U.S. DOJ Seizes $15M in USDT Linked to North Korean Cyber Operations

U.S. DOJ Seizes $15M in USDT Linked to North Korean Cyber Operations

The DOJ moves to return seized USDT stolen by North Korea’s APT38, as laundering through mixers and OTC desks underscores ongoing cybercrime threats.

USDT

Fact Check
The assessment is 'likely_true' with high confidence due to overwhelming and consistent evidence from multiple authoritative sources. The most critical piece of evidence is the official press release from the U.S. Department of Justice itself, which serves as the primary source for the event. This document directly confirms the seizure of over $15 million in the cryptocurrency USDT and explicitly links these funds to cyber operations conducted by North Korean state-sponsored actors (APT38).This primary account is strongly corroborated by multiple secondary sources. A news article from CoinDesk, a major cryptocurrency publication, a blog post from the crypto security company OneSafe, and a news-style article from the Phemex exchange all report on the same event, confirming the amount, the asset, and the connection to North Korea. Further, another article from CoinDesk, while focused on a different topic, mentions the seizure in passing, reinforcing that the event is a known fact in the industry.There is no conflicting evidence among the provided sources. Sources that do not confirm the statement are either too general in scope (Wikipedia), irrelevant to this specific seizure (the TechCrunch social media post), or of very low authority. The direct confirmation from the government entity responsible for the action, supported by consistent reporting from reputable news and industry sources, makes the statement highly credible.
Summary

The U.S. Department of Justice filed two civil forfeiture complaints on Nov. 16 to recover $15.1 million in USDT stolen in 2023 by North Korean hacking group APT38 from four overseas cryptocurrency platforms. The FBI seized the funds in March 2025, and the DOJ intends to return them to the victims. Authorities say APT38 continues its laundering operations using blockchain bridges, mixers, and over-the-counter trading desks.

Terms & Concepts
  • USDT (Tether): A stablecoin pegged to the U.S. dollar, widely used in cryptocurrency transactions to maintain price stability.
  • Advanced Persistent Threat 38 (APT38): A North Korean hacking group linked to the country’s military, involved in large-scale cryptocurrency thefts.
  • Blockchain Bridge: A protocol that enables transfer of tokens or data between different blockchain networks.