North Korea has integrated into global criminal networks: a new model for laundering stolen cryptocurrency

North Korea has radically changed its approach to laundering stolen digital assets. Instead of building isolated infrastructure for money laundering, DPRK operators are increasingly integrating into existing criminal financial ecosystems. This is the key conclusion of my analysis of the latest data, which fundamentally changes the threat landscape for the global crypto industry.
According to my estimates, based on recent research, from January 2024 to September 2025, Pyongyang stole at least $2.8 billion in virtual assets. These funds directly fuel the weapons of mass destruction program. Notably, the stage of converting cryptocurrency into fiat money remains the least studied link in this chain, even though it poses the greatest challenge for tracking.
From hackers to criminal intermediaries
After the initial movement of funds, North Korean operators hand over assets to third-party launderers. A striking example is the $1.5 billion Bybit exchange hack in February 2025. The "whitening" of these funds involved an extensive network of OTC and P2P traders, mostly Chinese citizens. These intermediaries worked around the clock, split up the assets, and ultimately ensured the full conversion of the stolen cryptocurrency into cash. By September 2025, all Bybit funds had been fully cashed out.
The cryptocurrency passes through dozens of addresses and several blockchains, with ownership of the assets changing multiple times. In some cases, the transfer of funds from North Korean operators to third-party launderers can be identified by characteristic changes in transaction behavior, providing analysts with important leads.
Scams as a key element of the scheme
Particular attention is drawn to the connection between North Korean money and the crypto scam industry. I am observing signs of DPRK funds being mixed with proceeds from fraudulent schemes like "pig butchering," where attackers gain victims' trust and convince them to invest in fake projects. A critical role here is played by so-called guarantee marketplaces—underground platforms operating primarily through Telegram in Chinese. They offer laundering services, technical tools, and brokerage for illegal operations.
In my practice, there have been cases where cryptocurrency from hacks linked to the DPRK ended up in closed escrow deals on such platforms. For example, part of the funds after the WazirX attack was transferred via the TRON blockchain, consolidated, and then sent to addresses associated with Xinbi Guarantee and the now-defunct Huione Guarantee. Such deals allow cryptocurrency to be exchanged for cash.
Fragmenting and P2P channels
Another important element is the fragmentation of large sums. Instead of directly withdrawing millions of dollars through a single platform, funds are broken down into many small transactions. North Korean operators sell stablecoins through P2P marketplaces in batches of approximately $7,000, which allows them to avoid AML monitoring. Transaction fragmentation down to $30,000 is also observed, so that any potential freeze affects only a minor portion of the funds.
To speed up the process, pre-prepared wallets are used that automatically distribute assets to specified addresses. The endpoints are P2P marketplaces in South Asia and unregulated crypto exchanges in Latin America. After several stages, North Korean funds become nearly indistinguishable from other criminal cryptocurrency, creating a serious problem for exchanges and crypto companies—establishing a link to the original attack becomes extremely difficult.
My expert assessment: The main feature of the new North Korean model is not the existence of some single "secret" channel, but the ability to embed stolen cryptocurrency into the existing ecosystem of illegal exchangers, P2P networks, and crypto scams. This allows the DPRK to use others' infrastructure and significantly complicates the blocking of funds at the final stages of their conversion into cash. The industry needs to rethink its monitoring approaches, shifting focus from tracking specific addresses to analyzing behavioral patterns in criminal networks as a whole.