North Korea Stole $659M in Crypto Using Fake Job Seekers
On Tuesday, a joint coalition of the United States, Japan, and South Korea revealed that North Korean-backed state hackers plundered at least $659 million in cryptocurrency during 2024 while deploying highly deceptive IT workers to infiltrate global blockchain firms from within.
Inside the $659 Million Crypto Heist Campaign
According to a rare joint statement released by the trilateral alliance, Pyongyang’s cyber warfare capabilities reached devastating new heights this year. The official report offers the very first state-level confirmation linking North Korea directly to the massive $235 million hack of WazirX, India’s premier cryptocurrency exchange, in July 2024. That security breach crippled WazirX, forcing the platform to freeze all trading activities and undergo a complex corporate restructuring.
The Multi-Million Dollar Victim List
WazirX was far from the only target in the regime’s crosshairs. The joint government advisory detailed several other high-profile exploits executed throughout 2024, which include:
- DMM Bitcoin (Japan): A staggering $308 million drained from the platform.
- Upbit & Radiant Capital: Hit for $50 million each in separate attacks.
- Rain Management: Suffered a loss of $16.13 million.
How Lazarus Group Infiltrates Tech Firms
The notorious Lazarus Group—a state-sponsored hacking collective acting on behalf of the Democratic People’s Republic of Korea (DPRK)—has diversified its attack vectors. Instead of relying solely on brute-force network intrusions, the group heavily utilized sophisticated social engineering schemes and custom-built, crypto-stealing malware strains like “TraderTraitor” to compromise exchange security.
The Threat of Fake IT Job Seekers
Beyond external cyberattacks, North Korea is actively planting insider threats within the Web3 ecosystem. The trilateral statement warns that North Korean IT operatives are posing as legitimate freelance developers and job candidates to secure employment at blockchain companies. Once hired, these covert workers gain internal access, allowing them to facilitate devastating exploits from the inside.
“The United States, Japan, and the Republic of Korea advise private sector entities, particularly in blockchain and freelance work industries, to thoroughly review these advisories and announcements to better inform cyber threat mitigation measures and mitigate the risk of inadvertently hiring DPRK IT workers,” the coalition urged in their joint statement.
Funding Nuclear Ambitions with Digital Loot
The scale of North Korea’s illicit digital operations is monumental. Prior estimates compiled by the United Nations indicate that Pyongyang siphoned roughly $3 billion in cryptocurrency between 2017 and 2023. These stolen assets are directly utilized to bypass international sanctions and fund the isolated nation’s illicit nuclear weapons and ballistic missile programs.
The threat shows no signs of slowing down. Recent blockchain intelligence from Chainalysis highlights that North Korean cyber actors were responsible for a staggering 61% of all cryptocurrency stolen worldwide in 2024, bringing their total haul for the year to $1.34 billion.
