{"id":554722,"date":"2026-02-12T04:10:44","date_gmt":"2026-02-12T04:10:44","guid":{"rendered":"https:\/\/Blockchain.News\/news\/crypto-hackers-stole-3-4b-2025-north-korea-lazarus-group"},"modified":"2026-02-12T04:10:44","modified_gmt":"2026-02-12T04:10:44","slug":"crypto-hackers-stole-3-4b-in-2025-as-north-korea-dominates-attacks","status":"publish","type":"post","link":"https:\/\/e-bitco.in\/index.php\/2026\/02\/12\/crypto-hackers-stole-3-4b-in-2025-as-north-korea-dominates-attacks\/","title":{"rendered":"Crypto Hackers Stole $3.4B in 2025 as North Korea Dominates Attacks"},"content":{"rendered":"<figure class=\"figure mt-2\">\n<p> <a href=\"https:\/\/blockchain.news\/Profile\/Jessie-A-Ellis\">Jessie A Ellis<\/a> <span class=\"publication-date ml-2\"> Feb 12, 2026 04:10<\/span> <\/p>\n<p class=\"lead\">Fireblocks report reveals $17B stolen since 2020, with DPRK&#8217;s Lazarus Group behind 75% of crypto platform attacks. Defense-in-depth approach now critical.<\/p>\n<p> <a href=\"https:\/\/image.blockchain.news:443\/features\/9BED484F63152ECD2721498B93AEE806A0F7F6C0430821D708627253D13A3405.jpg\"> <img decoding=\"async\" class=\"rounded\" src=\"https:\/\/image.blockchain.news:443\/features\/9BED484F63152ECD2721498B93AEE806A0F7F6C0430821D708627253D13A3405.jpg\" alt=\"Crypto Hackers Stole $3.4B in 2025 as North Korea Dominates Attacks\"> <\/a> <\/figure>\n<p>Cryptocurrency hackers made off with $3.4 billion in 2025, pushing total stolen digital assets past $17 billion since 2020, according to a new security white paper from institutional custody provider Fireblocks.<\/p>\n<p>The numbers paint a stark picture: North Korea&#8217;s Lazarus Group now accounts for roughly three-quarters of all attacks on crypto platforms. Their operations average nearly five times the haul of other threat actors, with DPRK-linked hackers responsible for over $2 billion of last year&#8217;s losses alone.<\/p>\n<h2>Crime Goes Corporate<\/h2>\n<p>What&#8217;s changed isn&#8217;t just the scale\u2014it&#8217;s the sophistication. These aren&#8217;t basement hackers anymore. They&#8217;re running what amounts to criminal enterprises with business development teams, revenue targets, and customer service.<\/p>\n<p>The emergence of &#8220;Drainer-as-a-Service&#8221; platforms has democratized crypto theft. Developers build turnkey wallet-draining kits and license them to non-technical affiliates on revenue-share deals. Think SaaS, but for stealing your tokens. These groups compete for market share like legitimate software companies.<\/p>\n<p>Fireblocks identified three primary threat categories in their analysis: state-sponsored operations (primarily DPRK), commoditized crime-as-a-service offerings, and the perennial insider threat from employees and contractors with legitimate access.<\/p>\n<h2>Why Crypto Security Differs From Traditional IT<\/h2>\n<p>Here&#8217;s the uncomfortable truth that makes digital asset security fundamentally different: attackers only need to win once. When a malicious transaction hits blockchain finality, those funds are gone. There&#8217;s no IT team restoring from backup, no insurance claim that makes you whole.<\/p>\n<p>&#8220;Nearly all digital asset theft incidents stem from actions that were &#8216;technically authorized&#8217; by weak policies,&#8221; the Fireblocks report states. A stolen credential combined with lax governance equals permanent loss.<\/p>\n<p>The company, which claims to have secured over $10 trillion in digital asset transfers across 550 million wallets, advocates for what they call an &#8220;Assume Breach&#8221; architecture. Multiple independent security layers must protect funds even when individual components get compromised.<\/p>\n<h2>Practical Defense Layers<\/h2>\n<p>The white paper outlines several critical controls. A cryptographically enforced policy engine sits at the core\u2014ensuring stolen credentials alone can&#8217;t authorize transfers. Transaction clarity features decode complex smart contract interactions into readable actions, killing &#8220;blind signing&#8221; scenarios where approvers unknowingly authorize malicious unlimited token approvals.<\/p>\n<p>This layered approach mirrors broader cybersecurity trends. Recent industry data shows identity misuse\u2014stolen credentials and privilege abuse\u2014factors into over 80% of ransomware operations. Backups, often considered the last line of defense, get compromised in 39% of incidents.<\/p>\n<p>The timing of Fireblocks&#8217; report coincides with heightened cyber pressure across sectors. Google flagged sustained attacks on defense industrial bases from Russia and China-linked actors this week, while the FCC urged communications providers to strengthen ransomware defenses.<\/p>\n<h2>What This Means for Institutions<\/h2>\n<p>For institutional players managing client funds, the message is clear: point solutions won&#8217;t cut it against adversaries running professional operations. The Fireblocks framework suggests every identified threat vector should face at least three independent protection layers.<\/p>\n<p>With the total crypto market cap sitting at $2.34 trillion, the $17 billion stolen since 2020 represents a meaningful percentage of industry value. As threats continue evolving, security architecture that assumes eventual compromise\u2014rather than hoping to prevent it entirely\u2014may be the only realistic approach.<\/p>\n<p><span><i>Image source: Shutterstock<\/i><\/span> <!-- Divider --> <!-- Author info END --> <!-- Divider --> <a href=\"https:\/\/blockchain.news\/\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Jessie A Ellis Feb 12, 2026 04:10 Fireblocks report reveals $17B stolen since 2020, with DPRK&#8217;s Lazarus Group behind 75% of crypto platform attacks. Defense-in-depth approach now critical. Cryptocurrency hackers made off with $3.4 billion in 2025, pushing total stolen digital assets past $17 billion since 2020, according to a new security white paper from [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":554723,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[12193,229,22545,5389,25,4113],"class_list":{"0":"post-554722","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-blockchain","8":"tag-crypto-security","9":"tag-cybersecurity","10":"tag-digital-asset-theft","11":"tag-lazarus-group","12":"tag-news","13":"tag-north-korea-hackers"},"_links":{"self":[{"href":"https:\/\/e-bitco.in\/index.php\/wp-json\/wp\/v2\/posts\/554722","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/e-bitco.in\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/e-bitco.in\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/e-bitco.in\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/e-bitco.in\/index.php\/wp-json\/wp\/v2\/comments?post=554722"}],"version-history":[{"count":0,"href":"https:\/\/e-bitco.in\/index.php\/wp-json\/wp\/v2\/posts\/554722\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/e-bitco.in\/index.php\/wp-json\/wp\/v2\/media\/554723"}],"wp:attachment":[{"href":"https:\/\/e-bitco.in\/index.php\/wp-json\/wp\/v2\/media?parent=554722"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/e-bitco.in\/index.php\/wp-json\/wp\/v2\/categories?post=554722"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/e-bitco.in\/index.php\/wp-json\/wp\/v2\/tags?post=554722"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}