North Korea’s New Superpower: AI

There’s a change coming to crypto crime, and North Korea’s state-backed hackers are in the vanguard.

There’s no longer any need for dozens of expensively educated programmers to analyze blockchain code and smart contracts for vulnerabilities, it’s now possible to set AI to the task, according to Kostas Kryptos Chalkias, co-founder and chief cryptographer of Mysten Labs.

Large language models represent a greater threat to the industry than quantum computing, which potentially would work so fast that the encryption algorithms used become obsolete. Pyongyang’s cyber units, responsible for stealing an estimated $2 billion in crypto already this year, have begun integrating large language models into nearly every stage of their attacks: reconnaissance, phishing, code analysis and laundering the proceeds, he said.

“AI is the best tool I’ve ever had as a white-hat hacker,” Chalkias said in an interview with CoinDesk. “And you can imagine what happens when it’s in the wrong hands.”

AI-driven theft at record scale

The Lazarus Group, the country’s most notorious hacking unit, has already set records in 2025. Investigators say the $1.5 billion Bybit breach in February, attributed by the FBI to North Korean operatives, was the largest crypto hack in history.

What’s new this year, Chalkias said, is automation. Using AI models similar to ChatGPT and Claude, attackers can now analyze open-source codebases across multiple blockchains, flag likely vulnerabilities and mirror successful exploits from one ecosystem to another.

“AI can combine data from previous hacks and immediately spot the same weakness elsewhere,” he explained. “A human can’t manually scan thousands of smart contracts, but an AI can do it in minutes.”

That ability turns a small cell of state hackers into something resembling a digital industrial complex. “You can scale your attack surface with a single prompt,” Chalkias said. “That’s what makes it dangerous.”

Security researchers at Microsoft and Mandiant have worked together on the trend, documenting a rise in AI-assisted phishing, deepfake impersonations and synthetic job applications used by North Korean operatives posing as Western software developers.

The regime’s AI toolkit now spans the entire intrusion chain from social engineering, code analysis and cross-chain exploitation to laundering, which uses pattern-recognition algorithms to track liquidity paths through mixers and OTC brokers, automating obfuscation.

Quantum: Still distant, but looming

For years, the industry’s doomsday scenario centered on quantum computing: Machines powerful enough to crack bitcoin’s SHA-56 encryption and unlock millions of dormant coins.

Chalkias, who holds a doctorate in identity-based cryptography and has spent more than a decade researching post-quantum algorithms, remains calm.

“There’s no evidence today that any computer, even a classified one, can break modern cryptography,” he said. “We’re at least 10 years away from that.”

He credits organizations like the U.S.’ National Security Agency and Enisa, the European Union’s agency for cybersecurity, for pushing early adoption of quantum-safe standards, and frames those efforts as preventive rather than reactive.

Mysten Labs, developer of the Sui blockchain, is already building migration tools that will let users shift funds into quantum-resistant accounts when the time comes. Chalkias worries that AI might bring that date closer by helping physicists design new materials or error-correction methods.

“The combination of AI and quantum is what freaks me out,” he said. “We might have created a new species, and we can’t predict its pace.”

The bigger and faster threat

While quantum threats remain theoretical, AI is currently breaking things at a rate of knots.

DeFi platforms are particularly exposed, Chalkias said, because open-source code allows AI models, friendly or hostile, to comb through every line of logic.

“AI makes it trivial to find mirrored bugs across protocols,” he said. “If one oracle fails, dozens may share the same flaw.”

He predicts that regulators will soon require continuous, AI-aware auditing for exchanges and smart-contract platforms, essentially a standing red-team that reruns vulnerability scans every time a major AI model is updated.

“Each new version of GPT or Claude finds different weaknesses,” he said. “If you’re not testing against them, you’re already behind.”

Still, AI is a double-edged sword and can be used defensively as well as in attack.

That means embedding AI-based security into wallets, custodians, and exchanges, and re-auditing smart contracts continuously. It also means preparing for the long-term quantum transition now, before regulation forces it.

“Unless we build anti-AI defenses into everything we do,” he warned, “we’ll always be one step behind.”

