
{"id":212614,"date":"2026-08-13T07:19:11","date_gmt":"2026-08-13T07:19:11","guid":{"rendered":"https:\/\/mycryptomania.com\/?p=212614"},"modified":"2026-08-13T07:19:11","modified_gmt":"2026-08-13T07:19:11","slug":"i-went-looking-for-the-crypto-hacking-gang-this-is-what-i-found","status":"publish","type":"post","link":"https:\/\/mycryptomania.com\/?p=212614","title":{"rendered":"I Went Looking for the Crypto Hacking Gang. This is What I Found"},"content":{"rendered":"<p><em>I thought I knew what I was looking for. I was\u00a0wrong.<\/em><\/p>\n<p>Let me get the disappointing part out of the way first, because I don\u2019t want you thinking I\u2019m about to hand you a spy\u00a0movie.<\/p>\n<p>I did not sneak into a hacker den. I didn\u2019t put on a fake accent, join an encrypted chat, and fist-bump a guy named \u201cShadowByte.\u201d I couldn\u2019t have. Nobody reputable could and the people who <em>do<\/em> get close to these operations are journalists and survivors who risk a lot more than a Substack deadline.<\/p>\n<p>What I actually did was quieter and, I\u2019d argue, more useful. I spent a couple of weeks reading everything I could get my hands on court filings, sanctions notices, blockchain forensics reports, the people who study this for a living. I wanted to find the\u00a0gang.<\/p>\n<p>And here\u2019s the thing that stopped me cold. <strong>There is no\u00a0gang.<\/strong><\/p>\n<p>The word itself is a comfort blanket. \u201cGang\u201d lets you picture a specific villain a face, a crew, a place the police could raid on a Tuesday. But when you follow the money that\u2019s being stolen from crypto right now, it doesn\u2019t lead to a crew. It leads to three things that are much harder to look\u00a0at.<\/p>\n<p><strong>First, The Scale Because You Need To Feel\u00a0It<\/strong><\/p>\n<h3>Someone stole a billion and a half dollars in an afternoon<\/h3>\n<p>On the 21st of February 2025, a big exchange called Bybit went to do something boring. They were moving a large pile of Ethereum from one wallet to another, the crypto equivalent of a bank shifting cash from the vault to the teller drawer. Routine. They\u2019d done it a thousand\u00a0times.<\/p>\n<p>Except the screen the staff were approving on had been quietly tampered with. What looked like a normal transfer was actually sending the funds straight to strangers. By the time anyone understood what happened, around <strong>$1.5 billion<\/strong> was gone. It remains the single largest theft in the history of crypto, and it was pulled off not by breaking the math of the blockchain, but by fooling the humans clicking \u201cconfirm.\u201d <a href=\"https:\/\/www.trmlabs.com\/resources\/blog\/the-bybit-hack-following-north-koreas-largest-exploit\">Investigators traced it<\/a> within\u00a0days.<\/p>\n<p>Zoom out and the number gets heavier. Across all of 2025, roughly <strong>$3.4 billion<\/strong> in crypto was stolen worldwide, according to the blockchain-tracking firm Chainalysis. And a single actor was responsible for about 60% of\u00a0it.<\/p>\n<p>Not a gang. A\u00a0country.<\/p>\n<p><strong>Face One: The Government That Robs Banks For A\u00a0Living<\/strong><\/p>\n<h3>It\u2019s not a heist. It\u2019s a line item in a national\u00a0budget.<\/h3>\n<p>The biggest \u201ccrypto hacking gang\u201d on Earth is a wing of the North Korean state. Security researchers call the crew Lazarus Group (or, if you like spy names, TraderTraitor). But calling them a \u201ccrew\u201d undersells it. This is a government department with a job to do, and the job is: bring home hard currency.<\/p>\n<p>Here\u2019s the incentive, plainly. North Korea is cut off from the normal banking system by sanctions. It can\u2019t easily wire money, sell oil, or move dollars through the usual pipes. So it went looking for a pipe that <em>doesn\u2019t<\/em> run through banks and crypto is exactly that. Borderless. Permission-free. No manager to call and freeze the account. The same features that make blockchain exciting as financial infrastructure make it the perfect getaway car for a sanctioned regime.<\/p>\n<p>And the scale of the operation shows it\u2019s institutional, not opportunistic. By the end of 2025, North Korea\u2019s total crypto haul over the years crossed roughly <strong>$6.75 billion<\/strong>. In 2025 alone they set a record about $2 billion while doing <em>fewer<\/em> attacks. Fewer, but each one enormous. That\u2019s not a smash-and-grab mindset. That\u2019s a strategy\u00a0meeting.<\/p>\n<p>Investigators have even mapped the routine. After a big theft, the stolen funds move through a laundering cycle that runs, on average, around <strong>45 days<\/strong>, a predictable rhythm of obscuring, shuffling, and cashing out. Predictable, because it\u2019s a process someone was told to follow. It\u2019s a workflow. It has a manual. Somewhere, there is probably a spreadsheet.