North Korea is integrating into criminal crypto networks: a new era of money laundering

Analysis of recent trends shows that North Korea is radically changing its approach to laundering stolen digital assets. Instead of building isolated infrastructure, North Korean operators are increasingly integrating into existing criminal financial ecosystems. This is a strategic shift that dramatically complicates the work of law enforcement agencies and blockchain analysts.
Money movement routes now span OTC services, P2P traders, illegal exchangers, mixers, cross-chain bridges, and platforms linked to the scam industry. Based on monitoring data, my estimates indicate that from January 2024 to September 2025, Pyongyang stole at least $2.8 billion in virtual assets. These funds directly fuel the weapons of mass destruction program. It is critical to understand: the stage of conversion into fiat money is far less studied than on-chain laundering, and this is where the main risks lie.
From hackers to criminal intermediaries
After the initial movement of funds, North Korea transfers cryptocurrency to third-party launderers. A telling example is the $1.5 billion Bybit hack in February 2025. The "whitening" process involved an entire network of OTC and P2P traders, mostly Chinese citizens. These intermediaries worked around the clock, moving assets and ultimately converting all stolen funds into fiat and cash. According to the international monitoring group MSMT, by September 2025, all Bybit funds had been cashed out.
At the same time, assets pass through dozens of addresses and several blockchains, with ownership constantly changing. In some cases, the transition from North Korean operators to third-party launderers can be tracked by characteristic changes in transaction behavior, but this requires enormous resources.
The scam industry as a key element
Particular attention is drawn to the connection between North Korean money and crypto scams. Investigators have recorded signs of mixing North Korean funds with proceeds from "pig butchering" fraud—investment schemes where victims are first drawn into trusting relationships and then persuaded to invest in fictitious projects.
A key role is played by so-called guarantee marketplaces—underground platforms that primarily operate via Telegram in Chinese. They offer money laundering services, technical tools, and intermediation. Elliptic has found cases where cryptocurrency from North Korea-related hacks ended up in closed escrow deals on such platforms. For example, part of the funds after the WazirX attack was transferred via TRON, consolidated, and sent to addresses linked to Xinbi Guarantee and the now-defunct Huione Guarantee. Such deals allow cryptocurrency to be exchanged for cash.
Fragmenting and P2P: tactics for evading AML
Another important element is the fragmentation of large sums. Instead of directly withdrawing millions of dollars, funds are split into many small transactions. North Korean operators sell stablecoins through P2P marketplaces in batches of approximately $7,000, receiving cash. Such amounts allow them to avoid AML monitoring. ZeroShadow has also recorded the fragmentation of transactions to approximately $30,000 so that any potential freeze would only affect a small portion of the funds.
To speed up the process, pre-prepared wallets with automatic asset distribution are used. The endpoints are P2P marketplaces in South Asia and unregulated crypto exchanges in Latin America.
As a result, after several stages, North Korean funds become almost indistinguishable from other criminal cryptocurrency. This creates an additional problem for exchanges: once funds enter the broad network of criminal intermediaries, the connection to the original attack becomes significantly harder to establish.
The main feature of the North Korean model is not the existence of some single "secret" channel, but the ability to embed stolen cryptocurrency into the existing ecosystem of illegal exchangers, P2P networks, and scams. This allows North Korea to use others' infrastructure and significantly complicates the blocking of funds at the final stages.
My comment: This trend confirms the industrialization of North Korean crypto thefts. We are witnessing not just hacker attacks, but a full-fledged state operation with its own logistics and integration into global criminal networks. For the industry, this means that simple on-chain monitoring is no longer sufficient—comprehensive solutions are needed that can track behavioral patterns and connections between seemingly unrelated addresses.