North Korean cybercriminals are increasingly harnessing advanced artificial intelligence tools to escalate their cryptocurrency hacking operations, driving a significant portion of global digital asset losses in 2026.
AI boosts North Korean cyber attacks
Blockchain intelligence firm TRM Labs reported that hackers linked to North Korea stole $643 million in cryptocurrency during the first half of 2026, accounting for 66% of all digital asset losses from hacking worldwide. This period saw a total of $972 million lost in 207 separate hacking incidents, highlighting the growing impact of state-backed actors in the space.
Research by South Korean cybersecurity firm Genians indicated that Kimsuky, a group under North Korea’s Reconnaissance General Bureau, has been integrating generative AI into its hacking strategies. The investigation revealed deployment of large language model platforms such as Ollama, GPT4All, and Msty, along with retrieval-augmented generation technology to support sophisticated cyberattacks.
Traditionally, North Korean groups have targeted individuals in diplomacy, academia, and security by sending deceptive emails from seemingly legitimate contacts. Attackers frequently disguised malicious documents as research reports, event invitations, or financial communications to dupe victims.
Genians observed that Kimsuky is now testing generative AI tools for new campaigns, establishing local large language models and AI-based development environments to craft more convincing phishing materials and automate parts of their workflow.
This analysis shows that a nation-backed hacking group is advancing its attack capabilities by building local LLMs and AI development environments to integrate AI into actual attack frameworks.
Evidence suggests that North Korean hackers are moving beyond simple phishing and are adopting broader automation through AI. Researchers found AI-assisted coding tools, speech-to-text systems, and AI-generated documents tailored to look like legitimate financial or cryptocurrency paperwork.
Kimsuky’s technical arsenal and methods
Genians found that Kimsuky weaponized AI-generated documents related to virtual assets and financial affairs, closely replicating genuine corporate documents in both style and appearance to lure targets. Utilization of local models such as Ollama, GPT4All, and Msty has enabled the group to build advanced RAG systems, AI agents, and speech-to-text tools. They also relied heavily on Cursor AI forening code development, concealing their code with Base64 encoding and custom obfuscation methods.
Typically, Kimsuky initiates attacks through malicious ZIP files delivered via email, containing LNK shortcuts camouflaged as official documents or research requests. These decoys feature professional filenames and seemingly trustworthy icons to increase the likelihood of being opened.
Crypto theft as a state revenue engine
Blockchain security company CertiK estimated that North Korean actors stole $2.06 billion in digital assets in 2025, amounting to 60% of all known crypto thefts that year. The most significant single incident was a $1.5 billion attack on Bybit in 2025, marking the largest cryptocurrency heist on record.
CertiK’s analysis revealed that crypto thefts have become a primary source of funding for the state. North Korea reportedly looted about $6.75 billion through 263 separate hacks between 2016 and 2026. Social engineering remains central to the majority of these operations, often involving some form of human deception at the onset of attacks.
The firm warned of the expanding use of AI for social engineering, increased targeting of IT professionals, and evolving money laundering tactics in 2026. To counter these threats, CertiK recommended that potential targets conduct video interviews with identity liveness checks, enforce zero-trust policies for remote workers, mandate withdrawal cooling-off periods, and secure critical infrastructure.
Since January 2026, hackers have stolen more than $900 million globally. However, TRM Labs noted a widening gap between the frequency of attacks and the total amount stolen. Hackers orchestrated 207 incidents but netted only $972 million in early 2026, compared to $2.3 billion taken during the first half of 2025.
Of these 207 reported hacks, 125 involved smart contract exploits, often exploiting multiple vulnerabilities in the underlying code. Crypto companies remain prime targets, with substantial funds continuing to be siphoned from digital asset firms and decentralized finance projects.
Recent developments have underscored the complex and rapidly evolving nature of the cryptocurrency market, with monitoring and technical analysis now more important than ever. As projects seek to enhance investor access and security, platforms such as 1stepSwap stand out by bringing real-world assets like US equities and commodities to blockchain networks. Without needing complex procedures or intermediaries, users can diversify their portfolios and instantly trade the largest stocks and resources at optimal prices directly from their wallets.





USDT
AAPL
