Crypto news

11.08.2026
17:28

The DPRK has integrated stolen cryptocurrency into global scam networks: a new level of money laundering

северокорейские хакеры North Korean hackers

Analysis of recent data shows that North Korea has radically changed its approach to laundering stolen digital assets. Instead of creating isolated infrastructure, Pyongyang is actively integrating its money flows into existing criminal financial ecosystems. This is not just an evolution of tactics, but a shift to a fundamentally new model that makes tracking funds significantly more difficult.

This involves the comprehensive use of OTC services, P2P traders, illegal exchangers, mixers, cross-chain bridges, and platforms linked to fraudulent schemes. Between January 2024 and September 2025, North Korea stole at least $2.8 billion in virtual assets. These funds directly fuel the weapons of mass destruction program, making the problem particularly acute.

Criminal intermediaries as a key link

The key point is the transfer of assets to third-party launderers. An analysis of the $1.5 billion Bybit hack in February 2025 showed that a sprawling network of OTC and P2P traders, mostly Chinese citizens, was involved in the process. These intermediaries worked around the clock, split amounts, and ultimately fully converted the stolen funds into fiat and cash. By September 2025, all Bybit funds had been cashed out. At the same time, assets pass through dozens of addresses and several blockchains, with ownership changing multiple times. Characteristic changes in transaction behavior make it possible to identify the moment funds are transferred from North Korean operators.

The scam industry as a refuge

Particular attention is drawn to the connection between North Korean money and crypto scams. My colleagues have recorded the mixing of North Korean funds with proceeds from "pig butchering" scams. So-called guarantee marketplaces—underground Telegram platforms in Chinese—play an important role. They provide laundering services, technical tools, and intermediation. Part of the funds after the WazirX attack was transferred via TRON, consolidated, and sent to addresses linked to Xinbi Guarantee and the now-defunct Huione Guarantee.

Fractioning and P2P networks

The scheme involves splitting large sums. Instead of withdrawing millions through a single platform, stablecoins are sold through P2P marketplaces in batches of approximately $7,000, which helps avoid AML monitoring. Transactions are also split into amounts of up to $30,000 so that a freeze affects only a small portion of the funds. Pre-prepared wallets are used for automatic asset distribution. The endpoints are P2P platforms in South Asia and unregulated exchanges in Latin America.

As a result, North Korean funds become indistinguishable from other criminal cryptocurrency. This creates a colossal problem for exchanges: once funds enter a broad network of intermediaries, it is almost impossible to establish a link to the original attack. The main feature of the model is not the existence of a "secret" channel, but the ability to embed stolen assets into an already functioning ecosystem of illegal exchangers and scams.

My analysis: This trend is an alarming signal for the entire industry. North Korea has effectively turned cryptocurrency into a tool of state policy, using others' criminal networks as a service. Exchanges and regulators will have to rethink their approaches to AML monitoring, focusing not on tracking specific addresses, but on analyzing behavioral patterns and network connections.