Crypto news

12.08.2026
01:57

North Korea has integrated into global criminal networks: a new era of cryptocurrency laundering

северокорейские хакеры North Korean hackers

Analysis of recent trends shows that North Korean operators have radically changed their approach to laundering stolen digital assets. Instead of building isolated infrastructure, they are actively integrating into existing criminal financial ecosystems, making fund tracking significantly more difficult.

Key capital movement routes now include over-the-counter (OTC) services, P2P traders, illegal exchangers, mixers, cross-chain bridges, and platforms linked to fraudulent schemes. Between January 2024 and September 2025, North Korea stole at least $2.8 billion in virtual assets. These funds directly fuel the weapons program, while the stage of conversion into fiat money remains the least studied.

The Role of Intermediaries and the Scam Industry

After the initial movement of assets, North Koreans often hand them over to third-party launderers. For example, in the case of the $1.5 billion Bybit hack in February 2025, an entire network of OTC and P2P traders, mostly Chinese citizens, was involved. These intermediaries worked around the clock, and by September 2025, all stolen funds had been fully cashed out. Notably, during the laundering process, cryptocurrency is often mixed with proceeds from scam schemes such as "pig butchering," creating a dense veil for law enforcement.

A special role is played by so-called guarantee marketplaces—underground Telegram platforms in Chinese. They provide laundering services, technical tools, and escrow services. Cases have been recorded where funds from attacks on WazirX passed through such platforms, were consolidated on the TRON network, and were directed to addresses associated with Xinbi Guarantee and Huione Guarantee.

Fragmenting and Final Conversion

A key element of the scheme is the fragmentation of large sums. Instead of withdrawing millions of dollars directly, operators split funds into small transactions. For example, stablecoins are sold through P2P marketplaces in batches of approximately $7,000, allowing AML monitoring to be bypassed. Fragmentation down to $30,000 is also used to minimize losses in the event of possible asset freezes. Endpoints include P2P platforms in South Asia and unregulated exchanges in Latin America.

As a result of multi-stage processing, North Korean funds become indistinguishable from other criminal flows. This creates a colossal problem for exchanges, as establishing a link to the original attack after funds enter the general network is nearly impossible.

My conclusion: We are witnessing a transition from "lone" hacker operations to an industrial approach, where North Korea acts not as an outcast but as a full-fledged participant in the shadow economy. This requires regulators and exchanges to adopt fundamentally new analysis methods based on behavioral patterns, rather than solely on tracking specific addresses.