North Korea has integrated into global criminal networks: a new era of crypto-asset laundering

Analysis of recent trends shows that North Korean operators have radically changed their approach to laundering stolen digital assets. Instead of building their own isolated infrastructure, they are now actively integrating into existing global criminal financial ecosystems. This is not just evolution—it is a qualitative leap in the complexity and scale of operations.
Fund movement routes span over-the-counter (OTC) platforms, P2P traders, illegal exchange offices, mixers, cross-chain bridges, and even venues linked to fraudulent schemes. Based on my estimates, drawn from a body of open-source data, from January 2024 to September 2025, North Korea stole at least $2.8 billion in virtual assets. These funds directly fuel the weapons program, and the key problem is that the fiat conversion stage is far less understood than on-chain analysis of token movement.
From hackers to criminal intermediaries
After the initial movement of assets, North Koreans hand them off to third-party launderers. For example, in the process of "whitening" funds following the $1.5 billion Bybit exchange hack in February 2025, a network of OTC and P2P traders, mostly Chinese nationals, was involved. These intermediaries worked around the clock, split up the assets, and ultimately ensured the full conversion of the stolen cryptocurrency into cash by September 2025. The cryptocurrency passes through dozens of addresses and multiple blockchains, with ownership changing hands repeatedly, making tracking extremely difficult.
The scam industry as a refuge
Particular attention is drawn to the connection between North Korean funds and proceeds from "pig butchering" scams. This refers to investment schemes where victims are first drawn into trusting relationships and then persuaded to invest in fictitious projects. My research shows that mixing flows has become common practice.
A key role here is played by so-called guarantee marketplaces—underground Telegram platforms in Chinese. They provide laundering services, technical tools, and escrow intermediation. For example, part of the funds after the WazirX attack was consolidated on the TRON network and directed to addresses linked to Xinbi Guarantee and the now-defunct Huione Guarantee. Such deals allow cryptocurrency to be exchanged for cash outside the traditional financial system.
Fragmenting and P2P networks
Another important element is the fragmentation of large sums. Instead of directly withdrawing millions, operators break funds into small transactions. For instance, stablecoins are sold through P2P marketplaces in batches of roughly $7,000, which helps evade AML monitoring. Transactions are also fragmented down to $30,000 so that a potential freeze affects only a minor portion of the capital. Pre-prepared wallets are used to automate the process, distributing assets to specified addresses. The end points are often P2P platforms in South Asia and unregulated exchanges in Latin America.
Ultimately, after several stages, North Korean funds become nearly indistinguishable from other criminal cryptocurrency. This creates a colossal problem for exchanges: establishing a link to the original attack once funds enter a broad network of intermediaries becomes almost impossible.
My expert conclusion: The main threat lies not in the existence of some single "secret" channel, but in North Korea's ability to seamlessly embed itself into the global ecosystem of illegal exchange offices, P2P networks, and scam projects. This turns the fight against the financing of weapons programs into an endless game of cat and mouse, where traditional methods of freezing assets at the final stages are becoming increasingly ineffective. The industry needs to rethink its monitoring approaches, shifting focus from hunting for "dirty" addresses to analyzing behavioral patterns across the entire network.