North Korea has embedded stolen crypto assets into global scam networks: a new era of money laundering

Analysis of recent trends shows that North Korean operators have radically changed their approach to laundering stolen digital assets. Instead of building isolated infrastructure, they now actively integrate into existing criminal financial ecosystems, making fund tracking many times more complex.
Key capital movement routes include over-the-counter (OTC) services, P2P traders, illegal exchangers, mixers, cross-chain bridges, and platforms linked to fraudulent schemes. Based on my estimates, drawn from a body of data over the past two years, from January 2024 to September 2025, North Korea stole at least $2.8 billion in virtual assets. These funds directly fuel the weapons of mass destruction program, and the stage of conversion into fiat money remains the least understood link in this chain.
From hackers to criminal intermediaries
After the initial movement of funds, North Koreans hand over the cryptocurrency to third-party launderers. A telling example is the $1.5 billion hack of the Bybit exchange in February 2025. The "whitening" process involved a sprawling network of OTC and P2P traders, mostly Chinese citizens, who moved assets around the clock. By September 2025, all stolen funds had been fully cashed out, confirming the effectiveness of this model.
The cryptocurrency passes through dozens of addresses and several blockchains, with ownership changing multiple times. In some cases, the transfer of funds from North Korean operators to third-party intermediaries can be identified by characteristic changes in transaction behavior.
The scam industry as a haven
Particular attention is drawn to the connection between North Korean money and the crypto scam industry. Investigators are recording the mixing of North Korean funds with proceeds from "pig butchering" fraud — investment schemes where victims are first drawn into trusting relationships and then persuaded to invest in fictitious projects. A critical role is played by so-called guarantee marketplaces — underground Telegram platforms in Chinese offering laundering services, technical tools, and intermediation.
There are known cases where cryptocurrency from hacks linked to North Korea ended up in closed escrow deals. For example, part of the funds after the WazirX attack was transferred via TRON, consolidated, and sent to addresses associated with Xinbi Guarantee and the now-defunct Huione Guarantee. Such deals allow cryptocurrency to be exchanged for cash with virtually no trace.
Fractioning and P2P mechanisms
Another element of the scheme is the fractioning of large sums. Instead of directly withdrawing millions of dollars, funds are split into many small operations. North Korean operators sell stablecoins through P2P marketplaces in batches of roughly $7,000, receiving cash and avoiding AML monitoring. Transactions are also split into chunks of up to ~$30,000 so that any potential freeze affects only a minor portion of the funds. To speed up the process, pre-prepared wallets with automatic asset distribution are used. The endpoints are P2P marketplaces in South Asia and unregulated exchanges in Latin America.
After several stages, North Korean funds become virtually indistinguishable from other criminal cryptocurrency. This creates a colossal problem for exchanges: establishing a link to the original attack becomes extremely difficult.
My conclusion: The key feature of the North Korean model is not the existence of a single "secret" channel, but the ability to embed stolen assets into an already functioning ecosystem of illegal exchangers and scams. This allows North Korea to use others' infrastructure, significantly complicating the blocking of funds at the final stages. The industry needs to rethink its monitoring approaches, shifting focus from tracking specific addresses to analyzing behavioral patterns in global criminal networks.