<\/p>\n<p><strong>When a nation-state runs the crime, you can\u2019t arrest your way out of it. You can\u2019t raid a country\u2019s budget.<\/strong><\/p>\n<p>Where does the money go? US and UN officials have said for years that these funds help pay for North Korea\u2019s nuclear weapons and missile programs. So the uncomfortable through-line is this: a badly-secured \u201cconfirm\u201d button on a crypto exchange can end up buying a component for a rocket. That\u2019s the actual supply chain. It\u2019s not thrilling. It\u2019s bureaucratic. And bureaucracy is far harder to stop than a\u00a0villain.<\/p>\n<p><strong>Face Two: The Call Is Coming From Inside The\u00a0House<\/strong><\/p>\n<h3>You imagined infiltrating them. They\u2019ve been infiltrating you.<\/h3>\n<p>This is the part that flipped my whole picture\u00a0around.<\/p>\n<p>When you think \u201chacker,\u201d you think of someone breaking <em>in<\/em> from the outside battering the firewall, cracking a password. But the fastest-growing method right now is the opposite. They don\u2019t break in. <strong>They get\u00a0hired.<\/strong><\/p>\n<p>Thousands of North Korean IT workers apply for ordinary remote developer jobs at tech and crypto companies all over the world, using fake names, borrowed identities, and AI-polished r\u00e9sum\u00e9s. In the job interview, some now use <em>real-time deepfake video<\/em> so the face on the call isn\u2019t the face doing the work. They pass the vibe check. They\u2019re often good coders. They get the offer, the laptop, the login and, eventually, the keys to move\u00a0money.<\/p>\n<p>How big is this? One North Korean group, nicknamed Famous Chollima, accounted for nearly <strong>half<\/strong> of all state-sponsored \u201chands-on-keyboard\u201d intrusions against tech companies in the year ending March 2026, per CrowdStrike\u2019s threat researchers. Blockchain analysts now believe a chunk of that record-breaking theft happened precisely because the thief was already <em>inside<\/em> a trusted employee, badge and\u00a0all.<\/p>\n<p>And it needed help from ordinary people to work. My favourite (wrong word most unsettling) detail is a woman in Arizona named Christina Chapman. She ran what prosecutors called a \u201claptop farm\u201d out of her house: rows of company laptops, each with a sticky note saying which American identity and which employer it belonged to. The North Koreans logged in remotely; the laptops sat in Arizona, so to the employer everything looked domestic. The scheme touched more than 300 US companies including Fortune 500 names, a major broadcaster, an aerospace firm and moved over $17 million to the regime. She was sentenced in 2025 to eight and a half\u00a0years.<\/p>\n<p><strong>The Line That Stuck With\u00a0Me<\/strong><\/p>\n<p>A US prosecutor summed the whole thing up better than I can. On the fake-employee schemes, she said the call is <strong>coming from inside the house<\/strong>, if it hit household-name corporations with real security teams, it can just as easily be happening at yours. The threat isn\u2019t at the gate. It filled out an onboarding form and joined the Monday\u00a0standup.<\/p>\n<p><strong>Face Three: The Scammer Texting You Might Be A\u00a0Prisoner<\/strong><\/p>\n<h3>The cruellest twist: many \u201ccriminals\u201d are victims\u00a0too<\/h3>\n<p>Now the hardest face to look\u00a0at.<\/p>\n<p>You\u2019ve gotten the message. \u201cHey Sarah, still on for lunch?\u201d except you\u2019re not Sarah and you\u2019ve never met this person. You reply \u201cwrong number,\u201d they\u2019re weirdly nice, a friendship forms over weeks, and eventually there\u2019s a \u201ccan\u2019t-miss\u201d crypto investment on a slick app that shows your money growing beautifully. Until you try to withdraw. Then it\u2019s gone. This is called <em>pig butchering<\/em>\u00a0, the target is fattened up emotionally before being financially, well, slaughtered. Ugly name. Accurate\u00a0name.<\/p>\n<p>Here\u2019s what almost nobody on the receiving end realises. The person typing those sweet messages is very often <strong>not free<\/strong>. Across Myanmar, Cambodia, and Laos, entire compounds run these scams as factories and the United Nations estimates <strong>over 200,000 people<\/strong> have been trafficked into them. They answered a fake job ad, flew somewhere for what looked like a normal office role, and instead had their passport taken, a daily scam quota set, and violence promised if they missed it or tried to\u00a0leave.