The DPRK has integrated into global criminal networks: a new model for laundering stolen cryptocurrency

Analysis of recent trends shows that North Korea has radically changed its approach to laundering stolen digital assets. Instead of building isolated infrastructure, Pyongyang is increasingly integrating into existing criminal financial ecosystems. This is not just evolution—it is a qualitative leap in the complexity and efficiency of money laundering.
My research indicates that North Korea's money flows now pass through OTC services, P2P traders, illegal exchangers, mixers, cross-chain bridges, and platforms linked to the scam industry. Between January 2024 and September 2025, North Korea stole at least $2.8 billion in virtual assets. These funds directly fuel the weapons of mass destruction program, making the issue particularly acute.
The key role of third-party intermediaries
Of particular interest is the stage of converting cryptocurrency into fiat money. After the initial movement of funds, North Korea transfers assets to third-party launderers. A telling example is the $1.5 billion Bybit hack in February 2025: a whole network of OTC and P2P traders, mostly Chinese citizens, participated in the "whitening" process. These intermediaries worked around the clock, moving assets through dozens of addresses and several blockchains. By September 2025, all stolen funds had been fully cashed out.
The scam industry as cover
The most alarming trend is the mixing of North Korean funds with proceeds from fraudulent schemes. I have found signs that North Korean assets are increasingly intersecting with money from "pig butchering"—investment scams where victims are first groomed for trust and then persuaded to invest in fictitious projects. A key role here is played by so-called guarantee marketplaces—underground Telegram platforms in Chinese offering money laundering services, technical tools, and intermediation.
Cases have been recorded where cryptocurrency from hacks linked to North Korea ended up in closed escrow deals on such platforms. For example, part of the funds after the WazirX attack was transferred via TRON and directed to addresses associated with Xinbi Guarantee and Huione Guarantee. This allows digital assets to be exchanged for cash with virtually no trace.
Fragmenting and P2P networks
Another element of the scheme is splitting large sums into small transactions. North Korean operators sell stablecoins through P2P marketplaces in batches of approximately $7,000, which allows them to avoid AML monitoring. In some cases, fragmentation reaches $30,000 so that any potential freeze affects only a minor portion of the funds. To speed up the process, pre-prepared wallets are used that automatically distribute assets to specified addresses. The endpoints are P2P marketplaces in South Asia and unregulated exchanges in Latin America.
The main feature of this model is not the existence of some "secret" channel, but the ability to embed stolen cryptocurrency into the already existing ecosystem of illegal exchangers and scam networks. After several stages, the funds become virtually indistinguishable from other criminal cryptocurrency. This creates a colossal problem for exchanges: the link to the original attack becomes extremely difficult to establish.
My comment: We are witnessing the professionalization of state-sponsored cybercrime. North Korea no longer acts as a lone hacker—it acts as a corporation using global shadow infrastructure. This requires regulators and crypto exchanges to adopt fundamentally new approaches to monitoring, based on analyzing behavioral patterns rather than just tracking specific addresses.