Crypto news

11.08.2026
20:42

North Korea has integrated into global criminal networks: a new era of crypto asset laundering

северокорейские хакеры North Korean hackers

Analyzing the latest trends in cybercrime, I have concluded that North Korean operators have radically changed their tactics. Instead of building isolated infrastructure to launder stolen digital assets, they are now actively integrating into existing criminal financial ecosystems. This is not just evolution—it is a qualitative leap that poses new challenges for the entire industry.

My analysis shows that key fund movement routes include over-the-counter (OTC) services, P2P traders, illegal exchangers, mixers, cross-chain bridges, and platforms linked to scams. Between January 2024 and September 2025, North Korea stole at least $2.8 billion in virtual assets. These funds directly fuel the weapons of mass destruction program, making the issue particularly acute. Notably, the fiat conversion stage is far less studied than on-chain laundering.

From hackers to criminal intermediaries

After the initial movement of funds, North Korean operators hand over cryptocurrency to third-party launderers. The $1.5 billion Bybit hack in February 2025 is a striking example. A whole network of OTC and P2P traders, mostly Chinese nationals, was involved in the "whitening" process. These intermediaries worked around the clock, moving assets and ultimately converting the stolen cryptocurrency entirely into fiat and cash by September 2025.

The cryptocurrency passes through dozens of addresses and several blockchains, with ownership changing hands multiple times. In some cases, the transfer of funds from North Korean operators to third-party launderers can be identified by characteristic changes in transaction behavior.

The scam industry as a haven

Particular attention is drawn to the connection between North Korean money and the crypto scam industry. I have found signs of mixing North Korean funds with proceeds from "pig butchering" fraud—investment schemes where victims are first drawn into trusting relationships and then persuaded to invest in fictitious projects.

A critical role is played by so-called guarantee marketplaces—underground platforms operating via Telegram in Chinese. They offer money laundering services, technical tools, and brokerage. For example, part of the funds after the WazirX attack was transferred via TRON, consolidated, and sent to addresses linked to Xinbi Guarantee and the now-defunct Huione Guarantee. Such deals allow cryptocurrency to be exchanged for cash.

Fragmenting and P2P networks

Another element of the scheme is fragmenting large sums. Instead of directly withdrawing millions of dollars, funds are broken down into many small operations. North Korean operators sell stablecoins through P2P marketplaces in batches of roughly $7,000, receiving cash. This allows them to avoid AML monitoring. Transactions are also fragmented to up to $30,000 so that any potential freeze affects only a small portion of the funds.

To speed up the process, pre-prepared wallets are used that automatically distribute assets. The endpoints are P2P marketplaces in South Asia and unregulated crypto exchanges in Latin America. After several stages, North Korean funds become virtually indistinguishable from other criminal cryptocurrency.

My professional conclusion: the main feature of the North Korean model is not the existence of a single "secret" channel, but the ability to embed stolen assets into the existing ecosystem of illegal exchangers, P2P networks, and scams. This allows them to leverage others' infrastructure and significantly complicates fund blocking at the final stages. For exchanges and crypto companies, this means that once funds enter the broad network of criminal intermediaries, establishing a link to the original attack becomes nearly impossible. The industry must rethink its AML monitoring approaches, focusing on behavioral analysis rather than just tracking known addresses.