The landscape of global finance shifted dramatically in early 2025. On February 21, hackers linked to North Korea a country under heavy international sanctions for its nuclear program stole $1.5 billion from the ByBit exchange. It was not just a big hack; it was a signal that state-sponsored cybercrime had become a primary revenue stream for regimes under pressure. This theft, attributed to the Lazarus Group a notorious North Korean hacking unit operating under the Reconnaissance General Bureau, marked a turning point. The international community realized that old diplomatic tools were no longer enough to stop billions of dollars from flowing into illicit weapons programs.
By mid-2026, the situation has only intensified. North Korea generated over $2.17 billion in cryptocurrency thefts in the first half of 2025 alone. To combat this, eleven nations formed a new coalition. But is this new approach working? Or are we playing catch-up against a highly adaptive enemy?
The End of the UN Panel and the Rise of the MSMT
For years, the United Nations relied on the Panel of Experts to monitor sanctions violations in the Democratic People's Republic of Korea (DPRK). However, in May 2024, this panel was dissolved. This created a significant enforcement gap. Without a central body to investigate and report on sanctions breaches, tracking North Korea’s digital heists became fragmented and slow.
In response, ten countries-plus the United States-stepped up. In October 2024, they established the Multilateral Sanctions Monitoring Team (MSMT) a coalition of 11 nations including the US, UK, Japan, and South Korea formed to monitor DPRK sanctions violations. This team includes the United States, Australia, Canada, France, Germany, Italy, Japan, the Netherlands, New Zealand, the Republic of Korea, and the United Kingdom. Unlike the UN’s consensus-based model, which often stalled due to political disagreements, the MSMT operates as an agile coalition of like-minded nations.
The shift was necessary. The UN structure struggled with geopolitical complexities, particularly as North Korea deepened its alliance with Russia. The MSMT aims to bypass these roadblocks by sharing intelligence directly among participating governments. Their goal is simple: document every violation, expose the networks, and freeze assets faster than before.
| Feature | UN Panel of Experts (Pre-2024) | Multilateral Sanctions Monitoring Team (MSMT) |
|---|---|---|
| Structure | Consensus-based UN body | Coalition of 11 specific nations |
| Speed of Action | Slow, bureaucratic processes | Agile, direct intelligence sharing |
| Coverage | Global mandate but limited enforcement power | Focused on participating nations; gaps elsewhere |
| Primary Focus | Broad sanctions compliance | Cybercrime and financial evasion tactics |
How North Korea Steals Billions: Tactics and Tools
To understand the response, you need to understand the threat. The Lazarus Group does not just break into computers; they run a sophisticated criminal enterprise. They target cryptocurrency exchanges, decentralized finance (DeFi) protocols, and even NFT marketplaces. In 2024, North Korea accounted for approximately 35% of all stolen cryptocurrency globally. By late 2025, that figure rose to nearly 39%.
Their methods have evolved. Early hacks relied on basic vulnerabilities. Today, they use advanced social engineering enhanced by artificial intelligence. Between July and September 2025, AI-generated content tricked security teams at three major technology firms. These deepfakes and convincing phishing emails bypassed traditional filters because they sounded exactly like legitimate colleagues or executives.
Another key tactic is the infiltration of Western tech companies. Thousands of North Korean IT workers operate abroad using fake identities. They earn salaries legally while simultaneously conducting espionage and laundering money. The MSMT documented how these workers access defense contractor networks, stealing military technology alongside crypto funds. This dual-threat nature makes them harder to detect and prosecute.
Once the money is stolen, laundering it is the next challenge. North Korean actors rotate through dozens of wallet clustering techniques. In the first half of 2025 alone, they used 17 different methods to obscure their tracks. They utilize decentralized exchanges, cross-chain swaps, and privacy coins like Monero to move funds away from traced addresses.
The Role of Blockchain Analytics and Private Sector Partners
Governments cannot track blockchain transactions alone. They rely heavily on private-sector firms like Chainalysis a leading blockchain data analytics company providing attribution services, Elliptic a blockchain analytics firm specializing in anti-money laundering solutions, and TRM Labs a risk management platform for digital asset transactions. These companies provide the technical infrastructure for attribution. They combine transaction tracing with pattern recognition to identify when funds belong to known DPRK entities.
