I thought I knew what I was looking for. I was wrong.
Let me get the disappointing part out of the way first, because I don’t want you thinking I’m about to hand you a spy movie.
I did not sneak into a hacker den. I didn’t put on a fake accent, join an encrypted chat, and fist-bump a guy named “ShadowByte.” I couldn’t have. Nobody reputable could and the people who do get close to these operations are journalists and survivors who risk a lot more than a Substack deadline.
What I actually did was quieter and, I’d argue, more useful. I spent a couple of weeks reading everything I could get my hands on court filings, sanctions notices, blockchain forensics reports, the people who study this for a living. I wanted to find the gang.
And here’s the thing that stopped me cold. There is no gang.
The word itself is a comfort blanket. “Gang” lets you picture a specific villain a face, a crew, a place the police could raid on a Tuesday. But when you follow the money that’s being stolen from crypto right now, it doesn’t lead to a crew. It leads to three things that are much harder to look at.
First, The Scale Because You Need To Feel It
Someone stole a billion and a half dollars in an afternoon
On the 21st of February 2025, a big exchange called Bybit went to do something boring. They were moving a large pile of Ethereum from one wallet to another, the crypto equivalent of a bank shifting cash from the vault to the teller drawer. Routine. They’d done it a thousand times.
Except the screen the staff were approving on had been quietly tampered with. What looked like a normal transfer was actually sending the funds straight to strangers. By the time anyone understood what happened, around $1.5 billion was gone. It remains the single largest theft in the history of crypto, and it was pulled off not by breaking the math of the blockchain, but by fooling the humans clicking “confirm.” Investigators traced it within days.
Zoom out and the number gets heavier. Across all of 2025, roughly $3.4 billion in crypto was stolen worldwide, according to the blockchain-tracking firm Chainalysis. And a single actor was responsible for about 60% of it.
Not a gang. A country.
Face One: The Government That Robs Banks For A Living
It’s not a heist. It’s a line item in a national budget.
The biggest “crypto hacking gang” on Earth is a wing of the North Korean state. Security researchers call the crew Lazarus Group (or, if you like spy names, TraderTraitor). But calling them a “crew” undersells it. This is a government department with a job to do, and the job is: bring home hard currency.
Here’s the incentive, plainly. North Korea is cut off from the normal banking system by sanctions. It can’t easily wire money, sell oil, or move dollars through the usual pipes. So it went looking for a pipe that doesn’t run through banks and crypto is exactly that. Borderless. Permission-free. No manager to call and freeze the account. The same features that make blockchain exciting as financial infrastructure make it the perfect getaway car for a sanctioned regime.
And the scale of the operation shows it’s institutional, not opportunistic. By the end of 2025, North Korea’s total crypto haul over the years crossed roughly $6.75 billion. In 2025 alone they set a record about $2 billion while doing fewer attacks. Fewer, but each one enormous. That’s not a smash-and-grab mindset. That’s a strategy meeting.
Investigators have even mapped the routine. After a big theft, the stolen funds move through a laundering cycle that runs, on average, around 45 days, a predictable rhythm of obscuring, shuffling, and cashing out. Predictable, because it’s a process someone was told to follow. It’s a workflow. It has a manual. Somewhere, there is probably a spreadsheet.
When a nation-state runs the crime, you can’t arrest your way out of it. You can’t raid a country’s budget.
Where does the money go? US and UN officials have said for years that these funds help pay for North Korea’s nuclear weapons and missile programs. So the uncomfortable through-line is this: a badly-secured “confirm” button on a crypto exchange can end up buying a component for a rocket. That’s the actual supply chain. It’s not thrilling. It’s bureaucratic. And bureaucracy is far harder to stop than a villain.
Face Two: The Call Is Coming From Inside The House
You imagined infiltrating them. They’ve been infiltrating you.
This is the part that flipped my whole picture around.
When you think “hacker,” you think of someone breaking in from the outside battering the firewall, cracking a password. But the fastest-growing method right now is the opposite. They don’t break in. They get hired.
