The United States has issued a fresh warning regarding the alleged thefts of hundreds of millions of dollars in cryptocurrency by North Korea.
In a joint statement alongside Japan and the Republic of Korea, the US said that the Democratic People’s Republic of Korea (DPRK) cyber-program threatens the international community, and poses a significant threat to the integrity and stability of global financial systems.
The three governments said that in 2024 alone, they had attributed more than $659 million (£541.4 million) in cryptocurrency thefts to the rouge nation, including $308 million in Bitcoin (£253 million) from the Japan-based cryptocurrency company DMM and $235 million (£192.9 million) from Indian crypto exchange WazirX.
Among the other crypto thefts noted in the statement were $50 million (£41.1 million) taken from Radiant Capital, $50 million from digital asset exchange Upbit, and $16.13 million (£13.2 million) from Rain Management.
The US said it had observed aggressive targeting of the cryptocurrency industry by the DPRK as recently as September, with well-disguised, highly tailored social engineering attacks being used that ultimately deployed malware.
Alongside the higher profile thefts of cryptocurrency, the US and its allies also warned those in the private sector about the continuing insider threat posed by North Korean threat actors posing as legitimate IT workers, with firms working in blockchain and freelance industries apparently being most at risk.
To date, several countries have issued their own warnings over the growing threat of the DPRK’s cyber-activities, with the UK’s National Cyber Security Centre helping to expose a global cyber-espionage campaign carried out by attackers allegedly sponsored by North Korea.
In this latest statement, the US, Japan, and South Korea advise those in the private sector to make themselves more aware of the tactics being used against them and foster security collaboration, which could help mitigate the risks of falling victim to state-sponsored cyber-attackers, or even inadvertently offering them a job.
Recommended reading
- North Korean Threat Actors Have Infiltrated UK Firms
- OpenAI Reveals Scale of Threat Actors Using AI to Influence Elections
- NCSC Uncovers North Korean Cyber Espionage Gang
“The advanced persistent threat groups affiliated with the DPRK… continue to demonstrate a pattern of malicious behaviour in cyber-space by conducting numerous cybercrime campaigns to steal cryptocurrency and targeting exchanges, digital asset custodians, and individual users,” read the joint statement.
“The United States, Japan, and the Republic of Korea will continue to work together to counter the DPRK’s malicious cyber-activities and illicit revenue generation, including by imposing sanctions on DPRK cyber-actors.”





