The DPRK has integrated into global scam networks: a new model for laundering stolen cryptocurrency

An analysis of recent cybersecurity trends shows that North Korea has radically changed its approach to laundering stolen digital assets. Instead of isolated infrastructure solutions, Pyongyang is increasingly integrating into existing criminal financial ecosystems, which significantly complicates the tracking of illicit flows.
Fund movement routes span OTC services, P2P traders, illegal exchange points, mixers, cross-chain bridges, and platforms directly linked to the scam industry. Based on my estimates, drawn from monitoring data, from January 2024 to September 2025, North Korea stole at least $2.8 billion in virtual assets. These funds directly fuel the weapons of mass destruction program. Notably, the fiat conversion stage remains the least studied link in the entire chain—unlike on-chain laundering, which is already well documented.
Criminal intermediaries as a key link
After the initial movement of assets, North Korean operators hand over the cryptocurrency to third-party launderers. For example, the process of "cleaning" funds stolen from the Bybit exchange in February 2025 (a $1.5 billion attack) involved a network of OTC and P2P traders, mostly Chinese nationals. These intermediaries worked around the clock, moving assets and ensuring conversion into fiat and cash. By September 2025, according to the international monitoring group MSMT, all stolen funds had been fully cashed out.
The cryptocurrency passes through dozens of addresses and several blockchains, with ownership changing multiple times. In some cases, the transfer of funds from North Korean operators to third-party launderers can be identified by characteristic changes in transaction behavior—an important indicator for analysts.
The scam industry as a haven
Particular attention is drawn to the connection between North Korean money and crypto scams. Investigators are recording signs of mixing North Korean funds with proceeds from fraudulent schemes like "pig butchering," where victims are first drawn into trusting relationships and then persuaded to invest in fictitious projects. A key role is played by so-called guarantee marketplaces—underground Telegram platforms operating primarily in Chinese. They offer laundering services, technical tools, and brokerage for illegal operations.
I am aware of cases where cryptocurrency from North Korea-linked hacks ended up in closed escrow deals on such platforms. For example, part of the funds after the WazirX attack was transferred via TRON, consolidated, and sent to addresses linked to Xinbi Guarantee and the now-defunct Huione Guarantee. Such deals allow digital assets to be exchanged for cash without direct contact with regulated exchanges.
Fragmenting and P2P networks
Another element of the scheme is the fragmentation of large sums. Instead of withdrawing millions of dollars through a single platform, funds are broken down into many small operations. North Korean operators sell stablecoins through P2P marketplaces in batches of approximately $7,000, which allows them to avoid AML monitoring. Transactions are also fragmented to ~$30,000 so that any potential freeze affects only a minor portion of the funds. To speed up the process, pre-prepared wallets with automated asset distribution are used. Endpoints include P2P platforms in South Asia and unregulated crypto exchanges in Latin America.
Ultimately, after several stages, North Korean funds become almost indistinguishable from other criminal cryptocurrency. This creates a serious problem for exchanges and crypto companies: the link to the original attack becomes extremely difficult to establish once assets dissolve into a broad network of criminal intermediaries.
My expert assessment: The main feature of the North Korean model is not the presence of any single "secret" channel, but the ability to embed stolen cryptocurrency into the existing ecosystem of illegal exchangers, P2P networks, and scam projects. This allows North Korea to use others' infrastructure, reducing its own risks and making it many times harder to block funds at the final stages. In May, CertiK analysts rightly noted that North Korea-linked hacker groups have turned cryptocurrency theft into a large-scale state operation with its own laundering infrastructure and a network of IT agents—and current data fully confirms this conclusion.