February 21, 2026, marked one year since North Korean (DPRK) hackers stole approximately $1.46 billion in cryptoassets from Dubai-based exchange Bybit in the largest confirmed crypto theft on record.
Elliptic first attributed the attack to DPRK actors, an assessment later confirmed by the FBI. The group employed novel laundering tactics, including the use of refund addresses, worthless tokens, and diversification across mixing services.
By August 2025, over $1 billion had been laundered, much through suspected Chinese OTC services. Today, most funds are processed, but the Bybit hack marked an escalation, not an end, to DPRK’s crypto theft operations.
DPRK hackers stole a record $2 billion in cryptoassets throughout 2025, pushing their cumulative total past $6 billion. Analysts believe these funds finance North Korea’s nuclear and missile programs.
Activity accelerated in 2026, with Elliptic recording twice as many exploits in January as in the prior year.
Social engineering is the primary attack vector across these incidents, despite the technical exploits that follow. Operatives craft convincing personas and pretexts, likely enhanced by AI, to overcome language barriers and improve deception.

DangerousPassword, Contagious Interview, and IT Infiltration Tactics
Two ongoing campaigns, DangerousPassword and Contagious Interview, have netted $37.5 million since January 1, 2026.
DangerousPassword hijacks compromised social media accounts to contact targets, often citing shared connections, such as past conferences.
Victims join video calls on Zoom or Microsoft Teams, where fake audio errors prompt them to run command-line code installing malware. This malware hunts private keys, seed phrases, and passwords, enabling further account takeovers.
Contagious Interview fabricates job offers, luring targets into “technical tests” via malware-laced code repositories on trusted platforms. Execution deploys similar key-stealing tools.

Both campaigns risk compromising the organization if victims use employer devices. Beyond these, DPRK IT workers infiltrate crypto projects patiently. They use fake identities, cloned accounts, rented laptops for location spoofing, and even refer to accomplices.
Salaries provide direct revenue, but the real goal often involves backdoors, persistent access, or developer machine compromises in remote-first environments.
The Tenexium incident highlights this evolution. On January 1, 2026, Tenexium.io a self-described decentralized margin trading protocol in the Bittensor (TAO) ecosystem went offline amid $2.5 million liquidity drains from its treasury.
Registered in September 2025, the project showed no activity after December 31. Reports flagged DPRK-linked contributors, with blockchain analysis revealing laundering patterns matching known DPRK exploits, including cross-chain overlaps and centralized cashouts.
While not fully proven as a DPRK front from inception, evidence suggests operatives may now build fake projects to siphon funds, shifting from infiltration to creation.
This sustained campaign demands vigilance. DPRK tactics are becoming more sophisticated, blending AI-enhanced phishing, malware, and insider threats.
| Incident | Date | Stolen Amount | Key Tactic | Source |
|---|---|---|---|---|
| Bybit Hack | Feb 2025 | $1.46B | Social Engineering + Exploit | Elliptic, FBI |
| 2025 Total | Jan-Dec 2025 | $2B | Mixed (Social Eng., IT Infil.) | Elliptic |
| Tenexium | Jan 1, 2026 | $2.5M | Suspected Fake Project | X Report |
| DangerousPassword + Contagious Interview | Jan 2026 | $37.5M | Social Engineering | Elliptic Research |
Crypto firms must screen for social engineering red flags like unsolicited calls or repo tests vet remote hires rigorously, and use blockchain analytics across 60+ chains to trace tainted funds. Elliptic’s tools, including Investigator for laundering visualization, help block DPRK-linked assets.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.