North Korea has integrated into criminal crypto networks: a new $2.8 billion money laundering scheme

Analysis of recent trends shows that North Korean operators have radically changed their approach to laundering stolen digital assets. Instead of building isolated infrastructure, Pyongyang is actively integrating into existing criminal financial ecosystems, which significantly complicates tracking and freezing funds.
My research indicates that the movement of stolen cryptocurrency now spans over-the-counter (OTC) services, P2P traders, illegal exchanges, mixers, and cross-chain bridges. Particular attention is drawn to connections with platforms affiliated with the scam industry. Between January 2024 and September 2025, North Korea stole at least $2.8 billion in virtual assets, and these funds directly fuel the weapons of mass destruction program. Notably, the fiat conversion stage is far less studied than on-chain laundering, creating serious gaps in the global countermeasures system.
From hackers to criminal intermediaries
A key element of the new strategy is handing assets over to third-party launderers. The $1.5 billion Bybit hack in February 2025 became a telling example: a network of OTC and P2P traders, mostly Chinese nationals, moved funds around the clock, ensuring their conversion into cash. By September 2025, all assets stolen from the exchange had been fully cashed out. Meanwhile, the cryptocurrency passes through dozens of addresses and several blockchains, with ownership changing multiple times, masking the original source.
Scam infrastructure as a refuge
Of particular interest is the convergence of North Korean money with proceeds from fraud schemes like "pig butchering." The analysis uncovered cases of mixing North Korean funds with assets obtained from investment scams. A significant role is played by so-called guarantee marketplaces—underground Chinese-language Telegram platforms offering laundering services and technical support. For example, part of the funds after the WazirX attack was consolidated on the TRON network and directed to addresses linked to Xinbi Guarantee and the now-defunct Huione Guarantee, potentially enabling the exchange of cryptocurrency for cash.
Fragmenting and P2P as survival tactics
Operators actively break large sums into small transactions. Selling stablecoins through P2P marketplaces in batches of roughly $7,000 allows them to evade AML monitoring. Transactions are also split into amounts up to $30,000 so that any potential freeze affects only a negligible portion of the funds. To speed up the process, pre-prepared wallets with automated asset distribution are used. The endpoints are P2P platforms in South Asia and unregulated exchanges in Latin America.
As a result, after several stages, North Korean funds become nearly indistinguishable from other criminal cryptocurrency. This creates a colossal problem for exchanges: establishing a link to the original attack is almost impossible. The model's main feature is not the existence of a secret channel, but the ability to embed itself into third-party infrastructure, making it extremely difficult to freeze funds at the final stages.
My comment: This trend is a troubling signal for the entire industry. While regulators and exchanges focus on on-chain analytics, North Korea is mastering the "gray" zones of the criminal economy where AML procedures are powerless. The industry needs to rethink its approach to monitoring P2P networks and illegal exchanges, otherwise we risk witnessing further professionalization of money laundering on a global scale.