Crypto news

11.08.2026
23:37

North Korea has integrated into global scam networks: a new model for laundering $2.8 billion

северокорейские хакеры North Korean hackers

Analysis of recent trends in cybercrime shows that North Korea has radically changed its approach to laundering stolen digital assets. Instead of building isolated infrastructure, Pyongyang is now actively integrating into existing criminal financial ecosystems. This is not just an evolution of tactics—it is a qualitative shift that poses fundamentally new challenges to the global anti-money laundering system.

My research confirms: from January 2024 to September 2025, the DPRK stole at least $2.8 billion in virtual assets. These funds directly fuel the weapons of mass destruction program. It is critical to understand: while on-chain laundering is well studied, the stage of converting to fiat currency remains a "gray zone" for analysts.

Criminal intermediaries as a new tool

A key element of the new strategy is handing stolen funds over to third-party launderers. For example, the $1.5 billion Bybit hack in February 2025 involved a sprawling network of OTC and P2P traders, mostly Chinese nationals. These intermediaries worked around the clock, split transactions, and ultimately cashed out all stolen assets by September 2025.

Particular attention is drawn to the connection between North Korean money and the crypto scam industry. I have found signs of DPRK funds being mixed with proceeds from "pig butchering" scams, where victims are first drawn into trusting relationships and then persuaded to invest in fictitious projects. So-called guarantee marketplaces play a significant role—underground Telegram platforms in Chinese offering a full range of laundering services.

Transaction splitting and P2P networks

The tactic of splitting transactions has become the standard: instead of large transfers, funds are broken down into small batches. North Korean operators sell stablecoins through P2P marketplaces in portions of roughly $7,000—this allows them to evade AML monitoring. A strategy of splitting down to $30,000 has also been observed, so that any potential freeze affects only a minor portion of the assets.

After several stages of "cleaning," North Korean funds become indistinguishable from other criminal cryptocurrency. This creates a colossal problem for exchanges: the link to the original attack is practically lost.

My expert assessment: we are witnessing not just adaptation, but the industrialization of state-scale crypto crime. While regulators focus on blocking individual addresses, the DPRK is already using others' infrastructure as its own. Without international coordination and real-time data sharing, the fight against this threat will be lost at every stage.