Crypto news

12.08.2026
02:37

North Korea has integrated into criminal crypto networks: a new $2.8 billion money laundering model

северокорейские хакеры

An analysis by the British defense institute RUSI has uncovered a troubling trend: Pyongyang has radically changed its tactics for laundering stolen digital assets. Instead of building isolated infrastructure, North Korean operators are now actively integrating into existing criminal financial ecosystems. This is not just evolution—it is a qualitative leap in the complexity and resilience of these schemes.

This involves a symbiosis with OTC services, P2P traders, illegal exchangers, mixers, and cross-chain bridges. Of particular interest is the use of platforms linked to crypto scams. From January 2024 to September 2025, North Korea stole at least $2.8 billion, and these funds directly fuel its weapons of mass destruction program. The key issue raised by researchers is that the stage of conversion into fiat currency is far less understood than on-chain tracking.

From Hackers to Criminal Intermediaries

After the initial breach, assets are handed off to third-party launderers. A telling example is the $1.5 billion Bybit hack in February 2025. According to analysts at ZeroShadow, a whole network of OTC and P2P traders, mostly Chinese nationals, was involved in the process, working around the clock. By September 2025, the monitoring group MSMT confirmed that all stolen funds had been fully cashed out. The movement of assets is obfuscated through dozens of addresses and multiple blockchains, and the transition to third-party intermediaries can only be detected through characteristic changes in transaction behavior.

Scams as Part of the Pipeline

Of particular concern is the connection between North Korean money and the fraud industry, specifically "pig butchering" schemes. Investigators are recording the mixing of stolen assets with proceeds from fake investment projects. A key role here is played by so-called guarantee marketplaces—underground Telegram platforms in Chinese offering laundering services, technical tools, and escrow deals. For example, part of the funds after the WazirX attack passed through TRON and was consolidated on addresses linked to Xinbi Guarantee and the now-defunct Huione Guarantee. This is a potential channel for exchanging cryptocurrency for cash.

Fractioning and P2P Tactics

Another element of the scheme is microtransactions. Instead of withdrawing millions of dollars, amounts are broken down into small batches. North Korean operators sell stablecoins through P2P marketplaces in batches of approximately $7,000 to avoid AML monitoring. ZeroShadow also recorded fractioning down to $30,000 to minimize losses in case of potential freezes. To speed up the process, pre-prepared wallets that automatically distribute assets are used. The end points are often P2P platforms in South Asia and unregulated exchanges in Latin America.

Ultimately, after several stages, North Korean funds become indistinguishable from other criminal cryptocurrency. This creates a colossal problem for exchanges: the link to the original attack is practically lost. The main conclusion of RUSI is that North Korea does not have a single "secret" channel. Their strength lies in their ability to embed themselves into others' infrastructure, making it extremely difficult to block funds at the final stages.

My comment: This trend is a direct consequence of strengthened regulation and AML controls on major exchanges. North Korea adapts faster than regulators can respond, turning the global crypto ecosystem into its shadow financial backbone. This requires a rethink of monitoring approaches: the focus should shift from tracking specific addresses to analyzing behavioral patterns in the P2P and OTC segments.