# North Korea-Linked Theft Figures Fall Short of $7.8 Billion Claim

By Simon Yoon

Canonical URL: https://www.tokenpost.com/news/technology/26084
Published: 2026-10-01T06:37:21.000Z
Updated: 2026-10-01T06:37:21.000Z
Section: Technology

> Publicly confirmed U.S. attributions exceed $3.1 billion, while a broader estimate reaches $6.75 billion through 2025. Adding the estimated Bitget loss produces about $7.10 billion.

North Korea-linked cyber operations have produced billions of dollars in cryptocurrency losses, but the available figures do not support a unified total of nearly $7.8 billion.

Publicly confirmed U.S. government attributions cover more than $3.1 billion in losses. A broader estimate puts North Korean hackers’ cumulative thefts at $6.75 billion through the end of 2025.

The higher figure depends on adding an estimated $351.6 million moved from Bitget hot and warm wallets on Sept. 24. That amount is based on Bitget’s reported loss and on-chain analysis, not a completed government finding, and North Korea’s involvement has not been confirmed. Adding it to the broader estimate produces approximately $7.10 billion, not $7.8 billion.

The Bitget incident occurred at 2:31 p.m. ET (18:31 UTC). Initial estimates for losses on EVM chains were $170 million to $190 million. Later outflows on the XRP Ledger and TRON brought the observed amount close to the reported total. Overlaps with laundering wallets connected to earlier North Korean thefts were identified, but another actor remained technically possible.

[On-chain activity linked stolen Bitget funds to the July AFX hack, but the connection to Lazarus remains unconfirmed.](<https://www.tokenpost.com/news/technology/23952>)

The FBI attributed approximately $1.5 billion in virtual assets stolen from Bybit on Feb. 21, 2025, to North Korea and called the activity “TraderTraitor.” Earlier cases included approximately $620 million taken from Sky Mavis’ Ronin Bridge on March 23, 2022, $100 million from Harmony’s Horizon bridge and $100 million from Atomic Wallet. North Korean cyber actors were also attributed responsibility for approximately $60 million from Alphapo and CoinsPaid combined and $41 million from Stake.com in 2023.

The Ronin Bridge theft was attributed to Lazarus Group and APT38. For the Harmony theft, Lazarus was identified as APT38. Lazarus Group is an umbrella label for overlapping North Korean state-linked cyber units rather than one clearly bounded organization. Lazarus, Bluenoroff and Andariel have been identified as state-sponsored groups subordinate to North Korea’s Reconnaissance General Bureau.

The groups have used spear-phishing, malicious cryptocurrency applications, social engineering and compromised software, as well as exchanges, mixers, bridges and other crypto services to move and launder funds. A 2021 U.S. Justice Department case alleged thefts of approximately $75 million from a Slovenian cryptocurrency company, $24.9 million from an Indonesian cryptocurrency company and $11.8 million from a New York financial-services company. The case also alleged that North Korean actors stole nearly $250 million from a cryptocurrency exchange in 2018 and laundered the proceeds through hundreds of transactions.

Through Sept. 16, approximately $690 million in 2026 crypto thefts had been attributed to North Korean hackers with medium or high confidence, excluding Bitget. North Korea’s responsibility for the Bitget incident remains unconfirmed.

## Links in this article

- [On-chain activity linked stolen Bitget funds to the July AFX hack, but the connection to Lazarus remains unconfirmed.](https://www.tokenpost.com/news/technology/23952)
