North Korea integrates stolen cryptocurrency into global scam networks: a new era of money laundering

Analysis of recent trends shows that North Korean operators have fundamentally changed their approach to laundering stolen digital assets. Instead of building isolated infrastructure, they are increasingly integrating into existing criminal financial ecosystems, which significantly complicates tracking and blocking funds.
My research confirms: capital flow paths cover over-the-counter (OTC) services, P2P traders, illegal exchangers, mixers, cross-chain bridges, and platforms linked to fraudulent schemes. Between January 2024 and September 2025, North Korea stole at least $2.8 billion in virtual assets, and these funds directly fuel its weapons program. Critically, the stage of conversion into fiat money remains the least studied link in this chain.
The key role of criminal intermediaries
After the initial movement of assets, North Korean hackers hand them over to third-party launderers. For example, the process of cashing out funds stolen from Bybit in February 2025 ($1.5 billion) involved a sprawling network of OTC and P2P traders, mostly Chinese citizens. These intermediaries worked around the clock, and by September 2025, all stolen funds had been fully converted into cash. Notably, the assets pass through dozens of addresses and several blockchains, with ownership changing multiple times, and the transition to third-party launderers can only be detected through characteristic changes in transactional behavior.
Scams as an integral part of the scheme
Of particular interest is the discovered connection between North Korean money and the crypto scam industry. I have managed to identify cases where North Korean funds are mixed with proceeds from "pig butchering" fraud—investment schemes where victims are first drawn into trusting relationships and then persuaded to invest in fictitious projects. A key role here is played by so-called guarantee marketplaces—underground Telegram platforms in Chinese offering laundering services, technical tools, and brokerage.
Moreover, part of the funds after the WazirX attack was transferred via TRON, consolidated, and directed to addresses linked to Xinbi Guarantee and the now-defunct Huione Guarantee. This allows cryptocurrency to be exchanged for cash bypassing traditional financial institutions.
Fragmenting and P2P marketplaces
Special attention deserves the tactic of fragmenting large sums. Instead of directly withdrawing millions of dollars, operators split funds into many small transactions. For example, stablecoins are sold through P2P marketplaces in batches of approximately $7,000, which helps avoid AML monitoring. Transactions are also fragmented down to $30,000 so that any potential freeze affects only a negligible portion of the funds. To speed up the process, pre-prepared wallets with automatic asset distribution are used, with end points being P2P platforms in South Asia and unregulated exchanges in Latin America.
As a result, after several stages, North Korean funds become almost indistinguishable from other criminal cryptocurrency. This creates a colossal problem for exchanges: once funds enter the broad network of criminal intermediaries, establishing a link to the original attack becomes extremely difficult.
My expert assessment: The main threat lies not in the existence of some single "secret" channel, but in North Korea's ability to embed itself into the existing ecosystem of illegal exchangers, P2P networks, and scams. This not only allows the use of others' infrastructure but also makes it nearly impossible to block funds at the final stages of their conversion into cash. The industry needs to develop new analytical methods focused on behavioral patterns rather than individual addresses.