North Korea has integrated into global criminal networks: a new model for laundering stolen cryptocurrency.

Analysis of recent trends shows that North Korean operators have radically changed their approach to laundering stolen digital assets. Instead of building isolated infrastructure, Pyongyang is increasingly integrating into existing criminal financial ecosystems. This is not just evolution—it is a qualitative leap in the complexity and resilience of the schemes.
Between January 2024 and September 2025, North Korea managed to steal at least $2.8 billion in virtual assets. These funds directly fuel the weapons program, and, critically, the stage of converting them into fiat money remains the least studied link in the entire chain. On-chain tracking is just the tip of the iceberg.
From hackers to criminal intermediaries
The key point is the transfer of stolen cryptocurrency to third-party launderers. In the case of the $1.5 billion Bybit hack in February 2025, a network of OTC and P2P traders, mostly Chinese nationals, worked around the clock. These intermediaries fragmented and moved the assets until, by September 2025, all funds were fully cashed out. Ownership of the assets changes multiple times, passing through dozens of addresses and several blockchains, making tracing extremely difficult.
Scams as part of the ecosystem
Of particular note is the connection between North Korean flows and the crypto scam industry. My fellow investigators have identified signs of mixing North Korean funds with proceeds from "pig butchering" schemes—investment frauds where victims are first groomed for trust and then persuaded to invest in fictitious projects. A central role here is played by so-called guarantee marketplaces—underground Telegram platforms in Chinese offering money laundering services, technical tools, and escrow intermediation.
For example, part of the funds after the WazirX attack passed through TRON, was consolidated, and sent to addresses linked to Xinbi Guarantee and the now-defunct Huione Guarantee. Such transactions allow cryptocurrency to be exchanged for cash without direct contact with exchanges.
Fragmentation and P2P mechanics
The laundering scheme is built on microtransactions. Instead of withdrawing millions of dollars in a single payment, stablecoins are sold through P2P marketplaces in batches of approximately $7,000, allowing AML monitoring to be bypassed. Fragmentation down to ~$30,000 is also observed, so that any potential asset freeze affects only a minor portion of the funds. To speed up the process, pre-prepared wallets are used that automatically distribute assets to specified addresses. Endpoints often include P2P platforms in South Asia and unregulated exchanges in Latin America.
After several stages, North Korean funds become nearly indistinguishable from other criminal cryptocurrency. This creates a colossal problem for exchanges: the connection to the original attack is lost in a web of intermediaries.
My conclusion: North Korea has not invented a new tool but masterfully exploits someone else's infrastructure. This means that anti-money laundering efforts must shift from tracking specific addresses to analyzing behavioral patterns in global P2P networks. While regulators and exchanges focus on on-chain tracing, attackers are already playing on a different field—in the gray zone of informal financial flows, where freezing funds at the final stages is practically impossible.