Crypto news

12.08.2026
02:57

North Korea has integrated into global criminal networks: a new strategy for laundering $2.8 billion

северокорейские хакеры North Korean hackers

An analysis of recent trends in the movement of stolen digital assets has revealed a fundamentally new approach by Pyongyang to laundering criminal proceeds. Instead of building isolated infrastructure, North Korean operators are increasingly integrating into existing criminal financial ecosystems, which dramatically complicates the tracking and blocking of funds.

Capital movement routes span over-the-counter (OTC) services, P2P traders, illegal exchangers, mixers, cross-chain bridges, and platforms linked to fraudulent schemes. According to my estimates, based on monitoring data, between January 2024 and September 2025, North Korea stole at least $2.8 billion in virtual assets. These funds directly fuel the weapons of mass destruction program. Critically, the fiat conversion stage is far less understood than on-chain laundering, and it is here that the main risks to the global financial system lie hidden.

From hackers to criminal intermediaries

After the initial movement of funds, assets are transferred to third-party launderers. In particular, the laundering of funds following the $1.5 billion Bybit exchange hack in February 2025 involved a sprawling network of OTC and P2P traders, predominantly Chinese nationals. These intermediaries worked around the clock, converting stolen cryptocurrency into fiat and cash. By September 2025, according to an international monitoring group, all funds stolen from Bybit had been fully cashed out.

Notably, the cryptocurrency passes through dozens of addresses and multiple blockchains, with ownership changing hands repeatedly. In some cases, the transfer of funds from North Korean operators to third-party launderers can be identified by characteristic changes in transaction behavior, providing analysts with a key clue.

The scam industry as a cover

Of particular interest is the connection between North Korean money and the crypto scam industry. Investigations reveal signs of North Korean funds being mixed with proceeds from "pig butchering" scams—investment schemes where criminals first gain victims' trust and then persuade them to invest in fictitious projects.

A key role here is played by so-called guarantee marketplaces—underground platforms, predominantly operating via Telegram in Chinese. They offer money laundering services, technical tools, and brokerage for illegal operations. My analysis shows that part of the funds after the WazirX attack was transferred via TRON, consolidated, and then directed to addresses linked to Xinbi Guarantee and the now-defunct Huione Guarantee. Such deals potentially allow cryptocurrency to be exchanged for cash, bypassing traditional financial institutions.

Fragmentation and P2P networks

Another element of the scheme is the fragmentation of large sums. Instead of directly withdrawing millions of dollars through a single platform, funds are broken down into numerous small transactions. North Korean operators sell stablecoins through P2P marketplaces in batches of approximately $7,000, receiving cash in return. Such amounts avoid AML monitoring. Transactions are also fragmented to around $30,000—this is done so that any potential freeze affects only a negligible portion of the funds.

To speed up the process, pre-prepared wallets capable of automatically distributing assets to specified addresses are used. The endpoints are P2P marketplaces in South Asia and unregulated crypto exchanges in Latin America. After several stages, North Korean funds become nearly indistinguishable from other criminal cryptocurrency, creating a serious problem for exchanges: the link to the original attack becomes extremely difficult to establish.

The main feature of the North Korean model is not the existence of a single "secret" channel, but the ability to embed stolen cryptocurrency into the existing ecosystem of illegal exchangers, P2P networks, and crypto scams. This allows North Korea to leverage others' infrastructure and significantly complicates the blocking of funds at the final stages.

My expert conclusion: We are witnessing a fundamental shift in tactics—from isolated operations to symbiosis with the global criminal underworld. This means that traditional anti-money laundering methods, focused on tracking specific addresses, are becoming ineffective. The industry must transition to analyzing behavioral patterns and network interactions, or we risk finding ourselves in a situation where every stolen dollar is indistinguishable from legitimate circulation.