Bitcoin Targeted in North Korean Hack Campaign Across 1,640 Firms
BTC/USDT
$10,455,761,355.93
$64,999.00 / $64,172.00
Change: $827.00 (1.29%)
-0.0011%
Shorts pay
AI SummaryAI
- A North Korean hacking campaign reached 1,640 companies across 57 countries and targeted Bitcoin wallet private keys.
- Researcher Vangelis Stikas spent about 22 months inside hacker servers and identified 700 to 800 severe compromises.
- Coinbase said the affected contractor was U.S.-based and the contract ended within 30 days of onboarding.
- A December 2025 blockchain report estimated North Korean-linked actors stole $2.02 billion in 2025, up 51%.
Crypto News
Bitcoin (BTC) wallets and private keys were the central objective in a North Korean hacking campaign that reached 1,640 companies across 57 countries, according to internal evidence presented by security researcher Vangelis Stikas at the Black Hat conference. The keys targeted in such intrusions are the controlling layer for self-custody tools, including an AI crypto wallet, and they remain the most valuable prize for state-linked theft teams. Stikas, chief technology officer of cybersecurity firm Kumio, said he spent about 22 months inside servers operated by the group and identified 700 to 800 organizations that suffered severe compromises. The affected list included Coinbase and Uniswap Labs, two major infrastructure names in Bitcoin and broader altcoin markets. The operation did not focus on a single protocol exploit. Instead, attackers pursued people: software developers and contractors were approached with high-paying fake jobs and asked to download malicious programs disguised as hiring tests. This method, tracked by Microsoft since 2022 as “Contagious Interview,” gave intruders access to internal systems and, in some cases, allowed one compromised contractor to hold access rights to as many as 30 companies at once. Stikas said he could view the hackers' own workstations and internal communication channels, including Slack and Discord accounts, and described the level of access to crypto assets as “ridiculous.” The campaign's financial backdrop is significant. A December 2025 blockchain analysis report estimated North Korean-linked actors stole at least $2.02 billion in crypto assets in 2025, a 51% increase from the prior year, with cumulative losses reaching $6.75 billion. Earlier incidents included the $625 million Ronin Bridge theft and the roughly $100 million Harmony Horizon Bridge theft, both attributed by U.S. authorities to Lazarus. Coinbase said the contractor involved was U.S.-based, that no evidence linked the individual to the North Korean government, and that the contract ended within 30 days of onboarding, before any external notification.
Physical coercion against Bitcoin (BTC) and other digital-asset holders is becoming a larger threat, with blockchain analytics data showing more than $30 million stolen through so-called wrench attacks in the first half of 2026. The data, published in a report titled “Violence Against Crypto Owners,” counts only successful forced transfers and excludes failed attempts, ransom demands, and frozen funds, meaning the true exposure is likely higher. If the current pace continues, annual losses would exceed the $58 million recorded in 2025, which stood as the category's prior all-time high. The report describes a shift from purely online fraud and hacking to kidnappings, home invasions, and direct threats against people who control private keys. Because self-custody places final settlement authority in the hands of individuals, criminals increasingly treat holders themselves as the attack surface. France illustrates how data leaks can accelerate violence. The report cites a case in which a French tax-authority employee allegedly stole and sold records containing names, addresses, holdings, and tax information of high-value digital-asset owners. In the first half of 2026, 30 related cases were publicly identified in France, and the French interior ministry began developing rapid-alert and protection measures for high-risk holders. The target set is widening. As of January 2026, attacks against family members or acquaintances represented about 25% to 30% of global cases, while in France the share exceeded 40%. Home invasions also rose sharply, from 14% of cases in 2025 to 37% in the first half of 2026. Unlike fake airdrop lures or malicious job offers, these incidents rely on physical intimidation. Junhyuk Kwon, who leads the analytics firm's Korea operations, said the findings show digital-asset crime is no longer confined to online environments and requires combined on-chain and traditional investigative methods.
COINOTAG's analysis: these two developments show the threat vector moving from remote compromise to physical coercion around Bitcoin (BTC) and other digital assets. The primary records support that conclusion. Coinbase's official statement confirms the affected contractor was terminated within 30 days and had no identified North Korean link, while the violence report's own methodology states it counts only successful seizures, leaving attempts and ransom cases unmeasured. For investors and operators, the lesson is operational: custody security now requires key management, personnel vetting, personal privacy controls, and coordination with law enforcement, not only software defense or market surveillance.
Add COINOTAG as a Preferred Source
Add COINOTAG to your preferred sources in Google News and Search to see our coverage first.
Add on GoogleRelated Tags
AI-generated, AI-reviewed, under COINOTAG editorial oversight.


