Institutions Are Moving Into Crypto — So Are the Hackers Trying to Break It

Two things are happening in crypto at the same time this month, and they’re pulling in opposite directions. On one side, traditional finance is quietly building the regulated infrastructure to bring trillion-dollar asset classes on-chain.

On the other, state-sponsored hackers are getting more sophisticated at exploiting exactly that growing institutional footprint. Neither story gets much attention on its own — but together, they explain where the industry actually is right now.

Regulators are finally building rails for Real-World gold

For years, tokenized gold has been a niche product — a handful of stablecoin-adjacent tokens like PAXG and XAUT, mostly used by crypto-native traders rather than institutions. That’s starting to change.

The UK’s Financial Conduct Authority is now holding talks with banks and market participants about formal regulatory standards for tokenized gold, specifically exploring how it could function as collateral in wholesale financial markets.

This isn’t happening in a vacuum. It’s an extension of a broader FCA and Bank of England push to build a regulatory framework around tokenization more generally — one that previously covered tokenized securities and settlement instruments, and that a government-linked task force estimates could add £33 billion a year to the UK economy by 2035.

The gold angle matters specifically because London handles roughly 70% of global notional gold trading volume — if any market has the scale to make tokenized gold a genuinely institutional product rather than a crypto curiosity, it’s this one.

The full breakdown of what the FCA is actually proposing, and how it fits into the UK’s wider tokenization roadmap, is worth reading in CryptoPulse’s coverage of the FCA’s tokenized gold framework.

While the Front Door Opens, State Hackers Are Working the Back Door

Here’s the uncomfortable part: the same institutional money flowing into crypto is exactly what’s attracting increasingly sophisticated attackers — and North Korea remains the most persistent threat actor in the space by a wide margin.

South Korean cybersecurity firm Genians Security Center recently found that Kimsuky (also tracked as APT43, Thallium, and Velvet Chollima), a hacking group linked to North Korea, has started embedding generative AI directly into its attack infrastructure.

Researchers discovered local AI tools — Ollama, GPT4All with retrieval-augmented generation, Microsoft’s Semantic Kernel framework — running on Kimsuky’s own servers, used to generate convincing phishing documents themed around crypto assets, investment strategies, and fintech services.

One decoy file was literally named after Pump.fun, the Solana meme-coin launchpad. The payload delivery chain is equally modern: malicious LNK files trigger PowerShell scripts that pull an encrypted AsyncRAT trojan via the GitHub Raw Content API, disguised as ordinary image files.

Using local rather than cloud-based AI models lets the attackers process stolen documents without ever sending sensitive data to an outside service — a level of operational sophistication that would have been unusual for a state-linked group even a year or two ago.

The full technical breakdown is in CryptoPulse’s report on Kimsuky’s AI-powered phishing campaign.

The Bill Is Coming Due – Slowly

The clearest illustration of how hard this problem is to actually solve is Bybit’s ongoing legal fight over its February 2025 hack, in which North Korea-linked Lazarus Group drained roughly $1.5 billion from the exchange’s cold wallet — one of the largest crypto thefts in history.

Bybit has now filed a civil RICO lawsuit in the US District Court for the District of Columbia, naming North Korea itself, its Reconnaissance General Bureau intelligence agency, and Lazarus Group as defendants, alongside unidentified wallet holders where traceable stolen funds ended up.

The court granted a temporary restraining order in June and partially granted a preliminary injunction freezing traceable assets across more than 28 exchanges and custodians in July.

Bybit CEO Ben Zhou summed up the effort simply: “Our focus has never changed: protect our users first, recover what we can, and make sure the people behind these attacks are held accountable.”

The numbers, though, put the scale of the problem in perspective: Bybit has recovered $48.4 million and frozen another $30.5 million — roughly 5.3% of the total stolen.

The exchange itself estimates that around 90% of the funds are now untraceable, laundered through mixers, cross-chain bridges, and unregulated OTC platforms faster than investigators can follow them.

It’s a legal win, and a real one — but it’s also a sobering reminder of how far behind law enforcement still runs relative to state-sponsored crypto theft.

The full story is covered in CryptoPulse’s piece on Bybit’s lawsuit against North Korea.

Two Speeds, One Industry

What ties these three stories together isn’t a single event — it’s a pattern. Regulators are moving, cautiously but genuinely, toward building the kind of institutional-grade infrastructure that could bring trillions in real-world assets on-chain.

At the same time, the attackers targeting that same infrastructure are professionalizing just as fast, folding in AI tooling and running operations with the discipline of a state intelligence service, because in Kimsuky’s case, that’s exactly what it is.

Crypto isn’t maturing in a straight line — it’s maturing on both fronts simultaneously, and the gap between the two is where most of the real risk currently sits.

Daily, fact-checked coverage of stories like these — sourced, verified, and free of invented numbers — runs on CryptoPulse.media.

cryptopulse.media

Artikel terkait lainnya