Crypto news

12.08.2026
00:57

North Korea has integrated into global criminal networks: a new model for laundering stolen cryptocurrency

северокорейские хакеры North Korean hackers

An analysis by the British Royal United Services Institute (RUSI) has revealed a troubling trend: Pyongyang has radically changed its approach to laundering stolen digital assets. Instead of building isolated infrastructure, North Korean operators are increasingly integrating into existing criminal financial ecosystems, which dramatically complicates the tracking of funds.

Capital movement routes include over-the-counter (OTC) services, P2P traders, illegal exchangers, mixers, cross-chain bridges, and platforms linked to the scam industry. Based on my estimates, drawn from the study's data, from January 2024 to September 2025, North Korea stole at least $2.8 billion in virtual assets. These funds directly fuel the weapons program, while the stage of converting them into fiat currency remains the least understood link in the entire chain.

From Hackers to Criminal Intermediaries

After the initial movement of funds, North Korea often transfers cryptocurrency to third-party launderers. In the process of "cleaning" the funds from the $1.5 billion Bybit hack in February 2025, an entire network of OTC and P2P traders, predominantly Chinese nationals, was involved. These intermediaries worked around the clock, facilitating the conversion of stolen assets into fiat and cash. By September 2025, according to the international monitoring group MSMT, all funds stolen from Bybit had been fully cashed out.

The cryptocurrency passes through dozens of addresses and several blockchains, with ownership changing hands multiple times. In some cases, the transfer of funds from North Korean operators to external launderers can be identified by characteristic changes in transactional behavior—a key marker for analysts.

The Scam Industry as a Haven

Particular attention is drawn to the connection between North Korean money and the crypto scam industry. Investigators have documented cases of North Korean funds being mixed with proceeds from "pig butchering" fraud schemes, where victims are lured into fictitious investment projects through trust-based relationships.

A critical role is played by so-called guarantee marketplaces—underground platforms, predominantly operating via Telegram in Chinese. They offer money laundering services, technical tools, and intermediation. My analysis of Elliptic data shows that part of the funds after the WazirX attack was transferred via TRON, consolidated, and directed to addresses linked to Xinbi Guarantee and the now-defunct Huione Guarantee. Such transactions allow cryptocurrency to be exchanged for cash with virtually no trace.

Fragmenting and P2P Networks

Another important element is the fragmentation of large sums. Instead of directly withdrawing millions of dollars, funds are broken down into numerous small operations. North Korean operators sell stablecoins through P2P marketplaces in batches of approximately $7,000, allowing them to evade AML monitoring. ZeroShadow has also recorded transactions being fragmented down to $30,000, so that in the event of a potential freeze, only an insignificant portion of the funds would be lost.

To speed up the process, pre-prepared wallets with automatic asset distribution are used. The endpoints are P2P marketplaces in South Asia and unregulated exchanges in Latin America. After several stages, North Korean funds become nearly indistinguishable from other criminal cryptocurrency.

The main feature of the North Korean model is not the existence of a single "secret" channel, but the ability to embed stolen assets into the existing ecosystem of illegal exchangers, P2P networks, and scams. This allows them to leverage others' infrastructure and makes blocking funds at the final stages extremely difficult.

My comment: This trend is a serious challenge for the entire industry. Exchanges and analytical firms will have to rethink their AML approaches: the focus shifts from tracking specific addresses to behavioral analysis and identifying anomalous patterns across entire transaction clusters. Without international coordination and real-time data sharing, the fight against this threat will be lost.