Crypto news

12.08.2026
00:37

North Korea has integrated into global scam networks: a new $2.8 billion money laundering model

северокорейские хакеры North Korean hackers

An analysis of recent trends in cybercrime shows that North Korean operators have radically changed their approach to laundering stolen digital assets. Instead of building isolated infrastructure, Pyongyang is now actively integrating into existing criminal financial ecosystems, which significantly complicates the tracking and blocking of funds.

This involves a comprehensive scheme that includes over-the-counter (OTC) services, P2P traders, illegal exchangers, mixers, cross-chain bridges, and platforms linked to the scam industry. Between January 2024 and September 2025, North Korea managed to steal at least $2.8 billion in virtual assets, and these funds directly fuel its weapons program. The key challenge for investigators is the fiat conversion stage, which is far less understood than on-chain movements.

From hackers to criminal intermediaries

After the initial withdrawal of funds, North Koreans transfer assets to third-party launderers. A telling example is the $1.5 billion hack of the Bybit exchange in February 2025. The "whitening" process involved an entire network of OTC and P2P traders, mostly Chinese citizens, who continuously split and moved assets around the clock, ultimately converting them into cash. By September 2025, all stolen funds had been fully cashed out.

The cryptocurrency passes through dozens of addresses and several blockchains, repeatedly changing "owners." In some cases, the transition from North Korean operators to third parties can be identified by characteristic changes in transaction behavior, but this is more the exception than the rule.

Scams as a key element

Particular attention is drawn to the connection between North Korean money and the crypto scam industry. Investigators are recording the mixing of North Korean funds with proceeds from fraudulent schemes like "pig butchering," where victims are first drawn into trusting relationships and then persuaded to invest in fictitious projects.

A critical role is played by so-called guarantee marketplaces—underground Telegram platforms in Chinese that offer laundering services, technical tools, and intermediation. Cases have been recorded where cryptocurrency from hacks linked to North Korea ended up in closed escrow deals on such platforms. For example, part of the funds after the WazirX attack was consolidated on the TRON network and then directed to addresses associated with Xinbi Guarantee and the now-defunct Huione Guarantee, potentially allowing assets to be exchanged for cash.

Splitting and P2P channels

A key element of the scheme is the splitting of large sums. Instead of directly withdrawing millions of dollars, funds are broken down into many small transactions. North Korean operators sell stablecoins through P2P marketplaces in batches of approximately $7,000, allowing them to bypass AML monitoring. In other cases, transactions are split down to $30,000 so that a potential freeze would affect only a minor portion of the funds. To speed up the process, pre-prepared wallets with automatic asset distribution are used. The end points are P2P marketplaces in South Asia and unregulated exchanges in Latin America.

As a result, after several stages, North Korean funds become nearly indistinguishable from other criminal cryptocurrency. This creates a colossal problem for exchanges: once assets enter the broad network of criminal intermediaries, establishing a link to the original attack becomes extremely difficult.

The main feature of the new North Korean model is not the existence of some single "secret" channel, but the ability to embed stolen assets into an already functioning ecosystem of illegal exchangers, P2P networks, and scam projects. This allows North Korea to use others' infrastructure and virtually eliminates the possibility of freezing funds at the final stages.

My comment: This trend is an alarming signal for the entire industry. While regulators and exchanges focus on blocking addresses linked to specific hacks, North Korea is already playing ahead, dissolving its assets into the general flow of criminal money. Combating this requires not point-based measures, but a comprehensive approach to verifying the origin of funds across the entire ecosystem, including the P2P segment, which remains a "gray zone" to this day.