Cryptocurrency thefts have surpassed $1 billion across 212 incidents in 2026, with North Korea-linked groups responsible for the largest share, according to figures published by Chainalysis and other blockchain analytics firms. The tally marks a record pace for the year.
Analysts at firms including Chainalysis and TRM Labs have attributed the bulk of the largest heists to hacking collectives tied to the Democratic People's Republic of Korea, notably the Lazarus Group. These operations typically target centralised exchanges, cross-chain bridges and decentralised finance protocols, using social engineering and code exploits to drain wallets.
The figures reflect a shift toward fewer but larger breaches, researchers said. Stolen funds are frequently laundered through mixing services and converted across multiple blockchains to obscure their origin before reaching entities capable of cashing out.
US and United Nations investigators have long argued that the proceeds help fund Pyongyang's weapons programmes. The report is likely to intensify pressure on exchanges and DeFi platforms to strengthen security and know-your-customer controls.
The US Treasury's Office of Foreign Assets Control has previously sanctioned wallet addresses and mixing services linked to North Korean actors, and further designations remain possible. Security specialists urged the industry to accelerate the adoption of hardware-based key management and independent smart-contract audits, warning that the growing sophistication of state-aligned attackers has outpaced the defences of many smaller platforms.