North Korea has integrated into global criminal networks: a new era of crypto-asset laundering

Analysis of recent trends shows that North Korean operators have radically changed their approach to laundering stolen digital assets. Instead of building isolated infrastructure, Pyongyang is increasingly integrating into existing criminal financial ecosystems, which significantly complicates the tracking and blocking of funds.
Scale and Routes of Fund Movement
From January 2024 to September 2025, North Korea stole at least $2.8 billion in virtual assets. These funds directly fuel the program to create weapons of mass destruction. A key feature is that capital flows through OTC services, P2P traders, illegal exchangers, mixers, cross-chain bridges, and platforms associated with scams. At the same time, the stage of conversion into fiat money is much less studied than on-chain laundering, creating serious gaps in the international monitoring system.
Integration with the Criminal World
The example of the $1.5 billion hack of the Bybit exchange in February 2025 is telling. A sprawling network of OTC and P2P traders, mostly Chinese citizens, was involved in the laundering process. These intermediaries worked around the clock, split transactions, and ultimately cashed out all stolen funds by September 2025. The cryptocurrency passed through dozens of addresses and several blockchains, with ownership changing hands multiple times.
Of particular interest is the connection between North Korean money and the crypto scam industry. Investigators are recording the mixing of North Korean funds with proceeds from fraudulent schemes like "pig butchering." A key role is played by so-called guarantee marketplaces—underground Telegram platforms in Chinese offering laundering services, technical tools, and escrow intermediation. For example, part of the funds after the WazirX attack was consolidated on TRON and directed to addresses linked to Xinbi Guarantee and Huione Guarantee.
Tactics of Splitting and P2P Networks
North Korean operators actively use the splitting of large sums. Instead of directly withdrawing millions, stablecoins are sold through P2P marketplaces in batches of approximately $7,000, which allows them to avoid AML monitoring. In some cases, transactions are split down to $30,000 so that a freeze affects only a minor portion of the assets. To speed up the process, pre-prepared wallets with automatic fund distribution are used. The endpoints are P2P platforms in South Asia and unregulated exchanges in Latin America.
As a result, after several stages, North Korean funds become almost indistinguishable from other criminal cryptocurrency. This creates a colossal problem for exchanges: the connection to the original attack is lost in a broad network of criminal intermediaries.
My comment: The key takeaway is that there is no single "secret" laundering channel. North Korea masterfully uses others' infrastructure, turning the global crypto ecosystem into its shadow bank. This requires regulators and exchanges to adopt fundamentally new approaches to analyzing transaction patterns, not just blocking known addresses. The industry must prepare for North Korean funds to penetrate legitimate circulation ever deeper through these hybrid schemes.