Cryptocurrency & Blockchain — Cyber Threat Activity

Cryptocurrency and blockchain is the only sector in this dataset where a nation-state is the dominant financially motivated attacker. Our incident log holds no recorded claims, because exchange thefts are announced by the victim or traced on-chain rather than posted to extortion sites, so the measurable record lives on public ledgers instead. The actor graph reflects who is actually here: 19 groups, and the leading names are overwhelmingly North Korean, including Lazarus Group, APT38, AppleJeus, TraderTraitor, Famous Chollima and Contagious Interview, with 49 malware families linked through those actors. The FBI attributed the theft of roughly $1.5 billion in virtual assets from the Bybit exchange in February 2025 to DPRK operators it tracks as TraderTraitor, and has tied the same activity to earlier eight-figure thefts from Alphapo, CoinsPaid and Atomic Wallet. CISA and partners have documented the method: sustained social engineering against employees of blockchain and virtual asset firms, frequently disguised as recruitment, leading to trojanised trading or wallet applications rather than to any exchange-level exploit. The sector's defining property is that theft is final. There is no chargeback, no clearing house and no reversal, so the attacker's problem is laundering rather than extraction, and the defender's window closes in minutes. Developers, custodians and bridge operators are therefore targeted as individuals, since one engineer's signing key can be worth more than the entire corporate network. Read the empty incident count as a collection limit and the actor list as published government and vendor research rather than incidents we have attributed.

All sectors

Threat actors targeting Cryptocurrency & Blockchain

Malware used against Cryptocurrency & Blockchain

Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.

Where these victims are

Recent incidents

Coverage. 94.7% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.

Read the full analysis on IntelFusions