North Korea has integrated into global criminal networks: a new model for laundering $2.8 billion

My analysis of the latest data on the movement of funds linked to North Korean cyber operations reveals a troubling trend: Pyongyang no longer relies on isolated channels to launder stolen assets. Instead, North Korean operators are actively integrating into existing criminal financial ecosystems, which dramatically complicates the tracking and blocking of funds.
This involves a comprehensive infrastructure that includes over-the-counter (OTC) services, P2P traders, illegal exchangers, mixers, cross-chain bridges, and platforms tied to the scam industry. From January 2024 to September 2025, the total volume of virtual assets stolen by North Korea reached at least $2.8 billion. These funds directly fuel the weapons program, and the key issue is that the stage of converting cryptocurrency into fiat is far less studied than on-chain laundering.
From hackers to criminal intermediaries
After the initial movement of funds, North Korean groups hand over assets to third-party launderers. A telling example is the $1.5 billion hack of the Bybit exchange in February 2025. The "whitening" process involved an entire network of OTC and P2P traders, predominantly Chinese citizens. These intermediaries worked around the clock, fragmented the assets, and by September 2025 had fully converted the stolen cryptocurrency into cash. The assets pass through dozens of addresses and several blockchains, with ownership changing multiple times, masking any connection to the original attack.
Symbiosis with the scam industry
Of particular interest is the intersection of North Korean flows with proceeds from fraudulent schemes known as "pig butchering." Investigations have recorded cases of mixing North Korean funds with money from victims of such investment scams. A key role in this nexus is played by so-called guarantee marketplaces—underground Telegram platforms in Chinese offering money laundering services, technical tools, and escrow intermediation. For example, part of the funds after the WazirX attack was consolidated on the TRON network and directed to addresses linked to Xinbi Guarantee and the now-defunct Huione Guarantee, potentially enabling the exchange of cryptocurrency for fiat.
Fragmentation and P2P networks
The laundering methodology is built on fragmenting large sums. Instead of withdrawing millions of dollars through a single platform, operators sell stablecoins via P2P marketplaces in batches of roughly $7,000 to avoid AML monitoring. Transactions are also fragmented to ~$30,000 so that freezes affect only a minor portion of the funds. To speed up the process, pre-prepared wallets with automatic asset distribution are used. Endpoints often include P2P platforms in South Asia and unregulated exchanges in Latin America.
As a result, after several stages, North Korean funds become nearly indistinguishable from other criminal cryptocurrency. This creates a colossal problem for exchanges and analytics firms: the link to the original attack is lost in the general flow of illegal operations.
My comment: The main takeaway from this data is that North Korea has become a systemic player in the global shadow economy, using others' infrastructure as a service. This means traditional address-blocking methods are becoming ineffective. The industry needs a fundamentally different approach based on behavioral analysis of transactions and interagency cooperation, rather than simple blacklists.