A cybersecurity researcher spent 22 months monitoring infrastructure linked to North Korean hackers and identified 1,640 breached companies, with cryptocurrency assets emerging as the main target across the attacks he observed.
- Nico Stykas identifies 1,640 breached companies while monitoring North Korean hacker infrastructure over a twenty-two-month intelligence operation.
- Attackers prioritize cryptocurrency credentials across every intrusion, contributing to the billions in digital asset theft previously documented by the United Nations.
- Hacking groups like Lazarus Group weaponize stolen private keys to generate state revenue while bypassing traditional international financial sanctions and oversight.
Nico Stykas, chief technology officer at cybersecurity firm Kumio, said the hackers repeatedly searched for cryptocurrency wallet credentials, blockchain access and digital asset systems after gaining entry into targeted networks.
The findings provide a rare look inside North Korean cyber operations, where attackers often moved beyond traditional espionage targets and focused on access that could lead to cryptocurrency theft.
Researcher Tracked North Korean Hackers for 22 Months
Stykas tracked activity linked to North Korean hacking groups by monitoring their infrastructure and observing how attackers operated after gaining access to compromised systems. The research identified 1,640 affected companies across multiple industries, including organisations outside the cryptocurrency sector.
The attackers did not only target crypto companies. Stykas found that hackers searched for digital asset credentials even after entering networks that contained other valuable information. Their activity showed a repeated focus on cryptocurrency wallets, private keys and blockchain-related access.
Have a development worth tracking?
Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.
→ Submit a Press ReleaseCrypto Credentials Became the Main Prize
The investigation found that North Korean hackers frequently prioritised cryptocurrency access once they were inside a network. Stykas said attackers continued searching for crypto-related information even when they had access to other sensitive systems.
The focus included wallet keys, credentials and access points connected to blockchain platforms. Cryptocurrency has become a major target for North Korean-linked hacking groups because stolen digital assets can be transferred internationally and converted through global networks.
The United Nations and cybersecurity researchers have previously linked North Korean cyber operations to billions of dollars in cryptocurrency theft.
North Korean Hackers Expanded Beyond Crypto Companies
The 1,640 breaches tracked by Stykas were not limited to cryptocurrency businesses. The activity affected organisations across sectors, including healthcare, technology and government-related entities.
Cybersecurity researchers have long attributed major cryptocurrency theft campaigns to North Korean-linked groups such as Lazarus Group, which has been accused of targeting exchanges, blockchain firms and financial organisations. North Korea has denied involvement in cyberattacks and cryptocurrency theft allegations.
The hacking groups have used a combination of malware, social engineering and network exploitation techniques to gain access to victims.
Why Digital Assets Remain a Target
Cryptocurrency theft offers North Korean hackers a way to generate revenue outside traditional financial systems. Unlike conventional bank transfers, digital assets can move quickly across borders through blockchain networks, making recovery more difficult once funds are stolen.
Security firms have documented multiple large-scale cryptocurrency thefts linked to North Korean groups, with attackers targeting exchanges, decentralised finance platforms and companies that hold digital assets. The Kumio research showed that cryptocurrency access remained a recurring objective across a wide range of intrusions.
Cybersecurity Teams Face Growing Challenge
The research highlights how cryptocurrency theft can be hidden inside broader network compromises. A company may initially identify an intrusion as a data breach before discovering attackers were searching for wallet credentials or blockchain access.
For organisations managing digital assets, protecting private keys, wallet systems and access controls remains a central security challenge. Stykas’ 22-month investigation offers a detailed view of how North Korean hackers operate after gaining entry into corporate networks and shows that cryptocurrency remains a consistent target across their campaigns.
Activate Terminal Layer
Structural analysis of the systems, pressures, and stakeholders behind this story.





