
A new report from the Japan Times, citing Japanese authorities, confirms what security researchers have been warning about for years: North Korea’s state-linked hacking groups aren’t just picking off a few high-profile exchanges anymore. They’ve built a theft operation with victims in roughly 100 countries a scale that makes them closer to a global criminal enterprise than a rogue nation-state side hustle.
This isn’t a story about one hack. It’s an infrastructure story. Groups like Lazarus and its offshoots (TraderTraitor, BlueNoroff, APT38 — the naming gets murky because North Korea runs multiple units under different aliases) have spent nearly a decade refining a playbook: fake job offers to developers, poisoned software updates, social engineering against exchange employees, and increasingly sophisticated smart contract exploits. Japan is just the latest country to acknowledge being on that list publicly, but the real headline is the geographic spread — this isn’t a regional problem confined to Asia or crypto-heavy jurisdictions like the U.S. and South Korea.
Why does this matter beyond the security community? Because the money funds North Korea’s weapons programs. UN and U.S. Treasury assessments have repeatedly tied crypto theft proceeds to missile development, and the scale reported here — 100 countries — suggests the funding pipeline is far more resilient and diversified than sanctions enforcement has been able to keep up with.
What This Means
The 100-country figure is the real signal here, not the Japan-specific detail. It tells you North Korean hacking units have moved past targeting marquee exchanges (Bybit, Coincheck, and WazirX have all been hit in recent years) and are now running a distributed, opportunistic model — smaller exchanges, DeFi protocols, individual wallets, even crypto-adjacent startups with weak operational security. That’s a shift from “big game hunting” to something closer to industrial-scale trawling, and it means the threat surface has effectively become every crypto business on earth, not just the ones with billion-dollar treasuries.
It also exposes a structural weakness in how the industry has responded to this threat. Exchanges have gotten better at cold storage and multisig custody after the Mt. Gox and Coincheck disasters, but the entry point for most of these attacks isn’t a smart contract flaw — it’s a phishing email, a fake recruiter on LinkedIn, or a compromised employee laptop. Japan’s own experience with Coincheck in 2018 and the more recent DMM Bitcoin breach (reportedly linked to North Korean actors; the attack resulted in the theft of 4,502.9 Bitcoin (BTC)
Fiat Value: Valued at approximately ¥48.2 billion JPY or $305 million to $308 million USD at the time of the exploit. shows that even mature, regulated markets aren’t immune. Regulation and custody standards have improved; human-layer security largely hasn’t kept pace.
Compare this to how the traditional banking sector handles state-sponsored cyber threats: banks share threat intelligence through formal networks like FS-ISAC, and regulators mandate specific incident reporting and red-team testing. Crypto’s equivalent infrastructure is patchy at best — exchanges in smaller markets, especially in the 100 countries now reportedly affected, likely have nowhere near that level of coordinated defense. That gap is exactly what North Korean operators are exploiting.
Our Take
The uncomfortable truth is that sanctions and law enforcement have not meaningfully slowed this down. The U.S. Treasury has sanctioned Lazarus-linked wallets and individuals repeatedly since 2019, and the FBI has issued specific warnings about North Korean recruiting tactics targeting crypto developers, yet the theft totals keep climbing, and now the geographic reach has expanded to match. That’s not a failure of any single company’s security team; it’s a failure of the ecosystem to treat this as the persistent, well-resourced threat it actually is.
Worth Watching
- Will Japan’s Financial Services Agency introduce new mandatory security disclosure or employee-vetting rules for exchanges in response to this report, similar to what followed the Coincheck breach?
- Do international bodies FATF and the UN Panel of Experts on North Korea push for a more coordinated cross-border threat-intelligence sharing mechanism specifically for crypto, given the confirmed 100-country reach?
- Will exchanges in smaller, less-regulated markets (the likely weak links in that 100-country figure) face increased scrutiny or delisting pressure from larger partners and liquidity providers as this pattern becomes harder to ignore?