Crypto news

11.08.2026
17:48

North Korea has embedded stolen cryptocurrency into global scam networks: a new level of laundering

северокорейские хакеры North Korean hackers

An analysis of recent trends in the movement of stolen digital assets shows that North Korean operators have radically changed their strategy. Instead of building isolated infrastructure for money laundering, they are increasingly integrating into existing criminal financial ecosystems. This is not just evolution—it is a qualitative leap in the complexity and resilience of their operations.

According to my data, from January 2024 to September 2025, North Korea stole at least $2.8 billion in virtual assets. These funds directly fuel the weapons program, and the key challenge for the industry is not so much the hack itself, but the final conversion into fiat currency. It is this stage, unlike on-chain tracking, that remains the least studied.

Criminal intermediaries as a new tool

The routes of fund movement include OTC services, P2P traders, illegal exchanges, mixers, and cross-chain bridges. Of particular interest is the use of so-called guarantee marketplaces—underground Telegram platforms in Chinese that offer escrow services and technical support for laundering. For example, after the $1.5 billion Bybit hack in February 2025, an entire network of OTC and P2P traders was involved in the process, many of whom were Chinese citizens. By September 2025, all stolen funds had been fully cashed out.

Scams as cover

A worrying trend is emerging of mixing North Korean funds with proceeds from fraud schemes like "pig butchering." Part of the assets after the WazirX attack was transferred via TRON to addresses linked to Xinbi Guarantee and Huione Guarantee. This allows not only hiding the origin of the funds but also exchanging them for cash without direct contact with the traditional banking system.

Fragmenting and automation

A key element of the scheme is transaction fragmentation. Operators sell stablecoins through P2P platforms in batches of approximately $7,000, which avoids AML monitoring. In some cases, amounts are fragmented down to $30,000 so that a freeze affects only a minimal portion of the funds. To speed up the process, pre-prepared wallets with automatic distribution of assets to endpoints are used—P2P marketplaces in South Asia and unregulated exchanges in Latin America.

As a result, after several stages, North Korean funds become almost indistinguishable from other criminal cryptocurrency. This creates a colossal problem for exchanges: the link to the original attack becomes nearly impossible to establish.

My conclusion: the main threat is not the existence of a "secret" channel, but North Korea's ability to parasitize on others' infrastructure. This requires the industry to rethink its monitoring approaches: fighting individual addresses is useless; a comprehensive analysis of behavioral patterns and interactions with criminal networks is needed. Hacker groups have already turned cryptocurrency theft into a large-scale state operation, and the industry must respond accordingly.