Reports published on February 6, 2022 disclosed that United Nations sanctions monitors regarded cyberattacks—particularly attacks involving cryptocurrency—as an important revenue source for North Korea while the country continued developing its nuclear and ballistic-missile capabilities.

The finding made cryptocurrency security a matter of international sanctions enforcement, not merely a problem of losses at exchanges. Digital assets offered state-linked attackers globally accessible targets, multiple instruments to steal and swap, and services that could be used to complicate tracing. At the same time, public blockchains created transaction records that investigators and analytics companies could examine after an intrusion.

Two estimates covered different periods

According to the contemporaneous account of the confidential UN report, information supplied by one member state attributed more than $50 million in stolen digital assets to North Korean cyber actors between the beginning of 2020 and the middle of 2021. At least three cryptocurrency exchanges in North America, Europe and Asia were reportedly affected.

That estimate was distinct from a Chainalysis analysis cited by the monitors. Chainalysis estimated on January 13, 2022 that North Korea-linked hackers conducted at least seven attacks against cryptocurrency platforms during calendar year 2021, extracting nearly $400 million in digital assets. The company calculated that the number of attributed attacks increased from four in 2020 to seven in 2021, while the estimated dollar value extracted increased 40%.

The two dollar figures should not be added together. They used overlapping but different measurement windows, came from different evidence providers and did not identify the same set of incidents. Neither was an audited government account of cash ultimately received by North Korea. Cryptocurrency values also change after theft, so a dollar estimate depends on the analyst’s valuation time and methodology.

Ether and tokens changed the laundering path

Chainalysis estimated that ether represented 58% of the value stolen in the seven attributed 2021 attacks. Bitcoin accounted for 20%, while ERC-20 tokens and other alternative cryptocurrencies represented the remaining 22%. That composition mattered because attackers acquiring numerous tokens could first use decentralized exchanges to convert them into more liquid assets.

The firm described a recurring sequence in which tokens were exchanged for ether, ether was passed through mixing services, the proceeds were converted into bitcoin, and bitcoin was mixed and consolidated before being sent toward exchange deposit addresses. Chainalysis estimated that more than 65% of North Korea-linked stolen funds moved through mixers during 2021, compared with 42% in 2020 and 21% in 2019.

Those percentages were Chainalysis findings based on its address attribution and transaction-clustering methods. They were not complete measurements of every North Korean cyber operation, and the company acknowledged that many attacks were likely—but not necessarily conclusively—conducted by the Lazarus Group. On-chain movement can establish transaction paths without independently proving who controlled every address or whether assets were successfully converted into sovereign currency.

The institutional context was already established

The February 6 disclosure did not introduce the state-attribution theory from nothing. On September 13, 2019, the U.S. Treasury Department designated Lazarus Group, Bluenoroff and Andariel as North Korean state-sponsored cyber groups controlled by the Reconnaissance General Bureau. Treasury said their activity included financial and cryptocurrency theft intended to generate revenue for the regime and potentially support prohibited weapons programs.

Still, the UN monitors’ assessment carried separate institutional weight. It placed current cryptocurrency theft inside the Security Council’s monitoring of sanctions imposed over North Korea’s nuclear and ballistic-missile activities. North Korea’s UN mission did not immediately respond to Reuters’ February 6 request for comment, and the confidential report was not yet available for public line-by-line scrutiny.

Later documentary confirmation

The Security Council published the panel’s final report as document S/2022/132 on March 1, 2022. Paragraphs 182 through 184 preserved the core cryptocurrency findings reported on February 6, including the member-state estimate, the Chainalysis figures and the assessment that cyberattacks remained an important revenue source. That later publication confirms what was reported on the event date; it does not establish the outcome of any individual theft or the final use of particular assets.

Primary sourceUnited Nations Security Council — Final report of the Panel of Experts, S/2022/132

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.