North Korean Hackers Steal Over $1 Billion in Crypto in 2026 as AI-Powered Attacks Expand
.png&w=3840&q=75)
North Korean cybercriminals are facing renewed scrutiny after a series of cryptocurrency thefts pushed suspected state-linked crypto losses past $1 billion this year. The latest developments include a major security breach at cryptocurrency exchange Bitget and a separate campaign involving fake job advertisements, artificial intelligence and malicious software that reportedly stole millions of dollars from thousands of victims.
According to blockchain analytics firm Elliptic, the September 24 attack on Bitget is highly likely to be connected to North Korean hacking groups. The incident, which involved hundreds of millions of dollars in unauthorized transfers, has added to a growing list of cryptocurrency thefts attributed to the country. Meanwhile, a separate operation known as WaterPlum has been targeting software developers and IT professionals through fraudulent recruitment campaigns, highlighting how cybercriminals are expanding beyond traditional exchange exploits.
The incidents demonstrate the increasingly varied methods used to target the cryptocurrency industry, from compromising exchange infrastructure to manipulating individuals through convincing online interactions.
Bitget's September security breach involved unauthorized transfers from several of the exchange's hot wallets. The company initially reported losses of approximately $351.6 million, with subsequent reporting putting the total at around $357 million. Elliptic has identified multiple indicators suggesting the attack was carried out by North Korean-linked actors, including similarities in the movement and laundering of stolen funds to previous incidents.
Bitget detected the unauthorized activity on September 24 and suspended customer withdrawals as a precaution. The exchange reported that its cold-storage wallets were unaffected and that the incident did not involve a compromise of private keys. Instead, CEO Gracy Chen described an attack on a critical backend system within the company's wallet infrastructure, in which transaction data was spoofed to trigger unauthorized transfers.
The exchange has said that the loss is covered by its User Protection Fund, which holds more than $464 million. Bitget is working with cybersecurity firms Mandiant and SlowMist as the investigation continues. The company has also notified law enforcement and initiated efforts to trace and recover the stolen assets.
Elliptic's assessment of the incident points to connections between the stolen funds and cryptocurrency addresses associated with earlier attacks attributed to North Korea, including the massive 2025 Bybit breach. Investigators also observed laundering patterns consistent with previous operations linked to the country. While these findings strongly suggest a North Korean connection, the investigation into the Bitget incident is ongoing.
The attack has helped push Elliptic's tracked total of suspected North Korean cryptocurrency thefts in 2026 beyond $1 billion. The firm has identified more than 50 incidents associated with North Korean actors this year, with its broader estimate of stolen funds reaching approximately $1.2 billion.
The Bitget breach is not the only recent example of North Korean cyber operations targeting digital assets. On September 29, ABC News reported on a separate campaign by a group known as WaterPlum, which authorities say stole approximately $10.71 million in cryptocurrency from around 7,000 accounts after infiltrating at least 30,000 devices.
Between December 2025 and July 2026, WaterPlum allegedly used fraudulent job advertisements to target software developers and IT professionals across more than 100 countries. Applicants were encouraged to download files presented as software alternatives to familiar video-conferencing applications, including Zoom, as part of supposed remote job interviews. These downloads could then expose their devices and sensitive information to malicious activity.
The operation also reportedly involved the use of artificial intelligence to disguise the identities of North Korean operatives during online interviews. Authorities described the use of AI-powered face-swapping technology, with individuals sometimes asking interviewers to turn off their cameras because of supposed network problems.
The campaign illustrates how recruitment processes can become a pathway for cyberattacks. Rather than directly targeting cryptocurrency exchanges, attackers can exploit the trust associated with employment opportunities to gain access to personal devices, credentials and potentially valuable accounts.
Authorities from the United States, Japan, Germany and Australia issued a joint statement warning about the activity. According to the reporting, WaterPlum also obtained identification images, passwords and other sensitive personal information from thousands of people, creating the possibility of further fraud or extortion.
The group has been linked by authorities to North Korea's 313 General Bureau of the Munitions Industry Department, which operates under the country's ruling Workers' Party. Investigators have also identified connections to so-called laptop farms, arrangements that allow remote workers to conceal their actual locations while appearing to work for legitimate companies.
Cybersecurity experts say artificial intelligence is making these operations easier to scale. AI tools can help attackers communicate with more potential victims, produce convincing messages, automate parts of their operations and keep track of interactions more efficiently. The result is a threat landscape where cybercriminals can pursue a much larger number of targets without necessarily requiring a corresponding increase in personnel.
For cryptocurrency users, the WaterPlum campaign is a reminder that security threats do not always begin with a suspicious wallet transaction or an unfamiliar exchange login. They can begin with an ordinary-looking job advertisement, an interview invitation or a software download that appears to be part of a legitimate hiring process.
The consequences of these attacks can extend well beyond the initial cryptocurrency theft. Stolen identification documents, passwords and personal information can be reused in future scams, account takeovers or extortion attempts. Individuals who have interacted with suspicious recruiters may therefore face ongoing risks even after the original malicious software has been removed.
The growing use of AI in cybercrime also presents challenges for companies employing remote workers. Organizations must consider how they verify the identities of applicants and employees, particularly when hiring across international borders. Video interviews alone may no longer provide sufficient assurance that an individual is who they claim to be, especially when attackers have access to convincing face-swapping tools.
For cryptocurrency exchanges and other digital asset businesses, the Bitget incident highlights the importance of securing the systems that authorize transactions, not just the private keys that control wallets. A company can maintain secure cold storage and still face substantial losses if attackers compromise the backend infrastructure used to validate and execute transfers.
The distinction is particularly important as exchanges continue to manage increasingly complex wallet systems and support a wide variety of digital assets and blockchain networks. Security practices need to account for the entire transaction process, including the systems responsible for approving withdrawals, monitoring suspicious activity and protecting administrative access.
Basic cybersecurity precautions remain important for individuals as well. Keeping devices and software updated, using unique passwords, enabling multifactor authentication and avoiding unfamiliar downloads can reduce exposure to common attack methods. Job seekers should independently verify employers and recruitment agencies before installing software or providing sensitive personal information. Businesses can also strengthen their hiring procedures through additional identity checks and secure device-management practices.
The latest incidents also demonstrate why cryptocurrency theft remains a significant international concern. Digital assets can move across borders quickly, and attackers can use exchanges, bridges and decentralized platforms to complicate efforts to trace stolen funds. Blockchain analysis can help investigators identify suspicious transactions and connections between attacks, but tracking funds does not automatically mean they can be recovered.
With more than $1 billion in suspected North Korean-linked cryptocurrency thefts recorded by Elliptic in 2026, the industry is facing continued pressure to improve security across both centralized platforms and individual user devices. The Bitget breach and WaterPlum's recruitment-based attacks show that the threat is not confined to a single vulnerability or type of victim.
As artificial intelligence becomes more accessible, the tools available to cybercriminals are likely to evolve alongside the security measures designed to stop them. For cryptocurrency businesses, developers, miners and everyday users, maintaining strong security practices is increasingly essential in an environment where attacks can target both the infrastructure behind digital assets and the people who use it.