VORANT. Threat Intelligence Sign in Get the full feed

Experts weigh state-linked crypto hacking threats

medium threat financial-services

Atlantic Council roundtable examines how North Korea, Russia, and other state actors exploit DeFi and crypto vulnerabilities for financial and geopolitical gain.

This Atlantic Council 5×5 expert panel discusses the cybersecurity risks inherent to cryptocurrency and decentralized finance (DeFi), noting that DeFi protocols accounted for the vast majority of the $3.8 billion in cryptocurrency stolen globally in 2022. Experts highlight that most attacks exploit vulnerabilities in smart contract code, cross-chain bridges, and wallet infrastructure rather than novel cryptographic breaks, with North Korea-linked actors like the Lazarus Group cited as the most capable and active state-sponsored threat, having stolen an estimated $1.7 billion in 2022 to fund weapons programs. Russia-based money laundering networks, including entities tied to Moscow's Federation Tower East and sanctioned exchanges Bitzlato and Garantex, are also discussed as key enablers of ransomware-related crypto laundering.

The panel covers the Harmony bridge hack (June 2022, ~$100 million), a January 2023 US-South Korean operation to interdict stolen funds, and other high-profile 2022 incidents including Wormhole, Ronin, and BitMart. Contributors emphasize that policy responses—sanctions, blockchain analytics, law enforcement takedowns of darknet markets like Hydra and Genesis Market, and smart contract security standards—represent the primary tools for mitigating state and non-state abuse of cryptocurrency infrastructure. The piece is a policy-oriented discussion rather than a report on a specific new incident, with recurring themes of decentralization's dual-edged security implications and the growing overlap between ransomware, money laundering, and state-sponsored crypto theft.

Mentioned in this report

Threat actors Lazarus Group
Campaigns BitMart HackHarmony Bridge HackRonin Bridge HackWormhole Hack

Source reporting: https://www.atlanticcouncil.org/content-series/the-5x5/the-5x5-cryptocurrency-hackings-geopolitical-and-cyber-implications

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free