between 2016 and 2026.
- In one 2025 incident, North Korean hackers stole $1.5 billion from Bybit, the largest theft of cryptocurrency ever recorded.
- More than 86% of the stolen ETH in the Bybit case was laundered into Bitcoin within a month.
Context
North Korean crypto theft is not being described as opportunistic fraud, but as a repeatable identity-led intrusion pattern. The core problem is that attackers can impersonate investors, trading firms, or job candidates well enough to bypass human trust checks and reach privileged workflows.
The article frames this as a governance failure at the human boundary, where verification, access approval, and withdrawal control are treated as separate issues. In practice, these controls only work when they are linked to the same trust model across onboarding, remote work, and transaction approval.
The article's starting position is typical for modern crypto theft reporting: the most damaging incidents increasingly begin before any technical compromise is visible, with social engineering creating the opening.
Key questions
Q: What breaks when attackers can impersonate trusted counterparties in crypto environments?
A: The trust chain breaks before technical controls even see the attacker. When staff accept fabricated investors, vendors, or candidates as legitimate, they may grant access, share information, or approve actions that expose wallets, treasury paths, or operational accounts.
Q: Why do North Korean crypto theft campaigns cause such outsized losses?
A: They focus on high-value workflows instead of high-volume noise. By concentrating social engineering on custody, treasury, and signing paths, attackers can convert a small number of successful intrusions into very large financial losses.
Q: What are the warning signs that human manipulation is being used to reach crypto assets?
A: Look for unsolicited recruitment or investment contact, pressure to move off normal communication channels, unusual verification exceptions, and urgency around wallet access or withdrawals. Those signals often precede access abuse rather than follow it.
Q: When should organisations delay withdrawals or settlement in crypto workflows?
A: Use delays whenever a transfer depends on a recently verified identity, a new third party, or an unusual approval path. Delays create a containment window that can stop a successful social engineering event from becoming immediate asset loss.
Technical breakdown
Human manipulation as the initial access path
The article shows that major North Korean thefts often start with social engineering rather than software exploitation. Attackers pose as investors, trading firms, or job candidates, which means the first control failure is not technical authentication alone but the human decision to grant trust. In identity terms, this is a boundary problem between assurance and access: if the organisation cannot distinguish genuine counterparties from fabricated ones, downstream privileges become reachable through social proof instead of verified identity. The pattern is especially dangerous in crypto, where remote work, cross-border hiring, and high-velocity transactions compress decision time.
Practical implication: tie onboarding, vendor contact, and privileged access approvals to stronger verification than email or chat-based trust signals.
Why high-value targets matter more than incident count
CertiK’s analysis says only 12% of documented incidents in 2025 were linked to North Korea, yet those incidents drove 60% of all crypto theft losses. That gap shows a selection strategy aimed at impact, not volume. For identity governance, the lesson is that threat models must account for adversaries who concentrate effort on a few privileged workflows, custody paths, or treasury operations rather than spraying broad attacks. The control question becomes whether the organisation can protect the specific identities and approval chains that unlock outsized value, not whether it has generic perimeter defences.
Practical implication: prioritise identity controls around treasury, hot wallets, and high-approval workflows rather than spreading effort evenly across all accounts.
Rapid laundering turns theft into irreversible loss
The Bybit case shows how quickly stolen crypto can be moved once the attacker has succeeded. CertiK says more than 86% of the stolen ETH was laundered into Bitcoin within a month, which collapses the recovery window and makes post-breach response largely reactive. This is important for identity teams because the consequence of manipulation is not only initial access, but also the speed at which the value can be converted, fragmented, and dispersed. When laundering pipelines are fast, the security programme has to treat detection latency as a value-loss multiplier.
Practical implication: connect identity abuse monitoring to withdrawal delay, anomaly detection, and transaction approval holds before funds exit controlled paths.
Threat narrative
Attacker objective: The objective is to convert manufactured human trust into direct theft of cryptocurrency and fast, difficult-to-recover laundering.
- Entry begins with human manipulation, where attackers impersonate investors, trading firms, or job candidates to gain trust and access to sensitive workflows.
- Credential or approval abuse follows when the fabricated identity is accepted into remote work, hiring, or operational channels that can influence crypto infrastructure.
- Impact occurs when the attackers reach high-value targets such as hot wallets or treasury workflows and move stolen assets rapidly into laundering channels.
Breaches seen in the wild
- Bybit hack 2025: Hijacked AWS session tokens from a Safe{Wallet} developer's laptop let attackers alter signing code and steal about $1.5 billion from Bybit.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Human manipulation is the real identity primitive in modern crypto theft: the attacker does not need to break authentication if they can manufacture trust at the human boundary. In this pattern, identity assurance fails before a login ever occurs because the organisation treats social plausibility as a proxy for legitimacy. The practitioner conclusion is that human verification and access approval must be governed as one trust chain, not separate controls.
