North Korea has integrated into criminal crypto networks: a new strategy for laundering $2.8 billion

An analysis of recent trends shows that North Korean operators have radically changed their approach to laundering stolen digital assets. Instead of using isolated infrastructure, Pyongyang is increasingly integrating into existing criminal financial ecosystems. This is not just evolution—it is a qualitative leap in the complexity and efficiency of money laundering schemes.
Between January 2024 and September 2025, the volume of virtual assets stolen by the DPRK reached at least $2.8 billion. These funds directly fuel the weapons of mass destruction program, making the issue not merely economic but a matter of global security. A key gap in understanding this threat is the stage of converting cryptocurrency into fiat money, which is far less studied than on-chain tracking.
Integration into criminal infrastructure
Fund flow routes include OTC services, P2P traders, illegal exchanges, mixers, and cross-chain bridges. Of particular note is the use of platforms associated with crypto scams. In the process of laundering funds after the $1.5 billion Bybit hack in February 2025, an entire network of intermediaries was involved, many of whom are Chinese citizens. These agents worked around the clock, split the assets, and ultimately converted them into cash. By September 2025, all funds stolen from Bybit had been fully cashed out.
A characteristic feature of the new model is the mixing of North Korean assets with proceeds from "pig butchering" scam schemes. Investigators are documenting how DPRK funds pass through underground guarantee marketplaces, predominantly based in Chinese-language Telegram. These platforms provide escrow services and technical support for illegal operations. For example, part of the funds after the WazirX attack was transferred via TRON and consolidated on addresses linked to Xinbi Guarantee and the now-defunct Huione Guarantee.
Fragmenting and bypassing AML
The strategy of fragmenting amounts has become particularly sophisticated. Instead of directly withdrawing millions of dollars, operators split funds into batches of approximately $7,000 through P2P marketplaces, allowing them to evade AML monitoring. In some cases, transactions are fragmented down to $30,000 so that a potential freeze would only affect a minor portion of the funds. Pre-prepared wallets are used to automate the process, distributing assets to specified addresses. The endpoints are P2P platforms in South Asia and unregulated exchanges in Latin America.
The main conclusion I draw from this analysis is that the North Korean model is not about having a single "secret" channel, but rather the ability to parasitize on someone else's criminal ecosystem. This creates a colossal problem for exchanges and regulators. Once funds enter a broad network of intermediaries, establishing a link to the original attack becomes nearly impossible. As I have repeatedly emphasized in my reviews, without global coordination and data sharing between jurisdictions, we will continue playing catch-up with those who have turned cryptocurrency theft into a state program.