North Korea has integrated into global criminal networks: a new model for laundering stolen cryptocurrency

An analysis by the UK's Royal United Services Institute (RUSI) has uncovered a troubling trend: Pyongyang has radically revised its strategy for laundering stolen digital assets. Instead of building isolated infrastructure, North Korean operators are increasingly integrating into already functioning criminal financial ecosystems, using them as a ready-made tool to conceal their tracks.
This involves the comprehensive use of over-the-counter (OTC) services, P2P traders, illegal exchangers, mixers, and cross-chain bridges. The key conclusion of my analysis: the stage of converting to fiat currency remains a "gray area," far less studied than on-chain tracing. According to estimates, from January 2024 to September 2025, North Korea stole at least $2.8 billion in virtual assets, directly fueling its weapons of mass destruction program.
From hackers to criminal intermediaries
After the initial hack, funds are often transferred to third-party launderers. A striking example is the Bybit incident in February 2025, where a whole network of OTC and P2P traders, mostly Chinese citizens, participated in "whitening" $1.5 billion. These intermediaries worked around the clock, split up the assets, and ultimately fully cashed out the stolen funds by September 2025. In the process, the funds pass through dozens of addresses and several blockchains, and the transition from North Korean operators to third parties can only be detected by characteristic changes in transactional behavior.
The scam industry as a refuge
Of particular interest is the connection between North Korean money and the crypto scam industry. I found signs of mixing North Korean funds with proceeds from fraudulent schemes like "pig butchering," where victims are lured into fake investment projects. A key role here is played by so-called guarantee marketplaces—underground Chinese-language Telegram platforms offering money laundering services, technical tools, and escrow intermediation. For example, part of the funds after the WazirX attack passed through TRON and was consolidated on addresses linked to Xinbi Guarantee and Huione Guarantee, potentially allowing cryptocurrency to be exchanged for cash.
Fractioning and P2P tactics
The scheme also includes the systematic fractioning of large sums. Instead of directly withdrawing millions, operators sell stablecoins through P2P marketplaces in batches of approximately $7,000, which helps avoid AML monitoring. Sometimes transactions are split down to ~$30,000 so that a potential freeze would only affect a small portion of the assets. To speed up the process, pre-prepared wallets with automatic fund distribution are used. The endpoints are P2P platforms in South Asia and unregulated exchanges in Latin America.
As a result, after several stages, North Korean assets become almost indistinguishable from other criminal cryptocurrency. This creates a colossal problem for exchanges: establishing a link to the original attack after funds enter a broad criminal network becomes extremely difficult.
My expert assessment: the main threat here is not the existence of a "secret" channel, but North Korea's ability to parasitize on others' infrastructure. This not only complicates blocking funds at the final stages but also makes anti-money laundering efforts more costly and less effective. The industry needs to rethink its monitoring approaches, focusing not on individual addresses but on behavioral patterns and connections to scam ecosystems.