North Korea has integrated into criminal crypto networks: a new $2.8 billion money laundering model

An analysis by the British Royal United Services Institute (RUSI) has uncovered a troubling trend: Pyongyang has radically changed its approach to laundering stolen digital assets. Instead of building isolated infrastructure, North Korean operators are now actively embedding themselves into existing global criminal financial ecosystems. This is not just an evolution of methods—it is a qualitative leap in tracking complexity.
According to my data, from January 2024 to September 2025, North Korea stole at least $2.8 billion in virtual currencies. Critically, these funds directly fuel the weapons of mass destruction program. At the same time, the least studied stage is not on-chain movements, but precisely the conversion into fiat money, where hackers most effectively leverage others' developments.
Infrastructure of Others' Crime
The routes for moving funds include OTC services, P2P traders, illegal exchangers, mixers, and cross-chain bridges. Of particular interest is the use of so-called guarantee marketplaces—underground Telegram platforms primarily targeting a Chinese-speaking audience. They provide laundering services, technical tools, and escrow intermediation. For example, part of the funds after the WazirX hack was consolidated on the TRON network and directed to addresses linked to Xinbi Guarantee and the now-closed Huione Guarantee, where cryptocurrency could be exchanged for cash.
A striking example is the laundering of $1.5 billion stolen from Bybit in February 2025. The process involved a sprawling network of OTC and P2P traders, many of whom are Chinese citizens. They worked around the clock, split transactions, and ultimately cashed out all the funds by September 2025, as evidenced by data from the MSMT monitoring group.
Fractioning and P2P Tactics
A key element of the scheme is microtransactions. Instead of withdrawing millions of dollars in a single stream, operators sell stablecoins through P2P marketplaces in batches of approximately $7,000. This allows them to bypass AML monitoring. Fractioning down to ~$30,000 is also observed, so that a potential freeze would only affect a minor portion of the assets. At the endpoints of the routes are P2P platforms in South Asia and unregulated exchanges in Latin America.
My professional assessment: the main threat here is not in some new hacking techniques, but in the symbiosis with the crypto scam industry, including "pig butchering" schemes. After several mixing stages, North Korean funds become indistinguishable from other criminal flows. This creates a colossal problem for exchanges: the link to the original attack is practically lost, and blocking at the final stages of conversion into cash becomes nearly impossible. We are witnessing not just laundering, but full integration into the shadow economy of digital assets, which requires fundamentally new approaches to global monitoring.