North Korea Linked To 2019 Ethereum Theft Worth $55.7M, Say South Korean Authorities

As a seasoned analyst with a decade of experience in cybersecurity and cryptocurrency markets, this revelation about North Korean hackers behind the 2019 Ethereum heist is both intriguing and alarming. The sheer audacity of these cybercriminals, who have managed to elude authorities for years, is a testament to their sophistication and relentless determination.


2019’s significant Ethereum theft has been traced back to North Korean hackers by South Korean officials, marking a significant advancement in the ongoing investigation.

58 billion won worth of cryptocurrency (equivalent to approximately $55.7 million) that was stolen, has been linked back to North Korea’s Reconnaissance General Bureau, a military intelligence agency. It is said that hackers breached a South Korean cryptocurrency exchange in order to carry out the theft.

Detailing the Hack and the Coordinated Efforts Behind Uncovering the Perpetrators

According to the National Police Agency’s report, these criminals managed to swipe a substantial amount of Ethereum tokens worth more than 1.4 trillion won, which is roughly equivalent to $1.05 billion, placing this incident among the largest known cryptocurrency heists in history.

Although the particular transaction involved wasn’t mentioned, it’s been reported that a significant amount of Ethereum was stolen from Upbit, a prominent South Korean cryptocurrency exchange, by an unknown wallet back in 2019.

The hackers laundered over half of the stolen funds through three self-operated crypto exchanges, offering discounts to convert the assets into Bitcoin. The remaining Ethereum was dispersed across 51 other exchanges globally.

The study mentions that the probe was a joint effort between South Korean officials and the FBI, where they employed sophisticated methods such as tracing IP addresses and monitoring the transfer of ill-gotten funds.

As a cryptocurrency investor, I’ve just learned that for the first time, South Korea has officially linked a cyberattack on a local crypto exchange to hacker groups believed to be operating from North Korea – specifically, Lazarus and Andariel. These notorious groups are associated with the Reconnaissance General Bureau of North Korea.

Hackers Persistent Threat To The Crypto Industry

It’s worth mentioning that North Korean hackers have previously been implicated in major hacking cases. In fact, they have built a reputation over the years by focusing on attacks against cryptocurrency exchanges and financial systems to finance their nation’s activities.

Although authorities strive to retrieve stolen assets from these infamous hackers, they continue to pose a relentless danger to the crypto sector. Lately, the United Nations has highlighted North Korea’s role in multiple cyber assaults on cryptocurrency exchanges.

A United Nations report from May suggests that the government may have been responsible for around 97 cryptocurrency thefts, occurring between 2017 and 2024, which are estimated to be worth approximately $3.6 billion in total.

It’s widely thought that these activities significantly contribute to financing North Korea’s missile and nuclear projects, underscoring the far-reaching geopolitical consequences of such criminal acts.

Regardless of the joint actions taken by authorities and online services to thwart these cyber-attacks, these hackers have proven to be adaptable. In fact, only last month, this same group managed to pilfer approximately $3 billion in cryptocurrency from users through the creation of a deceptive blockchain game.

Based on available information, it appears that a significant amount of money was stolen through an operation that lasted approximately six years. This operation was allegedly carried out by North Korean cybercriminals between 2016 and 2022.

Featured image created with DALL-E, Chart from TradingView

Read More

2024-11-22 07:13