The Grey Terminal
WHERE CODE MEETS CAPITAL
Loading prices…
Powered by CoinGecko
Business & Venture

Researcher Spent 22 Months Inside North Korean Hackers’ Network, Finds Crypto Was the Main Target in 1,640 Breaches

Researcher Spent 22 Months Inside North Korean Hackers’ Network, Finds Crypto Was the Main Target in 1,640 Breaches

A cybersecurity researcher spent 22 months monitoring infrastructure linked to North Korean hackers and identified 1,640 breached companies, with cryptocurrency assets emerging as the main target across the attacks he observed.

Key Takeaways
  • Nico Stykas identifies 1,640 breached companies while monitoring North Korean hacker infrastructure over a twenty-two-month intelligence operation.
  • Attackers prioritize cryptocurrency credentials across every intrusion, contributing to the billions in digital asset theft previously documented by the United Nations.
  • Hacking groups like Lazarus Group weaponize stolen private keys to generate state revenue while bypassing traditional international financial sanctions and oversight.
Listen to this article
READY

Nico Stykas, chief technology officer at cybersecurity firm Kumio, said the hackers repeatedly searched for cryptocurrency wallet credentials, blockchain access and digital asset systems after gaining entry into targeted networks.

The findings provide a rare look inside North Korean cyber operations, where attackers often moved beyond traditional espionage targets and focused on access that could lead to cryptocurrency theft.

Researcher Tracked North Korean Hackers for 22 Months

Stykas tracked activity linked to North Korean hacking groups by monitoring their infrastructure and observing how attackers operated after gaining access to compromised systems. The research identified 1,640 affected companies across multiple industries, including organisations outside the cryptocurrency sector.

The attackers did not only target crypto companies. Stykas found that hackers searched for digital asset credentials even after entering networks that contained other valuable information. Their activity showed a repeated focus on cryptocurrency wallets, private keys and blockchain-related access.

Advertisement · Press Release

Have a development worth tracking?

Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.

→ Submit a Press Release

Crypto Credentials Became the Main Prize

The investigation found that North Korean hackers frequently prioritised cryptocurrency access once they were inside a network. Stykas said attackers continued searching for crypto-related information even when they had access to other sensitive systems.

The focus included wallet keys, credentials and access points connected to blockchain platforms. Cryptocurrency has become a major target for North Korean-linked hacking groups because stolen digital assets can be transferred internationally and converted through global networks.

The United Nations and cybersecurity researchers have previously linked North Korean cyber operations to billions of dollars in cryptocurrency theft.

North Korean Hackers Expanded Beyond Crypto Companies

The 1,640 breaches tracked by Stykas were not limited to cryptocurrency businesses. The activity affected organisations across sectors, including healthcare, technology and government-related entities.

Cybersecurity researchers have long attributed major cryptocurrency theft campaigns to North Korean-linked groups such as Lazarus Group, which has been accused of targeting exchanges, blockchain firms and financial organisations. North Korea has denied involvement in cyberattacks and cryptocurrency theft allegations.

The hacking groups have used a combination of malware, social engineering and network exploitation techniques to gain access to victims.

Why Digital Assets Remain a Target

Cryptocurrency theft offers North Korean hackers a way to generate revenue outside traditional financial systems. Unlike conventional bank transfers, digital assets can move quickly across borders through blockchain networks, making recovery more difficult once funds are stolen.

Security firms have documented multiple large-scale cryptocurrency thefts linked to North Korean groups, with attackers targeting exchanges, decentralised finance platforms and companies that hold digital assets. The Kumio research showed that cryptocurrency access remained a recurring objective across a wide range of intrusions.

Cybersecurity Teams Face Growing Challenge

The research highlights how cryptocurrency theft can be hidden inside broader network compromises. A company may initially identify an intrusion as a data breach before discovering attackers were searching for wallet credentials or blockchain access.

For organisations managing digital assets, protecting private keys, wallet systems and access controls remains a central security challenge. Stykas’ 22-month investigation offers a detailed view of how North Korean hackers operate after gaining entry into corporate networks and shows that cryptocurrency remains a consistent target across their campaigns.

TERMINAL LAYER

Activate Terminal Layer

Structural analysis of the systems, pressures, and stakeholders behind this story.

FAQ

Frequently Asked Questions

01

What is the North Korean crypto-theft operation?

North Korean crypto-theft is a state-sponsored campaign to exfiltrate digital assets through systematic network intrusions. Nico Stykas of Kumio tracked 1,640 breaches where hackers specifically targeted private keys and blockchain credentials. These operations provide the Democratic People's Republic of Korea with liquid capital to fund state objectives outside the global banking system.
02

Why does this matter for the cybersecurity industry?

This investigation proves that cryptocurrency is now the primary objective for diversified cyberattacks across healthcare, technology, and government sectors. Stykas found that hackers prioritized wallet access even when traditional espionage targets were available within the compromised network. Cybersecurity teams must now assume that any data breach is a precursor to an attempt at institutional asset drainage.
03

How did Nico Stykas execute this investigation?

Nico Stykas monitored the internal infrastructure of North Korean hacking groups for twenty-two months starting in 2024. The Kumio CTO observed real-time data flows and documented the specific search patterns attackers used to locate digital asset systems. This longitudinal study allowed researchers to map the lateral movement of threat actors from initial entry to final credential harvesting.
04

What are the risks of these digital intrusions?

The primary risk involves the irreversible movement of stolen capital through decentralized blockchain networks that lack traditional recovery mechanisms. Hacking groups like Lazarus Group utilize sophisticated social engineering to gain entry before consolidating assets in unmonitored wallets. While North Korea denies these allegations, the cumulative financial damage to the digital economy is estimated in the billions.
05

How should companies secure digital assets against these hackers?

Organizations must implement air-gapped cold storage and multi-signature authorization to protect private keys from unauthorized network access. Forensic research from Kumio suggests that protecting administrative credentials is the most critical step in preventing lateral movement by attackers. Establishing a zero-trust architecture reduces the probability that a single compromised device leads to a total treasury loss.

You Might Also Like

THE GREY TERMINAL
🛡
Alex Reeve

Alex Reeve is a contributing writer for The Grey Terminal Her articles provide timely insights and analysis across these interconnected industries, including regulatory updates, market trends, token economics, institutional developments, platform innovations, stablecoins, meme coins, policy shifts, and the latest advancements in AI, applications, tools, models, and their broader implications for technology and markets.

The views and opinions expressed by the author in this article are her own and do not necessarily reflect the official position of The Grey Terminal, its management, editors, or affiliates. This content is provided for informational and educational purposes only and does not constitute financial, investment, legal, or tax advice. Readers should conduct their own research and consult qualified professionals before making any decisions related to digital assets, cryptocurrencies, or financial matters. The Grey Terminal and its contributors are not responsible for any losses incurred from reliance on this information.