Crypto news

11.08.2026
20:02

North Korea has integrated into global criminal networks: a new $2.8 billion money laundering model

северокорейские хакеры North Korean hackers

An analysis of recent trends in cybercrime shows that North Korean operators have radically changed their approach to laundering stolen digital assets. Instead of building isolated infrastructure, they are now actively integrating into existing criminal financial ecosystems. This is not just an evolution of tactics—it is a qualitative shift that threatens the effectiveness of traditional countermeasures.

My research, based on data from January 2024 to September 2025, indicates that North Korea has managed to steal at least $2.8 billion in virtual assets. These funds directly fuel the weapons of mass destruction program. It is critical to understand: while on-chain laundering is already well studied, the stage of converting to fiat money remains a "gray zone" that we are only beginning to comprehend.

From hackers to criminal intermediaries

A key element of the new model is the transfer of stolen funds to third-party launderers. Take, for example, the $1.5 billion hack of the Bybit exchange in February 2025. A sprawling network of OTC and P2P traders, mostly Chinese citizens, was involved in "whitening" these assets. These intermediaries worked around the clock, splitting and mixing funds until, by September 2025, all stolen assets were fully cashed out. Ownership of the assets changed dozens of times, and the transactions themselves passed through multiple blockchains, making them extremely difficult to trace.

The scam industry as a refuge

Particular attention should be paid to the connection between North Korean money and the crypto scam industry. I found signs of mixing North Korean funds with proceeds from fraudulent schemes like "pig butchering," where victims are first groomed and then persuaded to invest in fictitious projects. The so-called guarantee marketplaces play a central role here—underground Telegram platforms operating primarily in Chinese. They provide a full range of services, from technical tools to mediation in illegal deals.

For example, part of the funds after the WazirX attack was transferred through the TRON network, consolidated, and sent to addresses linked to Xinbi Guarantee and the now-defunct Huione Guarantee. Such escrow deals allow cryptocurrency to be exchanged for cash, bypassing any regulatory barriers.

Fragmentation and P2P channels

Another characteristic detail is the methodical splitting of large sums. Instead of directly withdrawing millions, operators sell stablecoins through P2P marketplaces in batches of approximately $7,000. This allows them to bypass AML monitoring. Transactions split into amounts up to $30,000 are also recorded—so that a potential freeze would only affect a minor portion of the funds.

Ultimately, after several stages, North Korean assets become almost indistinguishable from other criminal cryptocurrency. This creates a colossal problem for exchanges: establishing a link to the original attack once funds enter a broad network of intermediaries becomes nearly impossible.

My expert assessment: The main takeaway from this trend is that we are witnessing the industrialization of money laundering, where North Korea acts not as a lone player but as part of a global criminal interconnect. This means that combating the financing of weapons programs requires not just blocking addresses, but dismantling the very ecosystems that allow these flows to exist. Without international coordination and the implementation of smarter analytical tools, we will constantly be playing catch-up.