Thousands of North Korean IT workers apply for ordinary remote developer jobs at tech and crypto companies all over the world, using fake names, borrowed identities, and AI-polished résumés. In the job interview, some now use real-time deepfake video so the face on the call isn’t the face doing the work. They pass the vibe check. They’re often good coders. They get the offer, the laptop, the login and, eventually, the keys to move money.
How big is this? One North Korean group, nicknamed Famous Chollima, accounted for nearly half of all state-sponsored “hands-on-keyboard” intrusions against tech companies in the year ending March 2026, per CrowdStrike’s threat researchers. Blockchain analysts now believe a chunk of that record-breaking theft happened precisely because the thief was already inside a trusted employee, badge and all.
And it needed help from ordinary people to work. My favourite (wrong word most unsettling) detail is a woman in Arizona named Christina Chapman. She ran what prosecutors called a “laptop farm” out of her house: rows of company laptops, each with a sticky note saying which American identity and which employer it belonged to. The North Koreans logged in remotely; the laptops sat in Arizona, so to the employer everything looked domestic. The scheme touched more than 300 US companies including Fortune 500 names, a major broadcaster, an aerospace firm and moved over $17 million to the regime. She was sentenced in 2025 to eight and a half years.
The Line That Stuck With Me
A US prosecutor summed the whole thing up better than I can. On the fake-employee schemes, she said the call is coming from inside the house, if it hit household-name corporations with real security teams, it can just as easily be happening at yours. The threat isn’t at the gate. It filled out an onboarding form and joined the Monday standup.
Face Three: The Scammer Texting You Might Be A Prisoner
The cruellest twist: many “criminals” are victims too
Now the hardest face to look at.
You’ve gotten the message. “Hey Sarah, still on for lunch?” except you’re not Sarah and you’ve never met this person. You reply “wrong number,” they’re weirdly nice, a friendship forms over weeks, and eventually there’s a “can’t-miss” crypto investment on a slick app that shows your money growing beautifully. Until you try to withdraw. Then it’s gone. This is called pig butchering , the target is fattened up emotionally before being financially, well, slaughtered. Ugly name. Accurate name.
Here’s what almost nobody on the receiving end realises. The person typing those sweet messages is very often not free. Across Myanmar, Cambodia, and Laos, entire compounds run these scams as factories and the United Nations estimates over 200,000 people have been trafficked into them. They answered a fake job ad, flew somewhere for what looked like a normal office role, and instead had their passport taken, a daily scam quota set, and violence promised if they missed it or tried to leave.
So the “gang member” on the other end of your scam is sometimes a person behind a locked gate, being forced to rob you so their own captors don’t hurt them. Two victims. One transaction. The money flows up and out to the organised crime networks often laundered through crypto while the two humans at either end of the chat both lose.
These aren’t fringe amounts, either. Governments have started sanctioning these compounds directly; the scale of the fraud economy in that corner of the world is now estimated to rival a large slice of some countries’ entire GDP. This is an industry. With HR problems it solves through kidnapping.
So Why Does This Whole Machine Exist?
Follow the incentives, not the villains
At Naked Market we have one rule that never fails: when something crazy keeps happening, don’t ask “who’s the bad guy?” Ask “what does the system reward?” The bad guy is a symptom. The incentive is the disease.
So why crypto, specifically, for all three faces? Because crypto’s genuine superpowers are also, in the wrong hands, its exploit.
A. No bank to say no
Money moves without a middleman’s permission. Wonderful if you’re unbanked. Also wonderful if you’re a sanctioned state that no bank will touch.
B. Instant and borderless
Value crosses the planet in minutes. Great for a migrant sending wages home. Great, too, for whisking $1.5 billion out of reach before the coffee gets cold.
C. Final settlement
Once it’s sent, there’s no chargeback, no fraud department to reverse it. That certainty is the whole point of the technology. It’s also why victims almost never get their money back.
