South Korean cybersecurity firm Genians found that North Korea-linked hacking group Kimsuky has built local AI systems, including Ollama, GPT4All and Msty, to analyze stolen data and generate phishing documents without relying on external AI providers, Reuters reported Aug. 10, 2026.
North Korea-linked actors were responsible for approximately $643 million, or 66% of all cryptocurrency stolen through hacks and exploits during the first half of 2026, according to blockchain intelligence firm TRM Labs. Overall losses reached $972 million across 207 incidents, even as the total amount stolen fell sharply from the $2.3 billion recorded during the first six months of 2025.
The figures expose an important shift in the market: attacks are becoming more frequent, but the largest losses remain concentrated in a small number of highly sophisticated operations. TRM Labs recorded more than twice as many incidents in the first half of 2026 as in the same period last year, when it recorded 83 attacks.
Kimsuky pushes AI beyond phishing
The latest development involves Kimsuky, a North Korea-linked cyber-espionage group that has historically relied heavily on targeted phishing and social engineering. South Korean cybersecurity company Genians says the group has been experimenting with locally operated artificial-intelligence systems, including Ollama, GPT4All and Msty, alongside retrieval-augmented generation technology.
Reuters reported Monday that Genians discovered evidence of AI-agent frameworks, speech-to-text software and Cursor, an AI-assisted coding platform, on infrastructure associated with the campaign. Researchers also identified financial and cryptocurrency-themed documents apparently generated with AI and designed to resemble legitimate business or investment materials. The findings have not been independently verified.
The significance is broader than simply producing more convincing phishing emails. Running AI models locally could allow attackers to process sensitive material without sending information to an external AI provider, potentially giving operators greater control over stolen data.
Genians Security Center chief Moon Jong-hyun said the findings point to a deeper integration of AI into North Korean cyber operations.
“This analysis shows that a nation-backed hacking group is advancing its attack capabilities by building local LLMs and AI development environments to integrate AI into actual attack frameworks.”
The development represents a potential evolution from using generative AI as a productivity tool toward embedding AI capabilities across multiple stages of an attack.
Crypto theft remains a major North Korean revenue stream
The crypto hack problem is particularly significant because North Korea has repeatedly been accused by governments and cybersecurity firms of using cryptocurrency theft to generate revenue for the regime.
CertiK estimated that DPRK-linked hackers stole approximately $2.06 billion in digital assets during 2025, representing about 60% of the $3.4 billion in total cryptocurrency losses recorded that year. Its broader analysis estimates that North Korean actors stole approximately $6.75 billion across 263 incidents between 2016 and early 2026.
The most dramatic example came in February 2025, when Bybit suffered a theft of roughly $1.5 billion. Bybit said one Ethereum cold wallet was compromised, while subsequent investigations linked the incident to the North Korea-associated Lazarus Group.
That attack demonstrated why the industry cannot focus exclusively on smart-contract vulnerabilities. Human beings, signing infrastructure, credentials and operational systems remain critical targets.
TRM Labs found that infrastructure and operational compromises accounted for only about 15% of incidents in the first half of 2026 but generated approximately 76% of the money stolen. Smart-contract exploits, meanwhile, represented 125 of the 207 recorded incidents but accounted for a much smaller proportion of total losses.
More attacks, fewer dollars, but the threat is growing
The crypto hack statistics for 2026 reveal a striking contradiction. Attackers are launching more operations, yet the total value stolen is substantially lower than last year.
TRM Labs said two North Korea-linked attacks in April accounted for roughly $577 million of the first-half losses. The Drift Protocol incident generated approximately $285 million in losses, while the KelpDAO attack accounted for about $292 million. Together, those attacks represented the overwhelming majority of the $643 million attributed to North Korea-linked activity during the period.
That concentration means a single successful operation against a major crypto platform can dramatically alter the industry’s annual loss figures.
The crypto hack threat is also becoming more technically diverse. TRM Labs found that attackers increasingly combined multiple weaknesses in smart contracts rather than relying on a single coding error. At the same time, North Korean operations continue to exploit the human layer through social engineering and infrastructure compromise.
For crypto companies, the implication is clear: defending code alone is no longer enough.
Security teams must also strengthen employee awareness, identity verification, access controls, withdrawal safeguards, private-key protection and remote-worker security. CertiK has warned that AI could further enhance social-engineering campaigns while increasing attempts to target technology workers and facilitate new laundering techniques.
The crypto hack economy is therefore entering a new phase in which artificial intelligence may not necessarily create entirely new attack methods, but could make existing ones faster, cheaper and more convincing.
For an industry already struggling with billion-dollar thefts, that could prove to be the more consequential development.
The crypto hack numbers may show fewer dollars stolen than in 2025, but the emergence of AI-assisted North Korean operations suggests the underlying threat is becoming more adaptive. And as attackers gain better tools for persuasion, coding and intelligence processing, crypto firms face a security race in which human behavior could remain the weakest link.