Crypto news

12.08.2026
03:52

North Korea has integrated into global scam networks: a new model for laundering stolen cryptocurrency

северокорейские хакеры North Korean hackers

An analysis conducted by experts at the British Royal United Services Institute (RUSI) has revealed a troubling trend: North Korea has radically changed its approach to laundering stolen digital assets. Instead of building isolated infrastructure, North Korean hackers are increasingly integrating into existing criminal financial ecosystems, making fund tracking significantly more difficult.

Capital movement routes span over-the-counter (OTC) services, P2P traders, illegal exchangers, mixers, cross-chain bridges, and platforms linked to fraudulent schemes. From January 2024 to September 2025, North Korea stole at least $2.8 billion in virtual assets, and these funds directly finance its weapons of mass destruction program. The stage of conversion into fiat currency remains critically important and is far less studied than on-chain laundering.

From hackers to criminal intermediaries

After the initial movement of funds, North Korean operators hand over cryptocurrency to third-party launderers. A whole network of OTC and P2P traders, many of whom are Chinese citizens, was involved in the laundering process following the $1.5 billion hack of the Bybit exchange in February 2025. These intermediaries worked around the clock, moving assets and ultimately converting them into fiat and cash. By September 2025, all funds stolen from Bybit had been fully cashed out.

The cryptocurrency passes through dozens of addresses and several blockchains, with ownership changing hands multiple times. In some cases, the transfer of funds from North Korean operators to third-party launderers can be identified by characteristic changes in transaction behavior.

The scam industry as a key element

Researchers paid particular attention to the connection between North Korean money and the crypto scam industry. Signs were found of North Korean funds being mixed with proceeds from "pig butchering" scams—investment schemes where criminals first gain victims' trust and then convince them to invest in fictitious projects.

A key role is played by so-called guarantee marketplaces—underground Telegram platforms, predominantly in Chinese. They offer money laundering services, technical tools, and intermediation. Cryptocurrency from hacks linked to North Korea ended up in closed escrow deals on such platforms. For example, part of the funds after the WazirX attack was transferred via TRON, consolidated, and sent to addresses associated with Xinbi Guarantee and the now-defunct Huione Guarantee. Such deals allow cryptocurrency to be exchanged for cash.

Fragmenting and P2P networks

Another element of the scheme is the fragmenting of large sums. Instead of directly withdrawing millions of dollars, funds are broken down into many small transactions. North Korean operators sell stablecoins through P2P marketplaces in batches of approximately $7,000, receiving cash and avoiding AML monitoring. Transactions are also fragmented to ~$30,000 so that a potential freeze would only affect an insignificant portion of the funds.

To speed up the process, pre-prepared wallets that automatically distribute assets are used. The end points are P2P marketplaces in South Asia and unregulated crypto exchanges in Latin America.

As a result, after several stages, North Korean funds become almost indistinguishable from other criminal cryptocurrency. This creates a serious problem for exchanges: once funds enter the broad network of criminal intermediaries, establishing a link to the original attack becomes extremely difficult.

The main feature of the North Korean model is not the existence of some single "secret" channel, but the ability to embed stolen cryptocurrency into the already existing ecosystem of illegal exchangers, P2P networks, and scams. This allows North Korea to use others' infrastructure and virtually eliminates the possibility of freezing funds at the final stages.

My comment: we are witnessing an evolution from primitive hacker attacks to a complex, industrialized financial operation on a state scale. For the industry, this means that standard monitoring methods are no longer effective—the implementation of proactive behavioral analysis algorithms is required, not just tracking of known addresses.