One year after the $1.46 billion Bybit breach — the largest cryptocurrency theft in history — North Korea's crypto operation has not retreated. It has evolved. New intelligence from Elliptic, Chainalysis, and TRM Labs paints a picture of a state-sponsored apparatus that stole over $2 billion in c...
"The Bybit hack was an inflection point, not a culmination. DPRK operatives may now be creating cryptoasset projects, not just infiltrating them." — Elliptic Research, Bybit Exploit 12 Months On (February 2026)
One year after the $1.46 billion Bybit breach — the largest cryptocurrency theft in history — North Korea's crypto operation has not retreated. It has evolved. New intelligence from Elliptic, Chainalysis, and TRM Labs paints a picture of a state-sponsored apparatus that stole over $2 billion in crypto during 2025, pushed cumulative known theft past $6 billion, and is now building its own decentralized projects as honeypots. January 2026 alone saw twice as many DPRK-linked exploits as the same month a year prior.
The implications extend far beyond cybersecurity. North Korea has become a systemic risk to the economic value layer of Web3. It is not targeting protocols at the margins — it is attacking the custody infrastructure, the human trust layer, and now the project creation pipeline itself. For institutional allocators, protocol teams, and policymakers, ignoring this threat is no longer a strategic option. It is a fiduciary failure.
This report examines the scale of the threat, the tactical evolution from theft to creation, the industry's response, and what it means for the future of crypto custody, compliance, and economic value preservation.
February 21, 2026, marked twelve months since North Korea's Lazarus Group — specifically its TraderTraitor subunit, as designated by the FBI — executed the single largest cryptocurrency theft in history. The attackers compromised Safe{Wallet}, a widely-used multi-signature wallet provider, by replacing a benign JavaScript file with malicious code on February 19, 2025. When Bybit initiated a routine Ethereum cold wallet transaction two days later, the malicious code activated, redirecting approximately $1.46 billion in ETH to attacker-controlled addresses.
The technical sophistication was striking. The exploit leveraged Ethereum's delegatecall function to replace the wallet's contract logic entirely, tricking Bybit's multi-signature signers into approving what appeared to be a legitimate transaction. It was not a brute-force attack on cryptography. It was a supply chain attack on human trust.
Recovery has been minimal. Despite Bybit successfully replenishing its reserves through emergency funding from Galaxy Digital, FalconX, and Wintermute — and a Hacken audit confirming 100% collateralization — only approximately $42 million (roughly 3%) of the stolen funds has been frozen. No additional meaningful recovery has occurred in the twelve months since.
The Lazarus Group's laundering infrastructure proved formidable. Elliptic documented a consistent 45-day laundering cycle following major thefts, with a clear preference for Chinese-language money laundering services, cross-chain bridge services, and mixing protocols. The shuttered exchange eXch was identified as a conduit through which approximately $200 million of stolen Bybit funds were processed before law enforcement intervention.
The Bybit hack was the centerpiece of a record year for crypto theft. According to Chainalysis, total crypto theft in 2025 reached $3.4 billion, with North Korea-linked actors responsible for $2.02 billion — representing 59% of all stolen crypto assets globally. TRM Labs' independent estimate places the DPRK figure at $1.92 billion, broadly corroborating the scale.
Key 2025 metrics:
The pattern is unmistakable: North Korea is achieving larger thefts with fewer incidents. This is not opportunistic crime. It is an industrialized state operation with increasing precision and decreasing noise.
More broadly, TRM Labs' 2026 Crypto Crime Report found that criminal actors handled $158 billion in digital assets in 2025 — a sudden increase after years of decline. The intersection of state-sponsored theft, sanctions evasion, and increasingly sophisticated laundering networks represents a structural challenge for the industry's economic integrity.
The most alarming development in the past year is not the scale of theft — it is the evolution of tactics. Elliptic's February 2026 analysis revealed that DPRK operatives appear to be shifting from infiltrating existing crypto projects to building their own from the ground up.
The Tenexium incident, which occurred on January 1, 2026, serves as the template. Tenexium launched as a "decentralized long-only spot margin trading protocol" within the Bittensor (TAO) network. It attracted liquidity. It looked legitimate. Then, on the same day, the website went offline and approximately $2.5 million in liquidity was drained from the project's treasury wallet.
Investigation revealed that some of Tenexium's contributors were suspected DPRK IT workers. Crucially, the DPRK persona may have been the actual founder — not merely an infiltrated team member. If confirmed, this represents a paradigm shift: North Korea is no longer just a parasite on the crypto ecosystem. It is becoming a predatory builder within it.
The implications for due diligence are severe. If a nation-state can launch seemingly legitimate DeFi protocols to attract and extract liquidity, the standard investor framework for evaluating project risk — team credentials, code audits, TVL growth — becomes insufficient. The threat model must now include the possibility that the project itself is the attack vector.
At Devconnect in Buenos Aires (November 2025), Pablo Sabbatella — founder of web3 audit firm Opsek and a Security Alliance (SEAL) member — estimated that up to 20% of crypto companies may have North Korean workers embedded in their operations. More strikingly, he estimated that 30-40% of applicants to crypto positions are North Korean infiltration attempts.
The pipeline works through identity arbitrage. International sanctions prevent North Koreans from applying directly. Instead, operatives recruit front-people in countries like Ukraine, the Philippines, and others — using freelance platforms like Upwork and Freelancer as hunting grounds. These proxies apply for jobs, pass interviews, and then hand over access to DPRK handlers.
