Crypto news

11.08.2026
22:23

North Korea is integrating into criminal crypto networks: a new era of money laundering

северокорейские хакеры North Korean hackers

In the course of my in-depth analysis of the latest trends in cybersecurity, I have identified a troubling evolution in the methods of North Korean hackers. Instead of using isolated infrastructure to launder stolen crypto assets, North Korea is now actively embedding itself into existing criminal financial ecosystems. This fundamentally changes the rules of the game for global regulators and exchanges.

Scale and New Routes

From January 2024 to September 2025, North Korean groups stole at least $2.8 billion in virtual assets. These funds directly fuel the weapons program, making the issue particularly acute. The key conclusion I reach is that the stage of converting cryptocurrency into fiat money is far less studied than on-chain tracking, and it is here that the main risks lie.

The paths of fund movement now include OTC services, P2P traders, illegal exchangers, mixers, cross-chain bridges, and platforms associated with scams. For example, the $1.5 billion Bybit hack in February 2025 involved an entire network of intermediaries, many of whom are Chinese citizens. They worked around the clock, and by September 2025, all stolen funds had been fully cashed out.

The Scam Industry as a Cover

Particular attention is drawn to the connection between North Korean money and the crypto scam industry, including "pig butchering" schemes. I have found that North Korean funds are mixed with proceeds from fraudulent investment projects. A decisive role is played by so-called guarantee marketplaces—underground Telegram platforms in Chinese that offer money laundering services and technical support.

In particular, part of the funds after the WazirX attack was transferred via TRON to addresses associated with Xinbi Guarantee and Huione Guarantee. Such transactions allow cryptocurrency to be exchanged for cash outside the view of regulators.

Fragmentation and P2P Networks

Another characteristic feature is the fragmentation of large sums. North Korean operators sell stablecoins through P2P marketplaces in batches of approximately $7,000, which allows them to avoid AML monitoring. In some cases, transactions are fragmented down to $30,000 so that a potential freeze would affect only an insignificant portion of the assets. The endpoints are P2P platforms in South Asia and unregulated exchanges in Latin America.

After several stages of such operations, North Korean funds become virtually indistinguishable from other criminal cryptocurrency. This creates a colossal problem for exchanges: the connection to the initial attack becomes extremely difficult to establish.

My conclusion as an analyst: the main threat lies not in the existence of some "secret" channel, but in North Korea's ability to use others' infrastructure. This means that blocking funds at the final stages of their conversion into cash requires fundamentally new approaches to international cooperation and monitoring. The industry must realize: we are dealing with a state actor that has turned cryptocurrency theft into a large-scale industrialized operation.