Beautiful Virgin Islands

Wednesday, May 13, 2026

FBI says North Korean hackers stole more than $600 million in cryptocurrency in single hack

FBI says North Korean hackers stole more than $600 million in cryptocurrency in single hack

The FBI on Thursday blamed hackers associated with the North Korean government for stealing more than $600 million in cryptocurrency last month from a video gaming company -- the latest in a string of audacious cyber heists tied to Pyongyang.
"Through our investigation we were able to confirm Lazarus Group and APT38, cyber actors associated with the DPRK, are responsible for the theft of $620 million in Ethereum reported on March 29th," the FBI said in a statement. "DPRK" is an abbreviation for North Korea's official name, the Democratic People's Republic of Korea, and Ethereum is a technology platform associated with a type of cryptocurrency.

The FBI was referring to the recent hack of a computer network used by Axie Infinity, a video game that allows players to earn cryptocurrency. Sky Mavis, the company that created Axie Infinity, announced on March 29 that unidentified hackers had stolen the equivalent of roughly $600 million -- valued at the time of the hack's discovery -- on March 23 from a "bridge," or network that allows users to send cryptocurrency from one blockchain to another.

The US Treasury Department on Thursday sanctioned Lazarus Group, a wide swath of hackers believed to work on behalf of the North Korean government. Treasury sanctioned the specific "wallet," or cryptocurrency address, that was used to cash out on the Axie Infinity hack.

Cyberattacks have been an important source of revenue for the North Korean regime for years as its leader, Kim Jong Un, has continued to pursue nuclear weapons, according to a United Nations panel and outside cybersecurity experts.

North Korea last month fired what is believed to be its first intercontinental ballistic missile in more than four years.

Lazarus Group has stolen an estimated $1.75 billion worth of cryptocurrency in recent years, according to Chainalysis, a firm that tracks digital currency transactions.

"A hack of a cryptocurrency business, unlike a retailer, for example, is essentially bank robbery at the speed of the internet and funds North Korea's destabilizing activity and weapons proliferation," said Ari Redbord, head of legal affairs at TRM Labs, a firm that investigates financial crime. "As long as they are successful and profitable, they will not stop."

While many cybersecurity analysts' attention has been on Russian hacking in light of the war in Ukraine, suspected North Korean hackers have been far from quiet.

Researchers at Google last month disclosed two different alleged North Korean hacking campaigns targeting US media and IT organizations, and cryptocurrency and financial technology sectors.

Google has a policy of notifying users who are targeted by state-sponsored hackers.

Shane Huntley, who leads Google's Threat Analysis Group, said that if a Google user has "any link to being involved in Bitcoin or cryptocurrency" and they get a warning about state-backed hacking from Google, it almost always ends up being North Korean activity.

"It seems to be an ongoing strategy for them to supplement and make money through this activity," Huntley told CNN.
Newsletter

Related Articles

Beautiful Virgin Islands
0:00
0:00
Close
The Great Western Exit: Why Best Citizens Are Fleeing the Rich World [PODCAST]
The New Robber Barons of Intelligence: Are AI Bosses More Powerful Than Rockefeller?
The End of the Old Order [Podcast]
Britain’s Democracy Is Now a Costume
The AI Gold Rush Is Coming for America’s Last Open Spaces [Podcast]
The Pentagon’s AI Squeeze: Eight Tech Giants Get In, Anthropic Gets Shut Out [Podcast]
The War Map: Professor Jiang’s Dark Theory of Iran, Trump, China, Russia, Israel, and the Coming Global Shock [Podcast]
Labour Is No Longer a National Party [Podcast]
AI Isn’t Stealing Your Job. It’s Dismantling It Piece by Piece.
Lawyers vs Engineers: Why China Builds While America Litigates [Podcast]
Churchill’s Glass: The Drunk, the Doctor, and the Myth Britain Refuses to Sober Up From
Apple issues an unusual warning: this is how your iPhone can be hacked without you doing anything
The Met Gala Meets the Age of Billionaire Backlash
Russian Oligarch’s Superyacht Crosses Hormuz via Iran-Controlled Route
Gunfire Disrupts White House Correspondents’ Dinner as Trump Is Evacuated
A Leak, a King, and a Fracturing Alliance
Inside the Gates Foundation Turmoil: Layoffs, Scrutiny, and the Cost of Reputational Risk
UK Biobank Breach Exposes Health Data of 500,000, Listed for Sale on Chinese Platform
KPMG Cuts Around 10% of US Audit Partners After Failed Exit Push
French Police Probe Suspected Weather-Data Tampering After Unusual Polymarket Bets on Paris Temperatures
News Roundup
Microsoft lost 2.5 millions users (French government) to Linux
Privacy Problems in Microsoft Windows OS
News roundup
Péter András Magyar and the Strategic Reset of Hungary
Hungary After the Landslide — A Strategic Reset in Europe
×