<\/p>\n<p>So the \u201cgang member\u201d on the other end of your scam is sometimes a person behind a locked gate, being forced to rob you so their own captors don\u2019t hurt them. Two victims. One transaction. The money flows up and out to the organised crime networks often laundered through crypto while the two humans at either end of the chat both\u00a0lose.<\/p>\n<p>These aren\u2019t fringe amounts, either. Governments have started sanctioning these compounds directly; the scale of the fraud economy in that corner of the world is now estimated to rival a large slice of some countries\u2019 entire GDP. This is an industry. With HR problems it solves through kidnapping.<\/p>\n<p><strong>So Why Does This Whole Machine\u00a0Exist?<\/strong><\/p>\n<h3>Follow the incentives, not the\u00a0villains<\/h3>\n<p>At Naked Market we have one rule that never fails: when something crazy keeps happening, don\u2019t ask \u201cwho\u2019s the bad guy?\u201d Ask \u201cwhat does the system reward?\u201d The bad guy is a symptom. The incentive is the\u00a0disease.<\/p>\n<p>So why crypto, specifically, for all three faces? Because crypto\u2019s genuine superpowers are also, in the wrong hands, its\u00a0exploit.<\/p>\n<p><strong>A. No bank to say\u00a0no<\/strong><\/p>\n<p>Money moves without a middleman\u2019s permission. Wonderful if you\u2019re unbanked. Also wonderful if you\u2019re a sanctioned state that no bank will\u00a0touch.<\/p>\n<p><strong>B. Instant and borderless<\/strong><\/p>\n<p>Value crosses the planet in minutes. Great for a migrant sending wages home. Great, too, for whisking $1.5 billion out of reach before the coffee gets\u00a0cold.<\/p>\n<p><strong>C. Final settlement<\/strong><\/p>\n<p>Once it\u2019s sent, there\u2019s no chargeback, no fraud department to reverse it. That certainty is the whole point of the technology. It\u2019s also why victims almost never get their money\u00a0back.<\/p>\n<p>None of that makes crypto \u201cbad.\u201d Cash funded crime for centuries and we didn\u2019t ban paper. But it does mean the honest builders and the state-run thieves are riding the exact same rails and pretending otherwise is how you get robbed. We dug into this same tension in <a href=\"https:\/\/chetandugar.substack.com\/p\/crypto-was-supposed-to-escape-the\">Crypto Was Supposed to Escape the System<\/a>, if you want the longer\u00a0version.<\/p>\n<p><strong>The Plot Twist That Should Give You\u00a0Hope<\/strong><\/p>\n<h3>The reason we know all of this? The blockchain snitched.<\/h3>\n<p>Quick gut-check question. If these thieves are so sophisticated, how do we know the exact dollar amounts, the 45-day laundering cycle, the wallet trails, down to the transaction?<\/p>\n<p>Because the blockchain wrote it all down. Every move those stolen coins make is recorded on a public ledger that anyone can read forever. Firms like Chainalysis and TRM Labs don\u2019t need to hack anyone back they just <em>read the receipts<\/em>. Within minutes of the Bybit theft, analysts had already tagged the thief\u2019s addresses and started watching the money squirm in real\u00a0time.<\/p>\n<p>Sit with the irony. Criminals chose crypto because it dodges the banking system\u2019s watchers. But in dodging the banks, they stepped onto the most transparent financial rails ever built. The getaway car has a permanent, public GPS tracker bolted to the roof. It\u2019s the same reason <a href=\"https:\/\/chetandugar.substack.com\/p\/why-bribery-cant-hide-on-a-blockchain\">bribery can\u2019t really hide on a blockchain<\/a>, the ledger doesn\u2019t forget, and it doesn\u2019t take\u00a0sides.<\/p>\n<p><strong>Where This Goes\u00a0Next<\/strong><\/p>\n<h3>The next target isn\u2019t your wallet. It\u2019s your\u00a0AI.<\/h3>\n<p>Here\u2019s what I\u2019m watching, and what I think most people haven\u2019t clocked\u00a0yet.<\/p>\n<p>As more of finance gets handed to AI agents, little software workers that hold funds, sign transactions, and act on your behalf, the attackers are already turning toward them. Why phish a careful human when you can trick a fast, tireless bot into approving a transfer? The deepfake r\u00e9sum\u00e9s and the fake job interviews are just the current chapter. The next one is agents scamming agents, at machine speed, around the\u00a0clock.<\/p>\n<p>Which means the defender\u2019s job quietly changes shape. It stops being \u201cspot the shady link\u201d and becomes \u201cverify who and what you\u2019re really trusting\u201d every employee, every counterparty, every automated helper. That\u2019s a systems problem, and systems problems reward people who think in systems. (We poked at whether AI can be trusted to guard the gate in <a href=\"https:\/\/chetandugar.substack.com\/p\/can-you-trust-ai-to-catch-fraud\">Can You Trust AI to Catch\u00a0Fraud?