Cryptocurrency & Blockchain — Cyber Threat Activity
Cryptocurrency and blockchain is the only sector in this dataset where a nation-state is the dominant financially motivated attacker. Our incident log holds no recorded claims, because exchange thefts are announced by the victim or traced on-chain rather than posted to extortion sites, so the measurable record lives on public ledgers instead. The actor graph reflects who is actually here: 19 groups, and the leading names are overwhelmingly North Korean, including Lazarus Group, APT38, AppleJeus, TraderTraitor, Famous Chollima and Contagious Interview, with 49 malware families linked through those actors. The FBI attributed the theft of roughly $1.5 billion in virtual assets from the Bybit exchange in February 2025 to DPRK operators it tracks as TraderTraitor, and has tied the same activity to earlier eight-figure thefts from Alphapo, CoinsPaid and Atomic Wallet. CISA and partners have documented the method: sustained social engineering against employees of blockchain and virtual asset firms, frequently disguised as recruitment, leading to trojanised trading or wallet applications rather than to any exchange-level exploit. The sector's defining property is that theft is final. There is no chargeback, no clearing house and no reversal, so the attacker's problem is laundering rather than extraction, and the defender's window closes in minutes. Developers, custodians and bridge operators are therefore targeted as individuals, since one engineer's signing key can be worth more than the entire corporate network. Read the empty incident count as a collection limit and the actor list as published government and vendor research rather than incidents we have attributed.
- Recorded incidents: 14
- Incidents, trailing 180 days: 1
- Tracked threat actors: 20
- Malware families: 53
Threat actors targeting Cryptocurrency & Blockchain
- ShinyHunters 1 incident
- Lazarus Group researched targeting
- AppleJeus researched targeting
- APT38 researched targeting
- Famous Chollima researched targeting
- TraderTraitor researched targeting
- Contagious Interview researched targeting
- Coral Sleet researched targeting
- Earth Lusca researched targeting
- ELUSIVE COMET researched targeting
- Evilnum researched targeting
- GCMAN researched targeting
- Genesis Market researched targeting
- Mekotio researched targeting
- Moonstone Sleet researched targeting
- Pacha Group researched targeting
- PoisonSeed researched targeting
- Rocke researched targeting
- TA576 researched targeting
- TeamTNT researched targeting
Malware used against Cryptocurrency & Blockchain
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Cobalt Strike Malware
- Mimikatz Tool
- Qilin Malware
- WannaCry Malware
- BeaverTail Malware
- DarkComet Malware
- InvisibleFerret Malware
- KillDisk Malware
- LaZagne Tool
- NETWIRE Malware
- njRAT Malware
- PowerSploit Tool
Where these victims are
Recent incidents
- Bitcoin Depot Inc. 2026-04-08
- TripleA (aaa.com) 2025-10-03
- Gemini 2022-12-13
- CoinTracker 2022-12-01
- BTC-Alpha 2021-11-02
- CoinMarketCap 2021-10-12
- Ledger 2020-06-25
- GateHub 2019-06-04
- Atlas Quantum 2018-08-25
- InfoCorp Technologies Pte. Ltd. 2018-02-05
- Coinmama 2017-08-03
- Ethereum 2016-12-16
- Bitcoin Talk 2015-05-22
- BTC-E 2014-10-01
Coverage. 94.7% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.