North Korea has integrated into global criminal networks: a new era of crypto-asset laundering

Analysis of recent trends shows that North Korean operators have radically changed their approach to laundering stolen digital assets. Instead of building isolated infrastructure, they now actively integrate into existing criminal financial ecosystems. This is not just evolution—it is a qualitative leap in the complexity and efficiency of money laundering.
Capital movement routes cover over-the-counter (OTC) services, P2P traders, illegal exchange points, mixers, cross-chain bridges, and platforms linked to fraudulent schemes. Based on monitoring data, my estimates indicate that from January 2024 to September 2025, North Korea stole at least $2.8 billion in virtual assets. These funds directly fuel the weapons of mass destruction program. Notably, the stage of conversion into fiat currency is far less studied than on-chain laundering, creating serious gaps in the global countermeasures system.
From hackers to criminal intermediaries
After the initial movement of funds, North Korea increasingly transfers cryptocurrency to third-party launderers. A telling example is the $1.5 billion hack of the Bybit exchange in February 2025. A whole network of OTC and P2P traders, predominantly Chinese citizens, was involved in the "whitening" process. These intermediaries worked around the clock, moving assets, and ultimately converted all stolen cryptocurrency into fiat and cash. By September 2025, all Bybit funds had been cashed out.
The cryptocurrency passes through dozens of addresses and several blockchains, with ownership changing multiple times. In some cases, the transfer of funds from North Korean operators to third-party launderers can be tracked through characteristic changes in transaction behavior—a key indicator for analysts.
Scams as part of the ecosystem
Particular attention is drawn to the connection between North Korean money and the crypto scam industry. I am recording signs of mixing North Korean funds with proceeds from "pig butchering" fraud—investment schemes where victims are first drawn into trusting relationships and then persuaded to invest in fictitious projects.
A critical role is played by so-called guarantee marketplaces—underground platforms operating primarily through Telegram in Chinese. They offer money laundering services, technical tools, and intermediation. My analysis has identified cases where cryptocurrency from North Korea-linked hacks ended up in closed escrow deals on such platforms. For example, part of the funds after the WazirX attack was transferred via TRON, consolidated, and sent to addresses linked to Xinbi Guarantee and the now-defunct Huione Guarantee. Such deals potentially allow cryptocurrency to be exchanged for cash.
Fragmenting and P2P mechanisms
Another element of the scheme is fragmenting large sums. Instead of directly withdrawing millions through a single platform, funds are broken down into many small operations. North Korean operators sell stablecoins through P2P marketplaces in batches of approximately $7,000, receiving cash. Such amounts allow them to avoid AML monitoring. Transactions are also fragmented to approximately $30,000 so that any potential freeze affects only a minor portion of the funds.
To speed up the process, pre-prepared wallets are used that automatically distribute assets to specified addresses. The endpoints are P2P marketplaces in South Asia and unregulated crypto exchanges in Latin America.
As a result, after several stages, North Korean funds become almost indistinguishable from other criminal cryptocurrency. This creates an additional problem for exchanges and crypto companies: once funds enter the broad network of criminal intermediaries, establishing a link to the original attack becomes extremely difficult.
The main feature of the North Korean model is not the presence of some single "secret" channel, but the ability to embed stolen cryptocurrency into the existing ecosystem of illegal exchangers, P2P networks, and scams. This allows North Korea to use others' infrastructure and significantly complicates the freezing of funds at the final stages.
My comment: This trend signals that traditional anti-money laundering methods based on tracking individual addresses are becoming ineffective. The industry needs to shift toward analyzing behavioral patterns and collaborative filtering at the network level; otherwise, we will witness further convergence of state-sponsored cybercrime and organized crime.