Crypto news

12.08.2026
05:24

North Korea has integrated into global criminal networks: how the new scheme for laundering stolen cryptocurrency works

северокорейские хакеры North Korean hackers

An analysis conducted by RUSI experts has revealed a troubling trend: North Korea has radically changed its approach to laundering stolen digital assets. Instead of building isolated infrastructure, Pyongyang is actively integrating into existing criminal financial ecosystems. This is not just an evolution of tactics—it is a strategic shift that makes combating North Korean money laundering significantly more difficult.

This involves an entire network of tools: OTC services, P2P traders, illegal exchanges, mixers, cross-chain bridges, and platforms linked to scams. Between January 2024 and September 2025, the DPRK stole at least $2.8 billion in virtual assets. These funds directly fuel the weapons of mass destruction program, making the issue not merely financial but a matter of global security.

From Hackers to Criminal Intermediaries

The key point is the delegation of laundering to third parties. After the initial hack, such as the $1.5 billion Bybit exchange breach in February 2025, North Korean operators transfer assets to networks of OTC and P2P traders, often with Chinese roots. These intermediaries work around the clock, splitting and moving funds. According to the international monitoring group MSMT, by September 2025, all funds stolen from Bybit had been successfully cashed out. The cryptocurrency passes through dozens of addresses and multiple blockchains, and ownership changes so quickly that tracing the ultimate beneficiary becomes nearly impossible.

Scams as Cover

Of particular interest is the connection between North Korean money and the crypto scam industry. Experts have found signs of DPRK funds being mixed with proceeds from fraudulent schemes like "pig butchering." Here, so-called guarantee marketplaces play a key role—underground Telegram platforms in Chinese that offer laundering services, technical tools, and escrow intermediation. For example, part of the funds after the WazirX attack was transferred via TRON to addresses linked to Xinbi Guarantee and the now-defunct Huione Guarantee. This allows cryptocurrency to be exchanged for cash outside the traditional banking system.

Fragmenting and P2P Networks

The laundering scheme is built on fragmenting large sums. Instead of withdrawing millions of dollars in a single payment, funds are broken down into small transactions. North Korean operators may sell stablecoins through P2P marketplaces in batches of roughly $7,000, avoiding AML monitoring. ZeroShadow has recorded transaction fragmentation down to $30,000, so that any potential freeze affects only a minor portion of the funds. To speed up the process, pre-prepared wallets are used that automatically distribute assets. The end points are often P2P platforms in South Asia and unregulated exchanges in Latin America.

The main takeaway: the DPRK does not have a single "secret" channel. Their strength lies in the ability to embed themselves into the existing ecosystem of illegal exchanges, P2P networks, and crypto scams. This allows them to leverage others' infrastructure and makes blocking funds at the final stages extremely difficult. As I noted earlier, hacker groups linked to the DPRK have turned cryptocurrency theft into a large-scale state operation with its own infrastructure and a network of IT agents. Now we see that this operation has also become part of a global criminal interconnect, requiring regulators and exchanges to adopt fundamentally new approaches to transaction monitoring.