This public-private partnership is critical. For example, after the LND.fi hack in 2025, coordinated action between these analytics firms and financial intelligence units from five MSMT nations froze $237 million within 72 hours. This was one of the most effective rapid responses to date. It showed that when data flows quickly between private analysts and government enforcers, results follow.
However, there is a cost. Accessing these advanced analytics modules is expensive. Subscription fees for comprehensive DPRK-focused tools can reach $45,000 annually per organization. Smaller exchanges struggle with these costs, leaving them vulnerable. Meanwhile, global spending on blockchain security tools surged by 63% in 2025, reaching $2.8 billion, as institutions scramble to keep pace.
Legal Actions and Asset Recovery Challenges
Tracking the money is only half the battle. Recovering it is another story. The United States Department of Justice has been aggressive, filing 17 civil forfeiture cases between January and September 2025 targeting $214 million in DPRK-linked assets. One notable case involved a $7.7 million seizure of cryptocurrency and NFTs tied to a laundering network.
Yet, recovery rates remain low. Only about 12.3% of seized values are actually recovered. Why? Because by the time authorities identify the wallets, the funds have often moved through multiple layers of obfuscation. Privacy coins and decentralized exchanges make it difficult to pinpoint where the money sits physically. Jurisdictional issues also complicate matters. If funds pass through a non-participating nation, freezing them becomes legally complex and slow.
Regulatory frameworks are tightening to address this. The US implemented Executive Order 14155 in April 2025, requiring exchanges to perform enhanced due diligence on transactions over $10,000. In Europe, the MiCA II regulations took effect on January 1, 2026, establishing stricter rules for cross-border monitoring. Major players like Coinbase and Binance have adopted MSMT-recommended protocols, but smaller platforms still lag behind, creating weak links in the chain.
Future Outlook: The Intelligence Fusion Cell
Looking ahead to late 2026 and beyond, the strategy is shifting from reactive to proactive. The MSMT announced plans to create a dedicated Cryptocurrency Intelligence Fusion Cell in early 2026. Modeled after counterterrorism structures, this cell will pool resources from all 11 member nations. Initial funding stands at $85 million.
The goal is real-time monitoring. Currently, analysis happens after the hack. The fusion cell aims to detect suspicious patterns as they emerge, allowing for pre-emptive freezes. Target implementation is set for Q3 2026. Analysts warn that without such concerted efforts, North Korea will continue to exploit vulnerabilities. With their military cooperation with Russia expanding, the stakes for global security have never been higher.
What is the Multilateral Sanctions Monitoring Team (MSMT)?
The MSMT is a coalition of 11 nations-including the US, UK, Japan, and South Korea-formed in October 2024 to replace the dissolved UN Panel of Experts. Its purpose is to monitor and report on North Korean sanctions violations, specifically focusing on cybercrime and cryptocurrency theft.
How much money has North Korea stolen via crypto since 2024?
Cumulative known value exceeds $6 billion. In the first half of 2025 alone, North Korea generated over $2.17 billion in thefts, with the single largest incident being the $1.5 billion ByBit hack in February 2025.
Who are the Lazarus Group?
The Lazarus Group is a North Korean hacking unit operating under the Reconnaissance General Bureau. They are responsible for the majority of state-sponsored cryptocurrency thefts globally, using sophisticated social engineering and AI-enhanced tactics.
Why did the UN Panel of Experts dissolve?
The UN Panel of Experts was dissolved in May 2024 due to political gridlock and challenges in enforcing mandates, particularly amidst North Korea's deepening alliance with Russia. This led to the creation of the more agile MSMT.
How effective is asset recovery currently?
Recovery rates are low, at approximately 12.3% of seized values. While tracking capabilities have improved with firms like Chainalysis and Elliptic, sophisticated laundering techniques involving privacy coins and decentralized exchanges make final recovery difficult.
What new regulations affect crypto exchanges in 2026?
In the US, Executive Order 14155 requires enhanced due diligence for transactions over $10,000. In the EU, MiCA II regulations effective January 1, 2026, establish comprehensive frameworks for cross-border transaction monitoring.