Cybersecurity Policy Report, Cryptocurrency Hacks by North Korea Require Federal Response, Senators Say, (May 19, 2025)
A successful and sophisticated cyber attack on Bybit Fintech Ltd. by North Korean hackers has alarmed two Senate Democrats, who today asked the departments of Treasury and Justice to “redouble” their efforts to address North Korea’s cryptocurrency heists.
The Bybit hack, which occurred in February and was blamed on North Korea’s Lazarus Group, “reflects a further escalation in North Korea’s ability to execute complex crypto theft schemes,” Sens. Elizabeth Warren (D., Mass.), ranking member of the Senate Banking, Housing, and Urban Affairs Committee, and Jack Reed (D., R.I.) said today in a letter to Treasury Secretary Scott Bessent and Attorney General Pam Bondi.
“In the attack, hackers pulled approximately $1.5 billion from a ‘cold’ crypto storage wallet—a ‘piece of hardware ... kept mostly isolated from online networks’ that, prior to the attack, were ‘considered to be almost impervious to attacks,’” they said, citing news reports.
“The hack is expected to have significant impacts on the crypto industry and leaves companies scrambling to bolster cybersecurity,” they said.
“Between 2017 and 2023, North Korea stole an estimated $3 billion in crypto hacks, laundering tokens through crypto mixers to effectively mask their origins before funneling the proceeds back to Pyongyang. These stolen assets have helped keep the regime afloat and supported continued investments in its nuclear and conventional weapons programs,” the senators noted.
“In the wake of the Bybit hack, it is essential that the United States redouble its efforts to prevent North Korean crypto theft,” they added.
They asked Mr. Bessent and Ms. Bondi to inform them, by June 2, about the administration’s plans “to address threats to U.S. national security posed by North Korea’s theft of cryptocurrency” and whether Congress can assist those efforts.
News: FederalLegislation DataSecurity