North Korean Hackers Stole $400M in 2021, Mostly in Ether

For the first time, DeFi mixers were the biggest money-laundering tool for North Korean hackers.

AccessTimeIconJan 14, 2022 at 11:59 a.m. UTC
Updated May 11, 2023 at 3:41 p.m. UTC
10 Years of Decentralizing the Future
May 29-31, 2024 - Austin, TexasThe biggest and most established global hub for everything crypto, blockchain and Web3.Register Now

North Korean hackers stole almost $400 million worth of digital assets from crypto platforms last year, mostly in the form of ether, according to a Chainalysis report published on Thursday.

  • For the first time, ether accounted for most – 58% – of the stolen funds, according to the report. It was followed by altcoins and ERC-20 tokens, with bitcoin at just 20% of the total, Chainalysis said.
  • The increased variety of tokens has led the hackers to step up their efforts to launder their spoils, the report said. The typical process now involves several steps of swapping one cryptocurrency for another on decentralized exchanges and using decentralized finance (DeFi) mixers, which are privacy tools for obscuring the history of the transactions, to conceal their tracks, according to Chainalysis.
  • Mixers were the most used tool among North Korean hackers for the first time, accounting for over 65% of stolen funds, up from 42% in 2020 and 21% the year before, Chainalysis said. In 2017 and 2019, crypto exchanges were the most popular way of laundering money.
  • About $170 million of stolen funds from 49 exploits dating back to 2017 have yet to be laundered, the report said.
  • The number of North Korea-attributed attacks grew from four to seven, and the funds stolen grew by 40%, the highest since 2018, according to the report. The victims were mostly investment firms and centralized exchanges.
  • Chainalysis said that many of last year's attacks were likely carried out by a group labeled as advanced persistent threat 38 (APT38), also known as Lazarus Group. The group is believed to be led by Pyongyang’s primary intelligence agency, the Reconnaissance General Bureau.


Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. In November 2023, CoinDesk was acquired by the Bullish group, owner of Bullish, a regulated, digital assets exchange. The Bullish group is majority-owned by; both companies have interests in a variety of blockchain and digital asset businesses and significant holdings of digital assets, including bitcoin. CoinDesk operates as an independent subsidiary with an editorial committee to protect journalistic independence. CoinDesk employees, including journalists, may receive options in the Bullish group as part of their compensation.

Eliza Gkritsi

Eliza Gkritsi is a CoinDesk contributor focused on the intersection of crypto and AI.

Learn more about Consensus 2024, CoinDesk's longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to to register and buy your pass now.