North Korea has integrated stolen cryptocurrency into global scam networks: a new money laundering model

An analysis of recent fund movements shows that North Korea has radically changed its approach to laundering stolen digital assets. Instead of building isolated infrastructure, Pyongyang is actively integrating into existing criminal financial ecosystems, making it significantly harder to track fund flows.
My research confirms that from January 2024 to September 2025, the DPRK stole at least $2.8 billion in virtual assets, and these funds directly fuel its weapons program. The key problem is that the fiat conversion stage remains a "gray area" for analysts, unlike on-chain tracking.
From hackers to criminal intermediaries
After the initial movement of funds, North Korean operators hand over assets to third-party launderers. For example, the $1.5 billion Bybit hack in February 2025 involved a sprawling network of OTC and P2P traders, mostly Chinese nationals. These intermediaries worked around the clock, and by September 2025, all stolen funds had been fully cashed out.
Asset movement passes through dozens of addresses and multiple blockchains, with ownership changing hands repeatedly. In several cases, the transition from DPRK operators to external launderers can be identified by characteristic changes in transaction behavior.
Scams as a key element of the scheme
Particular attention is drawn to the connection between North Korean money and the crypto scam industry. I am observing signs of DPRK funds being mixed with proceeds from "pig butchering" fraud — investment schemes where victims are first drawn into trusting relationships and then persuaded to invest in fictitious projects.
A critical role is played by so-called guarantee marketplaces — underground Telegram platforms in Chinese. They offer laundering services, technical tools, and brokerage. For example, part of the funds after the WazirX attack was transferred via TRON, consolidated, and directed to addresses linked to Xinbi Guarantee and the now-defunct Huione Guarantee.
Fragmenting and P2P routes
Another characteristic feature is the fragmentation of large sums. Instead of directly withdrawing millions, operators split funds into small batches. According to my data, stablecoins are sold through P2P marketplaces in batches of approximately $7,000, which helps avoid AML monitoring. Fragmentation down to $30,000 is also observed, so that a freeze affects only a minor portion of assets.
To speed up the process, pre-prepared wallets with automatic fund distribution are used. Endpoints include P2P platforms in South Asia and unregulated exchanges in Latin America.
Ultimately, after several stages, North Korean funds become indistinguishable from other criminal cryptocurrency. This creates a serious problem for exchanges: establishing a link to the original attack is nearly impossible.
My conclusion: the main feature of the DPRK model is not the existence of a "secret" channel, but the ability to embed itself into the existing ecosystem of illegal exchangers and scams. This allows it to leverage others' infrastructure and makes blocking funds at the final stages extremely difficult. The industry needs new analytical approaches that go beyond traditional on-chain monitoring.