The $2.06 billion loss figure shows concentration, not randomness: 60% of all crypto theft losses in 2025 were linked to North Korean hackers, which means the threat is optimised for payoff. That concentration changes how identity security should be prioritised, because treasury, custody, and approval identities now carry disproportionate risk. The practitioner conclusion is to protect the few identities that move value, not just the many identities that access systems.
Rapid laundering creates identity governance pressure after compromise: when more than 86% of stolen ETH can be converted within a month, the response window is shorter than many investigation cycles. That means verification failure and recovery failure are linked, because once the value moves, proof of identity no longer rescues the asset. The practitioner conclusion is to treat withdrawal controls, liveness checks, and delayed settlement as identity-adjacent containment measures.
AI-enhanced social engineering will widen the gap between appearance and assurance: the article’s warning about borrowed identities and AI-driven manipulation points to a stronger impersonation layer, not just more phishing. That does not change the underlying problem, which is that many identity programmes still rely on surface signals that can be convincingly manufactured. The practitioner conclusion is to re-evaluate where your programme still trusts presentation over proof.
Identity blast radius is now tied to financial workflow design: the article makes clear that hot wallets and bridges are not only technical assets, they are identity-dependent value gates. Once an attacker reaches the right human or service approval path, the blast radius is defined by how much can be withdrawn before challenge. The practitioner conclusion is to design governance around value movement, not just account access.
What this signals
Identity governance now has to treat social engineering as a control-path problem: when attackers can present a believable human face, the weak point is often the approval workflow, not the credential store. Organisations that separate verification from authorisation leave a gap that sophisticated manipulation can exploit.
Crypto theft is moving toward value-centric targeting: the article shows that a small share of incidents can drive the majority of losses when attackers aim at treasury and custody paths. That means security priorities should be shaped by where value moves, not by account counts or ticket volumes.
For practitioners
- Tighten human verification for high-risk access Require video interviews with liveness checks and background verification for roles that can reach custody, treasury, or signing workflows. Use stronger verification for remote freelancers and third parties than for ordinary corporate access.
- Apply zero-trust policies to external workers Treat remote freelancers, contractors, and vendors as untrusted until they are continuously verified, with scoped access and explicit approval for privileged activity.
- Add withdrawal delays to transaction workflows Insert approval holds or time delays before withdrawals can leave controlled paths, so social engineering cannot immediately convert identity abuse into irreversible loss.
- Protect bridges and hot wallets as identity-critical assets Classify bridges, hot wallets, and signing systems as high-risk identity and value controls, then subject them to tighter approval, monitoring, and separation of duties.
- Train staff on manipulation patterns that mimic legitimate counterparties Teach employees to challenge investor outreach, recruitment contact, and partner requests that create urgency, authority, or secrecy around access and transfers.
Key takeaways
- North Korean crypto theft in this article is driven by manufactured trust at the human boundary, not just by technical compromise.
- The scale is concentrated, with $2.06 billion stolen in 2025 and more than 86% of stolen ETH in the Bybit case laundered within a month.
- The most effective limits are stronger identity verification, tighter approval paths, and withdrawal delays that slow conversion after manipulation succeeds.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The article centers on human and borrowed identities being accepted as legitimate access paths. |
| NHI-10 — Human Use of NHI | Attackers exploit people and human trust to reach machine and wallet access paths. | |
| NHI-05 — Overprivileged NHI | The highest-impact losses come from identities that can move value too easily once trust is gained. | |
| Recommendation — Strengthen verification gates so impersonated identities cannot reach privileged crypto workflows. Separate human approval from asset movement so social trust cannot directly trigger NHI actions. Reduce wallet and treasury privilege to the minimum needed for each operational path. | ||
| MITRE ATT&CK | TA0001;TA0006;TA0010 — Initial Access; Credential Access; Exfiltration | The article describes social engineering entry, trust abuse, and rapid asset movement. |
| Recommendation — Map manipulation-led theft chains to TA0001, TA0006, and TA0010 to improve detection coverage. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account governance and approval paths are central to controlling who can reach crypto assets. |
| Recommendation — Use account management controls to restrict and review access to custody and withdrawal functions. | ||
Key terms
- Human Manipulation: A social engineering pattern where an attacker uses believable identity cues, urgency, or authority to influence a person into granting access or approving an action. In crypto environments, it often targets onboarding, vendor contact, or withdrawal approval rather than the wallet itself.
- Withdrawal Delay: A control that creates a waiting period or approval hold before funds can leave a controlled crypto workflow. It reduces the chance that a successful impersonation or insider abuse becomes immediate, irreversible asset loss.
- Custody Workflow: The operational path used to hold, approve, transfer, or sign crypto assets. It is an identity-sensitive process because the people, services, and approvals inside it determine whether value movement is legitimate or abusive.
- Active Liveness Check: An active liveness check requires the user to complete a prompt during verification, such as blinking, smiling, or turning the head. The system uses the response to confirm presence and detect replay or spoofing attempts. It is stronger against fraud, but it adds friction and depends on user participation.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org