# Experts weigh state-linked crypto hacking threats

Published: 2023-05-03 · Severity: medium · Sectors: financial-services
Canonical: https://vorant.io/reports/146ffcbf-fe5a-5e56-8159-ea411373ccf2/experts-weigh-state-linked-crypto-hacking-threats

> Atlantic Council roundtable examines how North Korea, Russia, and other state actors exploit DeFi and crypto vulnerabilities for financial and geopolitical gain.

This Atlantic Council 5×5 expert panel discusses the cybersecurity risks inherent to cryptocurrency and decentralized finance (DeFi), noting that DeFi protocols accounted for the vast majority of the $3.8 billion in cryptocurrency stolen globally in 2022. Experts highlight that most attacks exploit vulnerabilities in smart contract code, cross-chain bridges, and wallet infrastructure rather than novel cryptographic breaks, with North Korea-linked actors like the Lazarus Group cited as the most capable and active state-sponsored threat, having stolen an estimated $1.7 billion in 2022 to fund weapons programs. Russia-based money laundering networks, including entities tied to Moscow's Federation Tower East and sanctioned exchanges Bitzlato and Garantex, are also discussed as key enablers of ransomware-related crypto laundering.

The panel covers the Harmony bridge hack (June 2022, ~$100 million), a January 2023 US-South Korean operation to interdict stolen funds, and other high-profile 2022 incidents including Wormhole, Ronin, and BitMart. Contributors emphasize that policy responses—sanctions, blockchain analytics, law enforcement takedowns of darknet markets like Hydra and Genesis Market, and smart contract security standards—represent the primary tools for mitigating state and non-state abuse of cryptocurrency infrastructure. The piece is a policy-oriented discussion rather than a report on a specific new incident, with recurring themes of decentralization's dual-edged security implications and the growing overlap between ransomware, money laundering, and state-sponsored crypto theft.

## Mentioned in this report

- Threat actors: Lazarus Group
- Campaigns: BitMart Hack, Harmony Bridge Hack, Ronin Bridge Hack, Wormhole Hack

Source reporting: https://www.atlanticcouncil.org/content-series/the-5x5/the-5x5-cryptocurrency-hackings-geopolitical-and-cyber-implications

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/146ffcbf-fe5a-5e56-8159-ea411373ccf2/experts-weigh-state-linked-crypto-hacking-threats.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
