What is North Korea?
North Korea is a country that the FBI has stated was responsible for the theft of approximately $1.5 billion in virtual assets from cryptocurrency exchange Bybit.
Company timeline
- May 2026 – Ari Redbord stated that North Korea stole $1.5 billion in Ethereum and converted almost all of it within 72 hours, using services it typically uses. He noted that North Korean proxies sat across tables from protocol employees over months, indicating social engineering at scale. He also observed that North Korea moved funds faster than ever before, attributing it to access to liquidity via Chinese criminal networks.
- May 2026 – Lukas Czinger described North Korea as a “paper tiger” that may not have updated its weapon systems and technology.
- Jun 2026 – Sarah Paine said sanctions prevent one to two percent growth per annum, and over generations this difference explains the gap between North and South Korea.
- Jul 2026 – Santiago Santos said the first half of the year was the highest in crypto history with 212 exploits and over $1 billion lost, three to three and a half times more than last year, and that North Korea’s Lazarus Group is responsible for half or more than half of that.
- Aug 2026 – Laura Shin said every significant crypto company dating back to at least 2020 has had an IT worker, many having 10, and that North Korea just doesn’t do these types of attacks. Another speaker noted that a nation state seeking a foothold in the future would target small companies to grow with them, and an unclear source said that assets under custody with no time lock are dangerous and make a target for North Korea, as seen with the Drift hack.
Where it appears in the record
Every line below is attributed to a named speaker.
North Korea converted nearly all of $1.5 billion in stolen Ethereum from the Bybit hack into other assets within the first 72 hours.
“Essentially, North Korea stole 1.5 billion in Ethereum. And within the first 72 hours, converted almost all of that And then started using the services that North Korea typically uses.”Ari Redbord · 11 May 2026
A researcher embedded in DPRK systems for 22 months observed operations touching 1,600 companies across 57 countries.
“He was he was in these systems for something like 22 months just watching them do their you know, 1,600 companies, 57 countries are impacted.”Patrick Gray · 12 Aug 2026
DPRK hackers were found inside major enterprises including Aon, Oppo, Coinbase, Uniswap Labs, and Italy's Supreme Judicial Council, contradicting the assumption that their campaigns mostly hit small to medium targets.
“I've always just thought that the other stuff going on is probably a long tail of small to medium actors on small to But these are big names that they were found in this research set like Aon Smart Technologies, Chinese phone manufacturer Oppo, crypto currency firms like Coinbase, Uniswap Labs, Italy Supreme Judicial Council.”Patrick Gray · 12 Aug 2026
Chinese criminal networks share wallet addresses across cartel, North Korean, and pig-butchering operations, revealing a single consolidated laundering infrastructure serving multiple threat actors.
“If you look on chain at cartel activity, North Korea hacks, and these pig butchering networks, you see wallet addresses that are being used in all three of those laundering typologies or th- those threat categories, that we associate with Chinese money laundering networks.”Ari Redbord · 11 May 2026
North Korean operatives meet protocol employees face-to-face at conferences over months to gain access, contradicting the assumption they operate purely through remote intrusion.
“North Korean proxies sitting across a table from protocol employees over a period of months.”Ari Redbord · 11 May 2026
After the Bybit hack, North Korea laundered funds faster and with more liquidity access than ever before, attributed not to internal capability gains but to Chinese criminal networks.
“We saw North Korea move faster than ever before. It was clear to us that they had more access to liquidity than ever before. And I think that's a result of these Chinese criminal networks that are laundering the funds.”Ari Redbord · 11 May 2026
North Korea's Lazarus group is not merely sharing tools with ransomware crews but operating as a unified team, evidenced by identical malware filenames, execution arguments, and SSH keys.
“That's not sharing at all. That's literally like sitting down together working as a team.”Patrick Gray · 5 Aug 2026
Sarah Paine describes sanctions as economic chemotherapy, arguing even leaky ones suppress growth enough to explain the North/South Korea divergence.
“Sanctions are like economic chemotherapy. What you're doing is presenting pre preventing one or two percent growth per animal even with leaky sanctions, right? Well, and you go, 'So what?' Well, oh no. So very what is the difference over several generations is the difference between North and South Korea.”Sarah Paine · 9 Jun 2026
Ari Redbord on North Korean cyber tactics shifting from systems to people.
“What we've really moved from is sort of just going after the technology to going after the people and it's really social engineering at scale.”Ari Redbord · 11 May 2026
Even leaky sanctions that trim only 1 to 2 percent annual growth compound across generations to produce the vast development gap visible between North and South Korea.
“Sanctions are like economic chemotherapy. What you're doing is presenting pre preventing one or two percent growth per animal even with leaky sanctions, right? Well, and you go, 'So what?' Well, oh no. So very what is the difference over several generations is the difference between North and South Korea.”Sarah Paine · 9 Jun 2026