cleartext

Independent, sourced crypto news. No paid placements.

north korea

CertiK Pins ~$2B of 2025 Crypto Theft on North Korea, or About 60% of All Losses

Blockchain security firm CertiK says North Korea–linked hackers stole about $2.06 billion in crypto in 2025 — roughly 60% of all theft losses — and $6.75 billion across 263 incidents since 2016.

North Korea–linked hackers accounted for the majority of crypto stolen in 2025, according to a new report from blockchain security firm CertiK, which puts DPRK-attributed losses at roughly $2.06 billion — about 60% of all theft losses for the year. The findings, drawn from CertiK's Skynet analysis and reported by Decrypt on September 23, frame state-sponsored theft as the single largest threat to decentralized finance.

Over a longer horizon, CertiK says DPRK-linked groups have stolen $6.75 billion across 263 incidents since 2016. The firm characterizes the shift as a move from opportunistic, one-off hacks toward sustained, state-directed operations — including social-engineering campaigns. Decrypt's headline points to one such tactic, fake job interviews used to compromise victims, which it says drained roughly $11 million from about 7,000 wallets; the specifics of how that campaign was carried out and measured weren't detailed in the account.

One number to watch: CertiK's own figure for 2025 is $2.06 billion, while Decrypt's headline rounds it to $2.1 billion. The gap is rounding, not a genuine discrepancy, but it's worth flagging since the rounded figure is the one likely to circulate.

Key facts

  • ~$2.06 billion in crypto attributed to DPRK-linked hackers in 2025 — about 60% of all theft losses that year (CertiK Skynet, via Decrypt).
  • $6.75 billion stolen across 263 incidents since 2016 (CertiK).
  • A fake-job-interview campaign reportedly drained ~$11 million from ~7,000 wallets (Decrypt headline; mechanics not detailed).
  • Headline figure appears both as $2.06B (CertiK) and rounded to $2.1B (Decrypt).

The real-world read

Attribution here comes from a single blockchain-security vendor, and the report doubles as a showcase for CertiK's own "Skynet" product — so it's threat research and marketing at once. That doesn't make the numbers wrong, but they are one firm's estimates and attributions, not confirmed by any government or by Pyongyang, and North Korea has never acknowledged such operations. Blame-attribution figures across security firms often diverge, so a single headline number should be read as CertiK's tally, not a settled fact.

The $11 million / 7,000-wallets claim is the eye-catching detail, yet the reporting available doesn't spell out the methodology, the timeframe, or how those wallets were counted — so treat it as a headline figure pending fuller disclosure. And "60% of all losses" is only as solid as the denominator: it depends on how CertiK defines and totals "theft losses" for the year, which the summary doesn't lay out.

Opinion, and whose

CertiK's read — that state-sponsored theft is now the dominant threat to DeFi — is the firm's own framing, consistent with a vendor whose business is selling detection and audit services. No competing attribution or independent confirmation is presented alongside it.

Sources

  • Decrypt (Tier 2, secondary), Sept. 23, 2026 — reported CertiK's figures and the fake-interview campaign. Cites CertiK's Skynet analysis as its source.
  • CertiK "Skynet" report (primary, as relayed by Decrypt) — origin of the $2.06B, 60%, $6.75B and 263-incident figures. Note: also serves as promotion for CertiK's own security product; read as interested-party research.

This is news reporting, not financial advice.