None of that makes crypto “bad.” Cash funded crime for centuries and we didn’t ban paper. But it does mean the honest builders and the state-run thieves are riding the exact same rails and pretending otherwise is how you get robbed. We dug into this same tension in Crypto Was Supposed to Escape the System, if you want the longer version.
The Plot Twist That Should Give You Hope
The reason we know all of this? The blockchain snitched.
Quick gut-check question. If these thieves are so sophisticated, how do we know the exact dollar amounts, the 45-day laundering cycle, the wallet trails, down to the transaction?
Because the blockchain wrote it all down. Every move those stolen coins make is recorded on a public ledger that anyone can read forever. Firms like Chainalysis and TRM Labs don’t need to hack anyone back they just read the receipts. Within minutes of the Bybit theft, analysts had already tagged the thief’s addresses and started watching the money squirm in real time.
Sit with the irony. Criminals chose crypto because it dodges the banking system’s watchers. But in dodging the banks, they stepped onto the most transparent financial rails ever built. The getaway car has a permanent, public GPS tracker bolted to the roof. It’s the same reason bribery can’t really hide on a blockchain, the ledger doesn’t forget, and it doesn’t take sides.
Where This Goes Next
The next target isn’t your wallet. It’s your AI.
Here’s what I’m watching, and what I think most people haven’t clocked yet.
As more of finance gets handed to AI agents, little software workers that hold funds, sign transactions, and act on your behalf, the attackers are already turning toward them. Why phish a careful human when you can trick a fast, tireless bot into approving a transfer? The deepfake résumés and the fake job interviews are just the current chapter. The next one is agents scamming agents, at machine speed, around the clock.
Which means the defender’s job quietly changes shape. It stops being “spot the shady link” and becomes “verify who and what you’re really trusting” every employee, every counterparty, every automated helper. That’s a systems problem, and systems problems reward people who think in systems. (We poked at whether AI can be trusted to guard the gate in Can You Trust AI to Catch Fraud?)
The scam of the future won’t ask you to click. It’ll ask your assistant to and your assistant is faster, more trusting, and never sleeps.The shift Naked Market is watching
The Mental Model To Take With You
There is no gang. There’s a state, a structure, and a supply chain.
If you remember one thing from today, make it this lens. Next time a headline says “crypto hacking gang,” quietly ask which of these three you’re actually looking at because the right response is completely different for each:
The State
A government treating theft as revenue. You can’t police this; it’s diplomacy, sanctions, and hardening the targets. There’s no door to kick in.
2. The Structure
The threat that got hired. The fix isn’t a bigger firewall, it’s verifying identity, inside the building, on your own team. Trust is now the attack surface.
3. The Supply Chain
Fraud produced by trafficked, coerced labour. The “criminal” may be a captive. Solving it is a human-rights problem wearing a cybercrime mask.
The word “gang” flattens all three into one cartoon so your brain can file it under “not my problem, that’s for the FBI.” Drop the cartoon and you see the real machine — a machine that grows precisely because it’s structural, not personal. You can’t behead a payroll. You can’t arrest a labour market. You can’t raid a country’s budget line.
But you can stop expecting a villain and start reading the system. That’s the whole game. It always was.
I went looking for a gang and found a mirror instead one pointed at how modern crime really organises itself. Which, weirdly, made me feel more prepared than any spy story could have.
– Chetan
If you want to understand where money is heading before it becomes obvious, this is the room for it.Subscribe to Naked Market
Keep Pulling The Thread
Start here → One Planet, 180 Currencies, Something’s Off — the welcome post, and the whole reason Naked Market exists.Crypto Was Supposed to Escape the System — why the same rails that free people also arm regimes.Why Bribery Can’t Hide on a Blockchain — the transparency twist, in full.Can You Trust AI to Catch Fraud? — the next battlefield: agents vs. agents.
-More Soon
I Went Looking for the Crypto Hacking Gang. This is What I Found was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.