North Korea’s Next Move

Beyond pure hacking, North Korea has begun experimenting with AI-generated propaganda and disinformation, according to Western intelligence agencies. But Chalkias said he believes the country’s most potent near-term weapon remains AI-enhanced social engineering.

When asked whether North Korea could ever build the first quantum computer, he laughed.

“No,” he said. “The real race is between the U.S. and China. North Korea will overuse AI for phishing, deepfakes and deception. That’s where their strength lies.”

Even without quantum capability, AI lets hackers simulate legitimate users, mimic transactions, and launder funds with unprecedented subtlety.

“They don’t need quantum to break crypto,” Chalkias said. “They just need AI to make the attack invisible.”



Source link

Oliver Knight

https://www.coindesk.com/business/2025/10/25/north-korea-s-ai-powered-hackers-are-redefining-crypto-crime

2025-10-25 12:00:00

bitcoin
Bitcoin (BTC) $ 87,335.00 1.84%
ethereum
Ethereum (ETH) $ 2,819.90 0.03%
tether
Tether (USDT) $ 1.00 0.01%
xrp
XRP (XRP) $ 2.03 0.32%
bnb
BNB (BNB) $ 840.63 2.45%
usd-coin
USDC (USDC) $ 0.99971 0.00%
solana
Solana (SOL) $ 128.80 1.90%
tron
TRON (TRX) $ 0.277687 0.15%
staked-ether
Lido Staked Ether (STETH) $ 2,821.71 0.16%
dogecoin
Dogecoin (DOGE) $ 0.137281 0.67%
cardano
Cardano (ADA) $ 0.394224 3.96%
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03 1.21%
whitebit
WhiteBIT Coin (WBT) $ 57.96 4.53%
wrapped-steth
Wrapped stETH (WSTETH) $ 3,445.31 0.22%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 87,202.00 1.84%
bitcoin-cash
Bitcoin Cash (BCH) $ 531.03 1.79%
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 3,056.82 0.23%
usds
USDS (USDS) $ 0.99973 0.00%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999046 0.02%
leo-token
LEO Token (LEO) $ 9.66 0.44%
hyperliquid
Hyperliquid (HYPE) $ 31.81 4.31%
chainlink
Chainlink (LINK) $ 12.21 1.16%
weth
WETH (WETH) $ 2,822.37 0.05%
stellar
Stellar (XLM) $ 0.235625 2.56%
wrapped-eeth
Wrapped eETH (WEETH) $ 3,054.39 0.08%
monero
Monero (XMR) $ 387.48 6.11%
ethena-usde
Ethena USDe (USDE) $ 0.999247 0.06%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 87,426.00 2.00%
litecoin
Litecoin (LTC) $ 78.43 1.62%
hedera-hashgraph
Hedera (HBAR) $ 0.133627 1.67%
avalanche-2
Avalanche (AVAX) $ 12.92 0.12%
zcash
Zcash (ZEC) $ 325.91 7.98%
sui
Sui (SUI) $ 1.38 2.37%
shiba-inu
Shiba Inu (SHIB) $ 0.000008 0.19%
dai
Dai (DAI) $ 0.999233 0.02%
world-liberty-financial
World Liberty Financial (WLFI) $ 0.157019 7.70%
susds
sUSDS (SUSDS) $ 1.08 0.10%
crypto-com-chain
Cronos (CRO) $ 0.10804 7.59%
paypal-usd
PayPal USD (PYUSD) $ 0.999804 0.01%
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.21 0.05%
usdt0
USDT0 (USDT0) $ 0.999701 0.03%
the-open-network
Toncoin (TON) $ 1.50 1.01%
uniswap
Uniswap (UNI) $ 5.52 0.00%
polkadot
Polkadot (DOT) $ 2.09 3.00%
mantle
Mantle (MNT) $ 0.98627 1.16%
usd1-wlfi
USD1 (USD1) $ 0.999001 0.02%
canton-network
Canton (CC) $ 0.075449 8.77%
aave
Aave (AAVE) $ 170.06 1.80%
bittensor
Bittensor (TAO) $ 261.82 0.53%
bitget-token
Bitget Token (BGB) $ 3.46 0.37%