According to Cointelegraph, cryptocurrency company Paradigm warned in a report titled "Unveiling the Mystery of North Korea's Threat" that North Korea's cyber warfare attacks on the cryptocurrency industry are becoming increasingly complex, and the number of groups involved in such criminal activities is also increasing. The report points out that North Korea has launched a wide range of cyber attacks, from exchange attacks and social engineering attempts to phishing attacks and complex supply chain hijacking. In some cases, these attacks can last up to a year, and North Korean hackers will patiently wait for the right opportunity.
Paradigm wrote that there were at least five North Korean organizations planning these attacks: Lazarus Group, Spinout, AppleJeus, Dangerous Password, and TraitorTrader. In addition, there is an alliance composed of North Korean hackers who disguise themselves as IT workers and infiltrate technology companies around the world.
Lazarus Group has planned some high-profile cyber attacks since 2016. According to Paradigm, the group attacked Sony and Bangladesh Bank in 2016 and assisted in planning the WannaCry 2.0 ransomware attack in 2017. The team also targeted the cryptocurrency industry, as the group attacked two cryptocurrency exchanges - Youbit and Bithumb - in 2017. In 2022, Lazarus Group exploited the Ronin Bridge vulnerability, resulting in millions of dollars in asset losses. In 2025, Lazarus Group stole $1.5 billion from Bybit, shocking the entire crypto community. The group may also be involved in some Solana meme coin scams.