North Korea has embedded stolen cryptocurrency into a shadow ecosystem: a new reality of money laundering

Analysis of recent trends shows that North Korean operators have radically changed their approach to laundering stolen digital assets. Instead of building isolated infrastructure, they are increasingly integrating into existing criminal financial networks, which dramatically complicates tracking and blocking funds.
This involves a comprehensive ecosystem that includes over-the-counter (OTC) services, P2P traders, illegal exchanges, mixers, and cross-chain bridges. Of particular interest is the fact that these channels are closely intertwined with platforms specializing in scam schemes. By my estimates, from January 2024 to September 2025, North Korea stole at least $2.8 billion in virtual assets, and these funds directly fuel its weapons program. It is critically important to understand: the stage of conversion into fiat money remains the least studied link in this chain, even though it poses the greatest threat.
The Role of Criminal Intermediaries
After the initial movement of funds, North Korean hackers transfer the cryptocurrency to third-party launderers. A striking example is the $1.5 billion hack of the Bybit exchange in February 2025. The "whitening" process involved a sprawling network of OTC and P2P traders, mostly Chinese citizens, who fragmented and moved assets around the clock. By September 2025, all stolen funds had been fully cashed out. Notably, the transition from North Korean operators to third-party intermediaries can often be detected by characteristic changes in transactional behavior, giving analysts leads.
The Scam Industry as a Haven
Of particular concern is the connection between North Korean money and proceeds from "pig butchering" scams. Investigations have uncovered signs of mixing North Korean funds with profits from these investment schemes. A key role here is played by so-called guarantee marketplaces—underground Telegram platforms in Chinese offering money laundering services, technical tools, and escrow intermediation. For example, part of the funds after the WazirX attack passed through TRON, was consolidated, and directed to addresses linked to Xinbi Guarantee and the now-defunct Huione Guarantee. Such transactions allow cryptocurrency to be exchanged for cash with virtually no trace.
Fragmentation and P2P Networks
The scheme also involves breaking down large sums into smaller transactions. North Korean operators sell stablecoins through P2P marketplaces in batches of approximately $7,000, which allows them to avoid AML monitoring. Fragmentation of transactions down to $30,000 has also been recorded—so that any potential freeze would affect only a small portion of the funds. To speed up the process, pre-prepared wallets with automatic asset distribution are used. The endpoints are P2P platforms in South Asia and unregulated exchanges in Latin America.
Ultimately, after several stages, North Korean funds become almost indistinguishable from other criminal cryptocurrency. This creates a colossal problem for exchanges: establishing a link to the original attack once funds enter a broad network of intermediaries becomes nearly impossible.
My conclusion: North Korea has not invented a new "secret" channel but masterfully exploits someone else's infrastructure. This is not just hacker activity, but a systemic state operation that requires regulators and crypto exchanges to adopt fundamentally new approaches to monitoring, going beyond traditional on-chain data analysis. Blocking funds at the final stages of their conversion into cash is no longer a technical but a political and legal challenge.