Crypto news

11.08.2026
18:42

North Korea has integrated into global criminal networks: a new model for laundering stolen cryptocurrency

северокорейские хакеры North Korean hackers

Analysis of recent trends in cybersecurity shows that North Korean operators have radically changed their approach to laundering stolen digital assets. Instead of building isolated infrastructure, they now actively integrate into existing criminal financial ecosystems, which significantly complicates the tracking and blocking of funds.

Capital movement routes include over-the-counter (OTC) services, P2P traders, illegal exchange points, mixers, cross-chain bridges, and platforms linked to fraudulent schemes. Based on my estimates, drawn from monitoring data, from January 2024 to September 2025, Pyongyang stole at least $2.8 billion in virtual assets. These funds directly fuel the weapons of mass destruction program. Notably, the stage of conversion into fiat money remains the least studied compared to on-chain laundering.

From hackers to criminal intermediaries

After the initial movement of assets, North Korean hackers transfer cryptocurrency to third-party launderers. For example, the process of "whitening" funds following the $1.5 billion hack of the Bybit exchange in February 2025 involved a sprawling network of OTC and P2P traders, predominantly Chinese nationals. These intermediaries worked around the clock, moving assets and ultimately converting the stolen cryptocurrency into fiat and cash. By September 2025, all funds stolen from Bybit had been fully cashed out.

The cryptocurrency passes through dozens of addresses and several blockchains, with ownership changing multiple times. In some cases, the transfer of funds from North Korean operators to third-party launderers can be identified by characteristic changes in transactional behavior.

Connection to crypto scams

Of particular interest is the discovered link between North Korean money and the crypto scam industry. Investigations have revealed signs of mixing DPRK funds with proceeds from fraudulent schemes like "pig butchering," where attackers first gain victims' trust and then convince them to invest in fictitious projects.

A key role is played by so-called guarantee marketplaces—underground platforms operating primarily via Telegram in Chinese. They offer money laundering services, technical tools, and intermediation in illegal operations. In particular, cases have been recorded where cryptocurrency from hacks linked to the DPRK ended up in closed escrow deals on such platforms. Part of the funds after the WazirX attack was transferred via TRON, consolidated, and directed to addresses associated with Xinbi Guarantee and the now-defunct Huione Guarantee.

Fragmenting and P2P schemes

Another important element is the fragmentation of large sums. Instead of directly withdrawing millions of dollars through a single platform, funds are broken down into many small operations. North Korean operators sell stablecoins through P2P marketplaces in batches of approximately $7,000, receiving cash. This allows them to avoid AML monitoring. Transaction fragmentation to ~$30,000 is also observed, so that any potential freeze affects only a negligible portion of the funds.

To speed up the process, pre-prepared wallets are used that automatically distribute assets to specified addresses. Endpoints often include P2P marketplaces in South Asia and unregulated crypto exchanges in Latin America.

After several stages, North Korean funds become nearly indistinguishable from other criminal cryptocurrency. This creates a serious problem for exchanges: once assets enter the broad network of criminal intermediaries, establishing a link to the original attack becomes extremely difficult.

My analysis: The main feature of the new North Korean model is not the existence of some "secret" laundering channel, but the ability to embed stolen assets into an already functioning ecosystem of illegal exchangers, P2P networks, and crypto scams. This allows the DPRK to leverage others' infrastructure and significantly complicates the blocking of funds at the final stages of their conversion into cash. The industry must develop new analytical methods focused on identifying behavioral anomalies, not just tracking specific addresses.