North Korean Hackers Steal $1.6 Billion in Crypto, 2025

3 Min Read

  • North Korean hackers reportedly stole $1.6 billion in cryptocurrencies by 2025, using fake job offers and sophisticated malware.
  • The hacking groups, known as UNC4899, TraderTraitor, Jade Sleet, and Slow Pisces, targeted cloud systems of major crypto companies.
  • These cybercriminals manipulated social media interactions to gain trust and access sensitive company information.
  • Their attacks focused on companies utilizing cloud-first infrastructures like Google Cloud and AWS, leading to significant financial losses.
  • A surge in fake IT job listings facilitated these breaches, particularly affecting cryptocurrency exchanges.

North Korean Hackers Exploit Crypto Sector with Fake Job Offers

In a staggering revelation from a Google Cloud report, North Korean hackers have escalated their attacks on the cryptocurrency industry in 2025. These cybercriminals stole over $1.6 billion using elaborate schemes involving fake job offers and cutting-edge malware. Particularly alarming is their method of gaining unauthorized access to cloud systems by posing as recruiters or experts in various fields.

The Rise of Sophisticated Cyber Threats

The group identified as UNC4899—or TraderTraitor among other aliases—has been under close watch for its advanced infiltration techniques. They primarily focus on building trust through social media before sending malicious scripts disguised as test assignments. This approach grants them remote access to company cloud environments where they can steal credentials and target nodes responsible for processing crypto transactions.

Targeting Cloud Infrastructures

Both Google Cloud and AWS have been victims of these sophisticated attacks which resulted in multi-million-dollar losses in cryptocurrencies. According to Jamie Collier from the Google Threat Intelligence Group, North Korean hackers frequently impersonate professionals such as journalists or professors to enhance credibility through AI-driven communication strategies.

Evolving Tactics: From JavaScript Attacks to IT Job Scams

TraderTraitor’s hacking campaigns began around 2020 with attacks through malicious crypto applications built on JavaScript (Electron). By 2024-2025, their tactics evolved into mass phishing via fake IT job listings—a strategy that heavily targeted cryptocurrency exchanges.

Major Heists Shake Crypto Markets

Some of the most notable breaches include a $303 million hack of Japan’s DMM Bitcoin exchange and a colossal $1.5 billion theft from Bybit reported in early 2025. Benjamin Read from Wiz highlights that TraderTraitor’s focus on cloud-based attacks stems from the industry’s reliance on cloud-first infrastructures—where data equates to money.

Growing Threat Landscape

Estimates suggest thousands may be involved with TraderTraitor across interconnected hacker groups. TRM Labs previously reported over $2.1 billion lost in the crypto sector during the first half of 2025 alone. Google’s warning about expanding North Korean hacker activities underscores an urgent need for heightened cybersecurity measures across the industry.
The persistent evolution of these threats presents significant challenges but also opportunities for innovation within cybersecurity practices tailored specifically toward safeguarding digital assets against increasingly sophisticated adversaries.

Anthropic Reveals Scientists Used Claude in Dangerous Biological Research

Anthropic said it blocked accounts in five Claude-assisted projects involving chikungunya, avian influenza, orthopoxviruses, poisons and toxins whose results could potentially support biological weapons development, but found no evidence of…

7 Min Read
Blockstream Refused to Pay Liquid Hackers Ransom for Remaining 598 BTC

After 3,400 BTC was returned following the September 6 Liquid Network incident, Blockstream said it would not pay a ransom for the remaining about 598.5 BTC, worth roughly $47 million.

3 Min Read
India Targets Tokenizing $627 Billion Worth of Corporate Bonds

India’s Securities and Exchange Board launched the Demat 2.0 pilot linking tokenized corporate bonds to the wholesale digital rupee, with three companies issuing 10.25 billion rupees in bonds by Sept.…

5 Min Read
US Treasury’s Over-$5B Buyback Fails to Halt 10-Year Bond Sell-Off

The U.S. Treasury accepted $5.2 billion in offers during its first expanded long-term bond buyback on September 10, while the 10-year yield subsequently approached 4.98%.

6 Min Read
Mexican Authorities Find 300-GPU Crypto Farm, Suspect Electricity Theft

Mexican authorities uncovered a suspected illegal cryptocurrency mining farm near the Necaxa dam in Tlaola, Puebla, finding about 300 GPUs and investigating possible electricity theft and money laundering.

4 Min Read