Crypto news

11.08.2026
20:22

North Korea has integrated into global criminal networks: a new model for laundering crypto assets

северокорейские хакеры North Korean hackers

Analysis of recent data shows that North Korea has radically changed its approach to laundering stolen digital assets. Instead of building isolated infrastructure, Pyongyang is actively integrating into existing criminal financial ecosystems, which significantly complicates the tracking and blocking of funds.

According to my estimates, based on the study of transaction flows, from January 2024 to September 2025, the DPRK stole at least $2.8 billion in virtual assets. These funds directly fuel the weapons of mass destruction program. Notably, the stage of conversion into fiat money remains the least studied compared to on-chain laundering.

Key channels and intermediaries

The movement of funds passes through over-the-counter (OTC) services, P2P traders, illegal exchangers, mixers, and cross-chain bridges. A special role is played by platforms associated with the scam industry. For example, the laundering process after the $1.5 billion Bybit hack in February 2025 involved a network of Chinese OTC and P2P traders who moved assets around the clock and ultimately cashed them out completely by September 2025.

An important element of the scheme is the so-called guarantee marketplaces, underground Telegram platforms in Chinese. They provide money laundering services and technical tools. I have recorded cases where cryptocurrency from hacks linked to the DPRK ended up in closed escrow deals on such platforms, including Xinbi Guarantee and Huione Guarantee.

Breaking up and masking

North Korean operators actively break up large sums. Instead of directly withdrawing millions of dollars, stablecoins are sold through P2P marketplaces in batches of approximately $7,000, which allows them to avoid AML monitoring. There is also a recorded fragmentation of transactions to $30,000 to minimize losses in case of a potential freeze. The final points are often P2P platforms in South Asia and unregulated exchanges in Latin America.

The result is that North Korean funds become almost completely indistinguishable from other criminal cryptocurrency. This creates a serious problem for exchanges: once assets enter the broad network of criminal intermediaries, establishing a connection to the original attack becomes extremely difficult.

My conclusion: the key feature of the new model is not the existence of some "secret" channel, but the ability to embed stolen assets into an already functioning ecosystem of illegal exchangers and scams. This allows the DPRK to use someone else's infrastructure and significantly complicates the blocking of funds at the final stages. The industry should expect increased regulatory pressure on the P2P segment and unregulated platforms, as they are becoming the main hub in this global scheme.