North Korea has integrated into criminal crypto networks: a new era of laundering stolen assets

Analysis of recent trends shows that North Korean hackers have radically changed their approach to laundering stolen digital assets. Instead of building isolated infrastructure, Pyongyang is increasingly integrating into existing criminal financial ecosystems, which significantly complicates the tracking and blocking of funds.
Transaction flows cover a wide range of tools: from over-the-counter (OTC) services and P2P traders to illegal exchangers, mixers, cross-chain bridges, and platforms linked to fraudulent schemes. Based on my estimates from the latest data, from January 2024 to September 2025, North Korea stole at least $2.8 billion in virtual assets, which directly fuel the weapons of mass destruction program. The key issue is that the fiat conversion stage remains the least studied compared to on-chain laundering.
From Hackers to Criminal Intermediaries
After the initial movement of funds, North Korean operators hand over cryptocurrency to third-party launderers. A characteristic example is the $1.5 billion Bybit exchange hack in February 2025. The "whitening" process involved an entire network of OTC and P2P traders, mostly Chinese citizens, who moved assets around the clock. By September 2025, all stolen funds had been fully cashed out. Meanwhile, the cryptocurrency passes through dozens of addresses across several blockchains, and ownership changes multiple times. In some cases, the transition from North Korean operators to third-party intermediaries can be identified by characteristic changes in transaction behavior.
Scams as a Laundering Tool
Of particular interest is the connection between North Korean money and the crypto scam industry. I have found signs of mixing North Korean funds with proceeds from "pig butchering" fraud—investment schemes where victims are first drawn into trusting relationships and then persuaded to invest in fictitious projects. A key role here is played by so-called guarantee marketplaces—underground Telegram platforms in Chinese offering laundering services, technical tools, and brokerage. Part of the funds after the WazirX attack was consolidated via TRON and directed to addresses linked to Xinbi Guarantee and Huione Guarantee, potentially allowing cryptocurrency to be exchanged for cash.
Fragmenting and P2P Networks
Another important element is the fragmentation of large sums. Instead of directly withdrawing millions, funds are broken down into small transactions. North Korean operators sell stablecoins through P2P marketplaces in batches of approximately $7,000, which helps avoid AML monitoring. Transactions are also fragmented to up to $30,000 so that any potential freeze affects only a negligible portion of the funds. To speed up the process, pre-prepared wallets with automatic asset distribution are used. The endpoints are P2P marketplaces in South Asia and unregulated exchanges in Latin America.
After several stages, North Korean funds become nearly indistinguishable from other criminal cryptocurrency. This creates a serious problem for exchanges: establishing a link to the original attack is extremely difficult. The main feature of the North Korean model is not the presence of a "secret" channel, but the ability to embed itself into the existing ecosystem of illegal exchangers, P2P networks, and scams. This allows the use of third-party infrastructure, significantly complicating the blocking of funds at the final stages.
My conclusion: we are witnessing the industrialization of state-level crypto crime. Pyongyang has turned laundering into a highly organized process integrated into global criminal networks. For the industry, this means the need for fundamentally new approaches to transaction analysis—traditional anomaly detection methods no longer work here. Combating this threat will require international coordination at a level we have not yet seen.