North Korea has integrated into global criminal crypto networks: a new $2.8 billion money laundering model

An analysis of recent trends in cybercrime shows that North Korea has radically changed its approach to laundering stolen digital assets. Instead of building isolated infrastructure, Pyongyang is now actively integrating into existing criminal financial ecosystems, making it significantly harder to track and block funds.
Between January 2024 and September 2025, North Korean hackers stole at least $2.8 billion in virtual assets. These funds directly fuel the weapons program, but the key challenge for investigations remains the stage of converting cryptocurrency into fiat money, which is far less studied than on-chain transactions.
Integration into the criminal ecosystem
After the initial hack, North Korean operators hand over assets to third-party launderers. For example, the $1.5 billion Bybit exchange hack in February 2025 involved an entire network of OTC and P2P traders, mostly Chinese citizens. They worked around the clock, split up the amounts, and by September 2025 had fully cashed out the stolen funds.
Of particular interest is the connection between North Korean money and the crypto scam industry, especially fraudulent schemes like "pig butchering." North Korean funds are often mixed with proceeds from such scams, creating additional "noise" for analysts. A significant role is played by so-called guarantee marketplaces—underground Telegram platforms in Chinese where money laundering services, technical tools, and escrow deals are offered. For instance, part of the funds after the WazirX attack was consolidated via TRON and directed to addresses linked to Xinbi Guarantee and Huione Guarantee.
Splitting and P2P channels
A key element of the scheme is splitting large amounts. North Korean operators sell stablecoins through P2P marketplaces in batches of roughly $7,000, which helps avoid AML monitoring. In other cases, transactions are broken down to $30,000 so that asset freezes affect only a minor portion of the funds. To speed up the process, pre-prepared wallets with automatic asset distribution are used. The endpoints of such chains are P2P platforms in South Asia and unregulated exchanges in Latin America.
The main takeaway from this analysis is that North Korea does not have a single "secret" channel. Instead, the country effectively parasitizes on other people's criminal infrastructure, making the final stages of laundering nearly indistinguishable from other illegal activity. For exchanges and crypto companies, this creates a fundamental problem: once funds enter a broad network of intermediaries, establishing their link to the original attack becomes almost impossible.
My comment: This strategy is a logical evolution. While regulators and analytics firms refine methods for tracking on-chain flows, North Korea has moved to "foreign territory," leveraging existing gray and black markets. This means that anti-money laundering efforts must shift from address analysis to studying behavioral patterns and interactions with unregulated P2P services, where traditional AML tools are often powerless.