How the World is Fighting North Korean Crypto Crime
Oct, 10 2026
Imagine losing $1.5 billion in a single afternoon because of a cleverly disguised digital heist. That’s exactly what happened to ByBit in February 2025, when the largest single cryptocurrency theft in history struck the exchange. The culprit? Not a lone hacker in a basement, but state-sponsored actors from North Korea. For years, the world watched as Pyongyang siphoned billions from the global crypto economy to fund its weapons programs. But recently, the international response has shifted from passive observation to aggressive, coordinated action.
You might wonder how the world coordinates against a country that barely participates in the global financial system. The answer lies in a new, agile coalition called the Multilateral Sanctions Monitoring Team (MSMT). Established in October 2024 after the UN Panel of Experts dissolved, this group of 11 nations-including the US, UK, Japan, and Germany-has taken over the job of tracking North Korea’s digital crimes. They aren’t just writing reports; they are freezing assets, training analysts, and hunting down stolen funds with a speed that traditional diplomacy never managed.
The Rise of the Multilateral Sanctions Monitoring Team
When the UN Panel of Experts ended in May 2024, many feared a vacuum in enforcement. North Korea seemed poised to exploit the gap. Instead, the MSMT filled it. This isn’t your typical slow-moving diplomatic body. It operates like a specialized task force, sharing intelligence in real-time among member nations. Their first major joint statement in October 2025 labeled North Korea’s cyber operations as "a sophisticated global criminal enterprise." This language matters. It moves the conversation from abstract sanctions violations to concrete criminal activity, allowing for faster legal actions.
The MSMT’s structure is designed for efficiency. Unlike the UN, which requires consensus from veto-wielding powers like Russia and China, the MSMT allows like-minded nations to act quickly. This agility has been crucial. In the first half of 2025 alone, the team documented over $2.17 billion in cryptocurrency thefts linked to Pyongyang. Without this rapid-response framework, those funds would likely have vanished into the murky waters of decentralized finance before anyone could react.
Lazarus Group and the Reconnaissance General Bureau
Who is actually pulling the trigger on these hacks? Most experts point to the Lazarus Group, a cyber-espionage unit under North Korea’s Reconnaissance General Bureau. This isn’t a rogue gang; it’s a military operation. The Reconnaissance General Bureau directs Lazarus to steal crypto not just for profit, but to bypass strict international sanctions on oil and luxury goods.
The scale is staggering. According to TRM Labs, North Korean actors accounted for roughly 35% of all cryptocurrency funds stolen globally in 2024. By late 2025, that number had climbed, with cumulative known thefts exceeding $6 billion since tracking began. These funds directly support the regime’s nuclear and missile programs. Every dollar stolen is a dollar that doesn’t go through official trade channels, making it invisible to standard banking oversight.
Technical Warfare: How They Steal and Launder
How do you track money that moves across blockchains without banks? The international response relies heavily on blockchain analytics firms like Chainalysis, Elliptic, and TRM Labs. These companies provide the eyes and ears for law enforcement. They trace transactions, identify laundering patterns, and link wallet addresses to specific attacks.
North Korean hackers are remarkably adaptable. In early 2025, Elliptic reported that DPRK actors rotated through 17 different wallet clustering techniques in just six months. They use decentralized exchanges, cross-chain swaps, and privacy coins like Monero to obscure their trail. Recently, they’ve even started using artificial intelligence to enhance social engineering tactics. Imagine receiving an email from a colleague that looks perfectly normal, complete with AI-generated voice notes, asking you to approve a transaction. That’s the new reality.
| Metric | Value/Fact | Source/Context |
|---|---|---|
| Total Stolen (First Half 2025) | $2.17 Billion | Chainalysis Mid-Year Update |
| Largest Single Hack | $1.5 Billion (ByBit) | February 2025 Incident |
| Global Share of State-Sponsored Theft | 38.7% | MSMT October 2025 Report |
| Asset Recovery Rate | ~12.3% | US DOJ Civil Forfeiture Data |
| Trained Analysts (MSMT) | 487 | As of October 2025 |
The IT Worker Frontline
It’s not just about hacking exchanges. A significant portion of North Korea’s revenue comes from IT workers who infiltrate Western tech firms. These individuals use fake identities to secure remote jobs, often at defense contractors or software companies. While they code, they also conduct espionage, stealing proprietary technology and data.
The MSMT has highlighted this vector as a critical vulnerability. Thousands of these workers generate revenue while simultaneously feeding information back to Pyongyang. Because they appear as legitimate employees, traditional financial sanctions don’t catch them. Detecting them requires human intelligence and subtle behavioral analysis, something that automated systems struggle to replicate. Recent cases show these workers contributing to both economic gain and military intelligence gathering.
Challenges in Enforcement and Recovery
Despite the progress, catching the money is harder than catching the thieves. The recovery rate for seized assets remains low, hovering around 12.3%. Why? Because by the time authorities identify the stolen funds, they’ve often been moved through multiple layers of mixing services and converted into hard-to-trace assets. Jurisdictional issues also play a role. If funds land in a country not part of the MSMT, recovery becomes a diplomatic negotiation rather than a legal seizure.
Exchange operators report frustration with the pace of cross-border asset recovery. While threat intelligence sharing has improved, the actual movement of frozen funds can take months or years. Smaller platforms struggle with compliance costs, estimated at $1.2 million annually per platform, creating a disparity in security readiness between giants like Coinbase and smaller startups.
The Future: Fusion Cells and Real-Time Monitoring
The fight is evolving. The MSMT plans to establish a dedicated Cryptocurrency Intelligence Fusion Cell in early 2026, modeled after counterterrorism units. With $85 million in initial funding, this cell aims to streamline data sharing between financial intelligence units across member nations. The goal is real-time monitoring, reducing the lag between a hack and a freeze order.
Regulations are tightening too. The US Executive Order 14155 now requires enhanced due diligence for transactions over $10,000, while the EU’s MiCA II regulations will soon mandate comprehensive cross-border monitoring. These rules aim to close the gaps that North Korean actors have exploited for years. However, the threat persists. As long as there are vulnerabilities in DeFi protocols and NFT marketplaces, the Lazarus Group will find a way to strike.
What is the Multilateral Sanctions Monitoring Team (MSMT)?
The MSMT is a coalition of 11 nations formed in October 2024 to monitor and report on North Korea's sanctions violations, particularly in the cryptocurrency sector. It replaced the functions of the dissolved UN Panel of Experts, focusing on agile, coordinated responses to DPRK cybercrime.
Why did the UN Panel of Experts dissolve?
The UN Panel of Experts dissolved in May 2024 primarily due to a veto by Russia, which complicated the renewal of its mandate. This created an enforcement gap that the MSMT was designed to fill with a more flexible, like-minded coalition approach.
How much cryptocurrency has North Korea stolen?
Cumulative known thefts exceed $6 billion since tracking began. In the first half of 2025 alone, North Korean actors stole over $2.17 billion, including the record-breaking $1.5 billion ByBit hack in February 2025.
What role does the Lazarus Group play?
The Lazarus Group is a state-sponsored cyber-espionage unit under North Korea's Reconnaissance General Bureau. It executes complex cryptocurrency heists and social engineering attacks to generate revenue for the regime's weapons programs and evade sanctions.
How effective is the international response so far?
While intelligence sharing has improved, asset recovery rates remain low at approximately 12.3%. The response is faster than previous UN mechanisms, but jurisdictional hurdles and sophisticated laundering techniques continue to challenge full recovery of stolen funds.