North Korea's nuclear program is funded by stolen cryptocurrency. Could it collapse now that FTX has?
- Written by James Jin Kang, Adjunct Lecturer, Computing and Security, Edith Cowan University
Since the world’s second-largest crypto exchange, FTX, declared bankruptcy[1] earlier this month, the flow-on effects[2] have been felt far and wide[3].
But among the many victims are also some not-so-innocent parties. For the Democratic People’s Republic of Korea, a country facing heavy sanctions, cryptocurrency theft has been a (relatively) simple way[4] to fund the country’s expanding nuclear arsenal.
It’s well documented[5] that Kim Jong-un’s military operation hackers have been stealing cryptocurrency[6] to support North Korea’s nuclear and missile program[7] for several years.
But with the general downturn in the crypto market, coupled with the recent FTX collapse and myriad other pitfalls[8], analysts estimate North Korea has probably lost most of its crypto haul[9].
Can we expect its nuclear weapons development to come to a halt, or slow down? It seems unlikely.
What North Korea’s hackers have been up to
North Korea sponsors several hacker groups, including Lazarus Group[10] (also called Guardian of Peace and Whois Team) and Advanced Persistent Threat 38 (APT38[11]).
While nobody knows exactly how many North Korea-backed hackers there are, experts have estimated[12] Kim Jong-un has between 6,000 and 7,000[13] working both inside and outside the country.
North Korea has invested in its national cybercrime arsenal for some 15 years[14]. It’s almost impossible for an organisation to defend itself against an army of this size and calibre once it comes charging.
In 2016, Lazarus hackers came close to stealing US$1 billion[15] from Bangladesh’s national bank – but a typo in the computer code meant they only got away with US$81 million.
Since then, they’ve refined their methods. Lazarus has been accused of stealing US$571 million[16] from cryptocurrency exchanges between January 2017 and September 2018, US$316 million[17] from 2019 to November 2020, and US$840 million in the first five months[18] of 2022.
According to Chainalysis, North Korean hackers have stolen an estimated[19] total of about US$1 billion in cryptocurrency this year. A large chunk of this would have come from Lazarus’ massively lucrative heist against NFT-based online game Axie Infinity. In April, US authorities held the group responsible for stealing US$620 million[20] in cryptocurrency from the game.
For context, it’s estimated[21] North Korea only earned about US$142 million from trade exports in 2020.
Okay, so how much has it now lost?
It’s difficult to say exactly how much cryptocurrency has been stolen (and used) by North Korean hackers – and therefore how much might remain.
In June, blockchain analyst and former FBI analyst Nick Carlsen told Reuters[22] one of North Korea’s crypto caches had lost 80% to 85% of its value in a number of weeks, falling to less than US$10 million.
Losses will have intensified following the FTX collapse. According to a Chainalysis report[23], in January North Korea held about US$170 million in stolen unlaundered cryptocurrency, taken from 49 hacks conducted from 2017 to 2021. It also claims Ether was the most common cryptocurrency stolen by North Korea in 2021, making up 58% of the total theft.
Ether’s value[24] fell by more than 20% following the FTX crash, and remains low. It’s reasonable to expect North Korea will wait before cashing out. When it does, experts looking on will be in a better place to figure out how much it has.
Why steal crypto to fund nuclear weapons tests?
The United States, South Korea and Japan have been warning[25] North Korea against conducting a seventh nuclear test. But Kim Jong-un doesn’t seem to be letting up. On Saturday, at the launch of North Korea’s largest ballistic missile yet, he told state media[26] the:
ultimate goal is to possess the world’s most powerful strategic force, the absolute force unprecedented in the century.
International sanctions and border closures due to COVID-19 have made it difficult for North Korea to trade and generate funds through other means – which makes the cryptocurrency market an attractive target.
Cryptocurrency remains unregulated by most countries’ governments. At the same time, transactions can be made quickly, and allow more anonymity than transactions made through traditional banking systems.
It’s also easier to hack a cryptocurrency exchange than it is to hack a bank. The latter are almost always bolstered by advanced security barriers and sometimes require in-person appearances.
Read more: Cryptocurrency has an impact on economies. That's why some are afraid of it – and some welcome it[27]
No more missile tests, for now?
The rapid drop in crypto’s value, compounded by the FTX crash, will have certainly left a dent in North Korea’s nuclear military expansion funds. Nonetheless, Kim Jong-un’s cybercriminal army will likely find new sources of illicit income (and will probably keep stealing crypto too).
North Korea has[28] also had[29] financial support[30] from supporters in South Korea who follow the “Juche” ideology – the same Marxist-Leninist-adjacent political philosophy imposed in North Korea.
And in April American crypto expert Virgil Griffith pleaded guilty[31] to helping North Korea evade US sanctions through using cryptocurrency.
Then there’s China – a key player in deciding whether sanctions against North Korea will actually work. In May, China joined Russia in vetoing[32] a draft proposal from the US to tighten sanctions against North Korea, and continues to trade with it[33].
As long as North Korea can glean financial benefit from China, and other avenues as mentioned above, it’s unlikely to stop its plans.
Read more: It's time to take Kim Jong Un and his nuclear threats seriously[34]
References
- ^ declared bankruptcy (www.theguardian.com)
- ^ flow-on effects (www.theguardian.com)
- ^ far and wide (www.nature.com)
- ^ simple way (www.nytimes.com)
- ^ documented (www.reuters.com)
- ^ stealing cryptocurrency (www.reuters.com)
- ^ nuclear and missile program (thediplomat.com)
- ^ other pitfalls (www.forbes.com)
- ^ crypto haul (www.zawya.com)
- ^ Lazarus Group (www.makeuseof.com)
- ^ APT38 (cybersophia.net)
- ^ have estimated (www.cnet.com)
- ^ 6,000 and 7,000 (www.bloomberg.com)
- ^ for some 15 years (www.washingtonpost.com)
- ^ stealing US$1 billion (www.bbc.com)
- ^ US$571 million (undocs.org)
- ^ US$316 million (www.securitycouncilreport.org)
- ^ the first five months (blog.chainalysis.com)
- ^ stolen an estimated (blog.chainalysis.com)
- ^ US$620 million (www.nytimes.com)
- ^ estimated (oec.world)
- ^ told Reuters (www.reuters.com)
- ^ Chainalysis report (blog.chainalysis.com)
- ^ Ether’s value (www.google.com)
- ^ have been warning (www.ft.com)
- ^ told state media (www.aljazeera.com)
- ^ Cryptocurrency has an impact on economies. That's why some are afraid of it – and some welcome it (theconversation.com)
- ^ has (www.sedaily.com)
- ^ had (namu.wiki)
- ^ financial support (www.sisaweek.com)
- ^ pleaded guilty (www.bbc.com)
- ^ in vetoing (www.aljazeera.com)
- ^ trade with it (thediplomat.com)
- ^ It's time to take Kim Jong Un and his nuclear threats seriously (theconversation.com)