<\/a>)<\/p>\n<p><strong><em>The scam of the future won\u2019t ask you to click. It\u2019ll ask your assistant to and your assistant is faster, more trusting, and never sleeps.<\/em>The shift Naked Market is\u00a0watching<\/strong><\/p>\n<p><strong>The Mental Model To Take With\u00a0You<\/strong><\/p>\n<h3>There is no gang. There\u2019s a state, a structure, and a supply\u00a0chain.<\/h3>\n<p>If you remember one thing from today, make it this lens. Next time a headline says \u201ccrypto hacking gang,\u201d quietly ask which of these three you\u2019re actually looking at because the right response is completely different for\u00a0each:<\/p>\n<p><strong>The State<\/strong><\/p>\n<p>A government treating theft as revenue. You can\u2019t police this; it\u2019s diplomacy, sanctions, and hardening the targets. There\u2019s no door to kick\u00a0in.<\/p>\n<p><strong>2. The Structure<\/strong><\/p>\n<p>The threat that got <em>hired<\/em>. The fix isn\u2019t a bigger firewall, it\u2019s verifying identity, inside the building, on your own team. Trust is now the attack\u00a0surface.<\/p>\n<p><strong>3. The Supply\u00a0Chain<\/strong><\/p>\n<p>Fraud produced by trafficked, coerced labour. The \u201ccriminal\u201d may be a captive. Solving it is a human-rights problem wearing a cybercrime mask.<\/p>\n<p>The word \u201cgang\u201d flattens all three into one cartoon so your brain can file it under \u201cnot my problem, that\u2019s for the FBI.\u201d Drop the cartoon and you see the real machine\u200a\u2014\u200aa machine that grows precisely because it\u2019s structural, not personal. You can\u2019t behead a payroll. You can\u2019t arrest a labour market. You can\u2019t raid a country\u2019s budget\u00a0line.<\/p>\n<p>But you <em>can<\/em> stop expecting a villain and start reading the system. That\u2019s the whole game. It always\u00a0was.<\/p>\n<p><em>I went looking for a gang and found a mirror instead one pointed at how modern crime really organises itself. Which, weirdly, made me feel more prepared than any spy story could\u00a0have.<\/em><\/p>\n<p>&#8211; Chetan<\/p>\n<p>If you want to understand where money is heading before it becomes obvious, this is the room for\u00a0it.<a href=\"https:\/\/chetandugar.substack.com\/\"><strong><em>Subscribe to Naked\u00a0Market<\/em><\/strong><\/a><\/p>\n<p><strong>Keep Pulling The\u00a0Thread<\/strong><\/p>\n<p><a href=\"https:\/\/chetandugar.substack.com\/p\/one-planet-180-currencies-somethings\"><strong>Start here \u2192 One Planet, 180 Currencies, Something\u2019s Off<\/strong><\/a>\u200a\u2014\u200athe welcome post, and the whole reason Naked Market\u00a0exists.<a href=\"https:\/\/chetandugar.substack.com\/p\/crypto-was-supposed-to-escape-the\"><strong>Crypto Was Supposed to Escape the System<\/strong><\/a>\u200a\u2014\u200awhy the same rails that free people also arm\u00a0regimes.<a href=\"https:\/\/chetandugar.substack.com\/p\/why-bribery-cant-hide-on-a-blockchain\"><strong>Why Bribery Can\u2019t Hide on a Blockchain<\/strong><\/a>\u200a\u2014\u200athe transparency twist, in\u00a0full.<a href=\"https:\/\/chetandugar.substack.com\/p\/can-you-trust-ai-to-catch-fraud\"><strong>Can You Trust AI to Catch Fraud?<\/strong><\/a>\u200a\u2014\u200athe next battlefield: agents vs.\u00a0agents.<\/p>\n<p>-More Soon<\/p>\n<p><a href=\"https:\/\/medium.com\/coinmonks\/i-went-looking-for-the-crypto-hacking-gang-this-is-what-i-found-0b33f3c891e2\">I Went Looking for the Crypto Hacking Gang. This is What I Found<\/a> was originally published in <a href=\"https:\/\/medium.com\/coinmonks\">Coinmonks<\/a> on Medium, where people are continuing the conversation by highlighting and responding to this story.<\/p>","protected":false},"excerpt":{"rendered":"<p>I thought I knew what I was looking for. I was\u00a0wrong. Let me get the disappointing part out of the way first, because I don\u2019t want you thinking I\u2019m about to hand you a spy\u00a0movie. I did not sneak into a hacker den. I didn\u2019t put on a fake accent, join an encrypted chat, and [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":212615,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-212614","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-interesting"],"_links":{"self":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts\/212614"}],"collection":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=212614"}],"version-history":[{"count":0,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts\/212614\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/media\/212615"}],"wp:attachment":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=212614"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=212614"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=212614"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}