mt logoMyToken
ETH Gas
EN

North Korean Hackers Compromised 1640 Companies Across 57 Countries, Crypto Theft Primary Target

north-korea-cyber-attack

For nearly two years, a cybersecurity researcher maintained a hidden vantage point inside the command-and-control infrastructure of North Korean state-backed hackers. The operation, conducted by Kumio CTO Vangelis Stykas, uncovered a breach footprint that dwarfs many previous estimates: 1,640 companies across 57 countries had been compromised, with crypto theft sitting at the center of the campaign. The scale and tactical focus revealed in the original report force a fresh reckoning with the structural weaknesses that allow such intrusions to spread.

The attackers relied on fake job interview lures, a social-engineering vector that has become a signature of North Korean cyber operations. But the damage went far deeper than phishing. Between 700 and 800 organizations suffered highly damaging breaches that included root access to servers, control over AWS environments, and exposure of cryptocurrency wallet keys. Stykas noted that the blast radius was heavily amplified by lax access controls among external contractors, turning routine third-party relationships into nation-state entry points.

Why Contractor Access Multiplies the Risk

Many crypto firms, trading desks, and DeFi platforms operate with a sprawling web of external developers, marketing agencies, and infrastructure providers. When one contractor gets compromised, the attacker often inherits broad permissions that cross internal network boundaries. In this campaign, Kumio observed hackers pivoting from a single breached contractor into multiple downstream organizations. Root access obtained on one node became a stepping stone to cloud consoles and ultimately to wallet infrastructure.

The implications for custody models and multisig setups are direct. Even well-designed on-chain key management can be undone if an attacker sits on the server that generates the transactions. Security teams have long warned that operational hygiene around contractors is the weak link, but the Kumio data quantifies just how wide the gap remains. With 57 countries affected, no jurisdiction appears immune.

The Crypto-Specific Motive and Laundering Challenge

Unlike broad espionage efforts, this cluster of intrusions maintained what Stykas called a laser focus on cryptocurrency theft. That narrow objective matches the economic pressures faced by North Korea, where the regime has turned digital heists into a state revenue stream. Blockchain analytics firms have traced billions of dollars in stolen crypto to Pyongyang-linked addresses, often funneled through mixers, cross-chain bridges, and nested exchange accounts. The Kumio findings suggest that the pipeline feeding those laundering operations is wider than many compliance teams assumed.

Exact loss figures are not yet public, and the researcher did not disclose the names of the affected organizations. That uncertainty leaves the industry in a familiar bind: the attack surface is visibly enormous, but the specific case studies that drive executive attention are often sealed behind non-disclosure agreements. Until more victims speak openly, security benchmarks will remain uneven.

Regulatory Spotlight and Industry Response

The breach data arrives as lawmakers debate comprehensive crypto oversight. In the United States, legislation that could reshape how digital asset firms manage operational risk is grinding through the Senate, and the banking lobby’s eleventh-hour push to modify the bill underscores how much is at stake. If a single compromised contractor can expose dozens of firms to root-level takeover, regulators will face pressure to mandate minimum access controls, genuine multi-factor verification, and routine audits of third-party integrations.

At the same time, the industry continues to expand the value sitting on-chain. Tokenized real-world assets recently crossed the $20 billion mark, and institutional tokenization is accelerating . Each new custody arrangement and smart contract deployment creates a richer target environment for the kind of operations Kumio observed. The motivation for Pyongyang will only intensify as the pool of available crypto assets grows.

The community’s technical defenses are also evolving. The chains with the most active developer communities tend to push rapid patches and security upgrades, but the lesson here is that human vectors still trump protocol-level resilience. No amount of smart contract auditing can stop a root-level server compromise that intercepts a signing operation before it hits the chain. The Kumio research makes clear that the weakest link sits between the chair and the keyboard, often wearing a contractor badge.

For crypto exchanges, wallet providers, and institutional desks, the immediate takeaway is that vetting third-party access must move from a compliance checkbox to a lived security discipline. The 22-month window during which Stykas silently observed the attackers also raises uncomfortable questions about visibility: if a single researcher could monitor the command-and-control server, why were the victims blind? Building better threat-intelligence sharing across the industry and with government agencies will be essential as the same groups refine their techniques. The numbers from Kumio are a reminder that the next breach is not a matter of if, but through which contractor it will arrive.

Disclaimer: This article is copyrighted by the original author and does not represent MyToken’s views and positions. If you have any questions regarding content or copyright, please contact us.(www.mytokencap.com)contact
More exciting content is available on
X(https://x.com/MyTokencap)
or join the community to learn more:MyToken-English Telegram Group
https://t.me/mytokenGroup