Full Breakdown
North Korean Hackers Steal Over $2 Billion in Cryptocurrency in 2025, CrowdStrike Report Finds
5/15/2026, 12:07:55 PM
Scale of the 2025 Crypto Heist
The 2026 Financial Services Threat Landscape Report by CrowdStrike attributes $2.02 billion in cryptocurrency theft to North Korean state-sponsored actors in 2025, a 51 % year-on-year rise. A single PRESSURE CHOLLIMA operation accounted for $1.46 billion.
Shift Toward DeFi Platforms
Previously focused on banks and insurers, North Korean cyber units shifted in 2025 toward DeFi platforms and exchanges, attracted by Web3 anonymity and easier laundering of digital assets.
Key North Korean Groups
Four groups were highlighted: PRESSURE CHOLLIMA used trojanised supply-chain software; GOLDEN CHOLLIMA employed recruitment-themed lures to breach cloud environments in Southeast Asia and Canada; FAMOUS CHOLLIMA doubled operations with AI-generated identities; STARDUST CHOLLIMA tripled activity using AI-generated recruiter personas and synthetic video meetings across North America, Europe and Asia.
Data & Statistics
The report noted a 43 % global rise in hands-on-keyboard intrusions against financial institutions over two years and a 27 % increase in financial services firms appearing on public leak sites, reaching 423 entities in 2025.
Why It Matters
The stolen assets are believed to fund North Korea’s weapons programs, bypassing UN sanctions. The attacks expose weaknesses in smart-contract code, private-key management and cross-chain bridge security, prompting calls for stronger defenses and regulatory oversight.
Official Statements & Responses
CrowdStrike called the findings a “clear, data-driven picture of an evolving threat landscape” and warned AI-enabled deception lowers the cost of identity fabrication. The United Nations and several governments have condemned the illicit fundraising and urged international cooperation to track, freeze and recover stolen assets.
Criticism & Opposition
Industry analysts argue many cryptocurrency platforms have not prioritized security sufficiently, noting the $2 billion loss highlights gaps in threat detection, incident response and multi-signature custody. The report’s authors call for accelerated investment in advanced detection tools and regular security audits.
Conflicting Reports & Gaps
The two sources differ on the total amount stolen—one cites $2.02 billion, the other “more than $2 billion.” Neither provides a detailed breakdown of the assets’ final destinations, leaving a gap in understanding the full financial flow.
Verbatim Quotes
- “Financial services organizations face threats from every direction and AI is making each of them harder to stop. The cost to create convincing identities, automate reconnaissance, and accelerate credential theft is near zero,” — Adam Meyers, Head of Counter Adversary Operations, CrowdStrike
- “CrowdStrike described it as the largest financial theft yet reported.” — CrowdStrike, 2026 Financial Services Threat Landscape Report
- “Implications for the Crypto Industry The report serves as a stark warning for cryptocurrency businesses and investors.” — CrowdStrike, 2026 Financial Services Threat Landscape Report
- “For the cryptocurrency industry, the message is unequivocal: security must remain the highest priority.” — MEXC (cryptocurrency news outlet)
What’s Next
Industry observers expect cryptocurrency platforms to adopt advanced threat detection, conduct regular security audits, implement multi-signature and cold-storage solutions, and develop rapid incident-response protocols. International law-enforcement agencies have pledged continued cooperation to trace, freeze and recover illicit proceeds.