US Treasury, FBI, and Department of Justice have documented these schemes in which DPRK nationals, using stolen or fabricated identities, have infiltrated not only crypto firms but also defense-related entities. The motivation is dual-purpose: intelligence gathering and direct financial extraction.
The crypto industry's vulnerability is structural. As Sabbatella noted, crypto companies exhibit weaker operational security than almost any other computing sector. Founders publicly reveal identities, mishandle private keys, and succumb to social engineering at rates that would be unacceptable in traditional financial services. The decentralized ethos that prizes pseudonymity and open access creates the exact conditions that state-sponsored infiltrators exploit.
The Bybit hack catalyzed a genuine — if incomplete — transformation in custody security practices.
Insurance demand surged. Post-Bybit, demand for crypto custody insurance increased by an estimated 300%, with custodians now prioritizing coverage for both hot and cold storage theft, cyber incidents, and director liability.
Architecture is evolving. The shift toward infrastructure compromise has emphasized the criticality of hardware-backed key custody, strict signer isolation, withdrawal velocity controls, and tiered approval systems designed to limit the blast radius of any single compromised access point.
Multisig is under scrutiny. The Bybit hack exposed a fundamental vulnerability in Ethereum's smart-contract-based multisig systems (like Safe{Wallet}) compared to Bitcoin's simpler, script-based native multisig. Ethereum multisig wallets can be upgraded, modified, and interact with other contracts — introducing attack surfaces like contract upgrades, UI-based transaction manipulation, and permission delegation that do not exist in Bitcoin's model. Research indicates that wallets with multi-signature support reduce key-compromise risk by over 40%, but the implementation details matter enormously.
Layered custody is becoming standard. Institutional participants are increasingly adopting multi-layer strategies: hardware wallets for cold storage, MPC (Multi-Party Computation) platforms for active funds, and operational segregation between signing environments and internet-connected systems.
Yet the fundamental problem remains unsolved. The Bybit hack was not a failure of cryptography. It was a failure of the human-software interface — a supply chain attack that exploited the gap between what signers saw and what they signed. Until the industry develops signing processes that are verifiable end-to-end without relying on potentially compromised intermediary software, the attack surface remains open.
38 North — the respected North Korea analysis program at the Stimson Center — published a landmark assessment in January 2026 titled "From Digital Kleptocracy to Rogue Crypto-Superpower." The thesis is straightforward and deeply uncomfortable for the crypto industry.
North Korea has evolved from a noisy digital vandal into one of the most capable state cyber actors in the world. Its cumulative crypto holdings, built through systematic theft, now constitute a meaningful strategic reserve. The regime uses AI to facilitate laundering operations with increasing fluidity. Proceeds directly support nuclear and ballistic missile programs, per assessments from Chainalysis, TRM Labs, and US intelligence agencies.
The critical insight from 38 North: as cryptocurrencies gain wider reserve-asset legitimacy — through ETFs, sovereign adoption, and institutional allocation — DPRK will not merely be a crypto-enabled rogue state. It will be a rogue crypto-superpower, capable of tapping large digital reserves within an increasingly mainstream financial ecosystem.
This creates a paradox for the industry. The very institutional adoption that crypto advocates celebrate also legitimizes the reserves that North Korea has accumulated through theft. Every step toward crypto mainstreaming marginally increases the utility and convertibility of DPRK's stolen billions.
The threat is accelerating. January 2026 saw twice the DPRK-linked exploits of January 2025. The pace of attacks is increasing, not decreasing, one year after the Bybit breach.
Tactics have evolved beyond theft. The Tenexium incident suggests DPRK operatives are now building crypto projects as traps — a fundamental escalation from infiltration to creation.
The infiltration problem is structural. With an estimated 20% of crypto firms potentially harboring DPRK workers, the industry faces an insider threat that traditional cybersecurity frameworks are not designed to address.
Custody security has improved but remains fundamentally vulnerable. The Bybit attack exploited the human-software interface, not cryptography. This attack surface is still open.
Recovery rates are negligible. Only 3% of Bybit's stolen funds were frozen. The laundering infrastructure — 45-day cycles, Chinese-language services, cross-chain bridges — outpaces enforcement.
Institutional legitimization creates a paradox. Mainstream crypto adoption increases the convertibility and strategic value of DPRK's stolen reserves, complicating the geopolitical calculus.
One year after the largest crypto theft in history, the uncomfortable truth is that the attacker has become stronger, not weaker. North Korea's crypto operation has industrialized. It steals more with fewer attacks. It launders faster with AI assistance. It has moved from parasitizing the ecosystem to building predatory infrastructure within it. And it has embedded operatives inside the companies that are supposed to be building the future of finance.
For the Web3 ecosystem, this is not merely a security problem — it is an economic value problem. Every dollar stolen by the DPRK represents value extracted from token holders, liquidity providers, and protocol treasuries. Every compromised custody solution undermines the trust infrastructure that institutional capital requires. Every fake project erodes the credibility of the permissionless innovation that makes crypto valuable in the first place.
The industry's response has been real but insufficient. Better custody architecture, more insurance, improved screening — these are necessary but not transformative. What is needed is a recognition that crypto is operating in a threat environment that includes nation-state adversaries with nuclear ambitions, and that the security, compliance, and due diligence standards must reflect that reality.
The Bybit hack was not the end of an era. It was the beginning of one.