Crypto news

12.08.2026
03:17

North Korea has embedded itself into the shadow crypto ecosystem: how $2.8 billion disappears through scam networks

северокорейские хакеры North Korean hackers

An analysis conducted as part of research by the British defense institute RUSI has uncovered Pyongyang's new tactics in laundering digital assets. Instead of creating isolated infrastructure, North Korean operators are increasingly integrating into existing criminal financial networks, which fundamentally changes the rules of the game for global regulators and exchanges.

This involves a complex system that includes over-the-counter (OTC) services, P2P traders, illegal exchangers, mixers, cross-chain bridges, and—most notably—platforms linked to the scam industry. From January 2024 to September 2025, based on my estimates derived from this data, North Korea stole at least $2.8 billion in virtual assets. These funds directly finance the weapons program, and the key issue is that the stage of converting them into fiat currency remains the least understood link in the entire chain.

From hackers to criminal intermediaries

After the initial hack, funds do not remain at a single address. A striking example is the attack on Bybit in February 2025, when an astronomical sum of $1.5 billion was stolen. A whole network of OTC and P2P traders, predominantly Chinese citizens, was involved in "whitening" these assets. These intermediaries worked around the clock, split transactions, and ultimately, by September 2025, fully cashed out the stolen funds. Notably, the transfer of assets from North Korean operators to third-party launderers can often be tracked through characteristic changes in transaction behavior—this is the only lead for analysts.

Scams as part of the puzzle

Of particular interest is the connection between North Korean money and the crypto scam industry. Traces of North Korean funds are found in pools alongside proceeds from fraudulent schemes known as "pig butchering." A decisive role here is played by so-called guarantee marketplaces—underground Telegram platforms in Chinese that offer laundering services, technical tools, and escrow services. For example, part of the funds after the WazirX hack was consolidated on the TRON network and directed to addresses linked to Xinbi Guarantee and the now-defunct Huione Guarantee. This is not just a technical detail but an entire market where cryptocurrency is directly exchanged for cash.

Fractioning and P2P

A key element of the scheme is micro-fractioning. Instead of withdrawing millions of dollars in a single tranche, operators sell stablecoins through P2P marketplaces in batches of approximately $7,000. Such an amount allows bypassing AML monitoring. In other cases, transactions are split down to $30,000 so that freezing one part does not paralyze the entire flow. To speed up the process, pre-prepared "smart" wallets are used that automatically distribute assets. The endpoints are P2P platforms in South Asia and unregulated exchanges in Latin America.

As a result, after several stages, North Korean assets become indistinguishable from other criminal cryptocurrency. This creates a colossal problem for exchanges: establishing a link to the original attack after funds enter a broad network of intermediaries is nearly impossible.

My conclusion: The main takeaway from this analysis is not the existence of some "secret" channel, but North Korea's surprising ability to embed itself into others' criminal infrastructure. This means that combating weapons financing requires not only blocking specific addresses but also systematically cleansing the entire shadow ecosystem, including scam platforms and illegal OTC networks. As long as this market exists, Pyongyang will find ways to exploit it for its own purposes.