The DPRK has integrated stolen cryptocurrency into global scam networks: a new era of money laundering

An analysis of recent trends in cybercrime reveals a troubling evolution in North Korea's strategy for laundering illegally obtained digital assets. Instead of isolated channels, Pyongyang is increasingly embedding its financial flows into existing criminal ecosystems, which drastically complicates their tracking.
My research shows that fund movement routes now include over-the-counter (OTC) platforms, P2P traders, illegal exchange offices, mixers, cross-chain bridges, and even platforms linked to fraudulent schemes. Between January 2024 and September 2025, the total volume of virtual assets stolen by the DPRK reached at least $2.8 billion. These funds directly fuel the weapons of mass destruction program. Notably, the fiat conversion stage remains the least studied compared to on-chain laundering.
Criminal intermediaries as a key link
After the initial movement of assets, North Korean operators hand them off to third-party launderers. In particular, the process of "cleaning" funds stolen from the Bybit exchange in February 2025 (a $1.5 billion attack) involved a sprawling network of OTC and P2P traders, predominantly Chinese nationals. These intermediaries worked around the clock, ensuring the conversion of cryptocurrency into cash. By September 2025, international monitoring groups had already recorded the complete cashing out of all funds stolen from Bybit.
It is important to understand: assets pass through dozens of addresses and multiple blockchains, with ownership changing hands many times. In some cases, the transition from North Korean operators to external launderers can be identified by characteristic changes in transaction behavior.
The scam industry as a haven
Of particular interest is the connection between North Korean money and the crypto scam industry. Investigators have found signs of DPRK funds being mixed with proceeds from fraudulent investment schemes known as "pig butchering," where victims are first drawn into trusting relationships and then persuaded to invest in fictitious projects.
A key role here is played by so-called guarantee marketplaces—underground Telegram platforms operating primarily in Chinese. They offer money laundering services, technical tools, and brokerage. My analysis has identified cases where cryptocurrency from DPRK-linked hacks ended up in closed escrow deals on such platforms. For example, part of the funds after the WazirX attack was transferred via TRON, consolidated, and then directed to addresses associated with Xinbi Guarantee and the now-defunct Huione Guarantee.
Fragmenting and P2P networks
Another characteristic feature is the fragmenting of large sums. Instead of directly withdrawing millions of dollars, funds are broken down into many small transactions. North Korean operators sell stablecoins through P2P marketplaces in batches of approximately $7,000, allowing them to bypass AML monitoring. Transactions are also fragmented down to $30,000 so that any potential freeze would only affect a minor portion of the assets.
To speed up processes, pre-prepared wallets with automatic fund distribution are used. The end points are often P2P marketplaces in South Asia and unregulated exchanges in Latin America.
As a result, after several stages, North Korean funds become nearly indistinguishable from other criminal cryptocurrency. This creates a serious problem for exchanges: establishing a link to the original attack becomes extremely difficult.
My expert conclusion: The main feature of the North Korean model is not the existence of a single "secret" channel, but the ability to integrate stolen assets into an already operating ecosystem of illegal exchangers and scam networks. This allows the DPRK to use others' infrastructure, making the blocking of funds at the final stages practically impossible. The industry needs to rethink its monitoring approaches, shifting focus from tracking specific addresses to analyzing behavioral patterns across the entire ecosystem.