Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› Why do North Korean crypto theft campaigns cause…
Threats, Abuse & Incident Response

Why do North Korean crypto theft campaigns cause such outsized losses?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 10, 2026 Domain: Threats, Abuse & Incident Response

They focus on high-value workflows instead of high-volume noise. By concentrating social engineering on custody, treasury, and signing paths, attackers can convert a small number of successful intrusions into very large financial losses.

Why a Few Successful Intrusions Become Massive Crypto Losses

North Korean theft crews do not need broad, noisy access to inflict major damage. Their advantage is concentration: they look for the one workflow that can move or sign funds, then use social engineering, credential theft, or supply-chain compromise to reach that path. When the target is custody or treasury, even one compromise can convert into a very large loss.

The economics are asymmetric. A normal phishing campaign aims for lots of low-value victims; these campaigns aim for a small number of high-value operators, developers, or approvers. That means the loss profile is driven by the value of the workflow, not by the number of attempted intrusions. The same logic explains why Bybit hack 2025 produced such outsized damage after access to a signing path was obtained.

In practice, the most valuable targets are the places where one action can authorize many downstream transfers, such as hot wallets, multisig signers, treasury consoles, cloud sessions, or release pipelines. If attackers can impersonate or influence those functions, they do not need to drain accounts one by one. They can use a single trusted channel to move funds at scale, which is why BitMart hot wallet hack 2021 and similar incidents caused losses far beyond the initial intrusion effort.

Where the Attack Path Becomes Financially Explosive

The critical failure point is usually not malware volume, but trust concentration. Attackers focus on identities and sessions that can reach signing systems, treasury approvals, or code paths that influence payment logic. That is why a single stolen session token, revoked credential that was not actually revoked, or compromised development account can be enough to alter transaction behavior. Ledger Connect Kit npm compromise 2023 shows how a relatively small compromise can become a broader theft campaign when the trusted distribution path is poisoned.

This pattern also benefits from speed. Treasury and custody systems often reward fast action, while defenders need time to notice abnormal approvals, unusual signing requests, or session reuse from unexpected locations. If the attacker lands inside that narrow window, the blast radius is determined by how much authority the compromised path already carries. In other words, the campaign is not large because the attacker is noisy, it is large because the workflow is.

That is also why these operations often blend social engineering with technical compromise. The initial lure is frequently aimed at a person who can approve, sign, deploy, or recover access, because those roles sit at the intersection of trust and execution. Once the attacker owns that bridge, the rest is mechanically simple: reuse the authority, trigger the transfer, and exit before the discrepancy is reviewed.

What Practitioners Should Harden First

Defence should be organised around the highest-leverage action path, not around generic account hygiene alone. The first question is which identity, session, or approval path can move material value with the least friction. The second is whether that path is observable, time-bound, and separable from ordinary developer or operator access. Where possible, break up signing authority, enforce fresh authentication for high-risk actions, and require independent review for treasury changes.

Practitioners should also treat custody and treasury workflows as blast-radius problems. The goal is to make compromise expensive for the attacker, not merely inconvenient. That means monitoring for abnormal signing requests, tightening session lifetime, checking offboarding and token revocation, and reviewing whether any single role can still trigger an irreversible transfer without a second control. NIST SP 800-57 Key Management is useful where key lifecycle discipline is part of the control gap, and NIST SP 800-207 Zero Trust Architecture supports the broader principle of verifying each high-value action instead of trusting ambient access.

Risk and Threat Considerations

These campaigns are dangerous because they target authority density. The attacker does not need to compromise many endpoints if one compromised workflow can move large balances, alter wallet logic, or approve high-value transactions. That makes the real exposure a combination of privileged access, session trust, and operational urgency.

Failure mechanism: A trusted operator, developer, or signatory path is compromised, then reused to authorize transfers or alter signing behavior before the anomaly is contained.

Impact: A single foothold can produce outsized financial loss, rapid fund movement, and difficult recovery because the transactions are often valid from the system’s point of view.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-57, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-57Key ManagementCrypto theft loss often hinges on key custody and rotation discipline.
Recommendation — Apply key lifecycle controls to reduce the blast radius of signing-key compromise.
NIST Zero Trust (SP 800-207)Zero Trust ArchitectureHigh-value signing paths should not inherit broad ambient trust.
Recommendation — Verify each privileged action and narrow trust around custody workflows.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementToken, key, and session lifecycle failures directly enable theft paths.
Recommendation — Enforce lifecycle management for authenticators, tokens, and keys.
MITRE ATT&CKT1098 — Account ManipulationAttackers abuse or alter trusted accounts and approvals to keep access.
T1078 — Valid AccountsThe campaigns succeed by using legitimate access to execute theft.
Recommendation — Hunt for changes to privileged accounts, roles, and approval paths. Detect unusual use of valid accounts in high-value workflows.

Practitioner Guidance

What to prioritise: Start with the roles and sessions that can move value, not with the largest user populations. If one account can sign, approve, or modify payout logic, it deserves stricter controls than a dozen low-privilege accounts.

What to verify: Confirm that high-value workflows require fresh, bounded, and separately approved access. If a compromised session can still reach production signing or treasury actions, the control design is too permissive.

Common mistake: Treating wallet or treasury compromise as a pure malware problem. The more useful lens is authority concentration, because the attacker is exploiting a business process that can already cause irreversible loss.

Practitioner takeaway: The decisive defence is not reducing every intrusion opportunity equally, it is making sure no single compromise can directly reach large-value movement without detection, delay, and independent approval.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org