
Experts from the UK’s Royal United Services Institute (RUSI) found that North Korea increasingly launders stolen cryptocurrency through existing criminal financial networks rather than isolated infrastructure.
The movement of funds involves OTC services, P2P traders, illegal exchanges, mixers, cross-chain bridges, and scam-related platforms.
According to the authors, from January 2024 to September 2025, North Korea stole at least $2.8 billion in virtual assets. The report states that these funds directly support the weapons of mass destruction program. Researchers emphasize that the conversion to fiat is less understood than on-chain laundering.
From Hackers to Criminal Intermediaries
After the initial movement of funds, North Korea may transfer cryptocurrency to third-party launderers. According to ZeroShadow, the laundering process of Bybit funds after a $1.5 billion exchange hack in February 2025 involved a network of OTC and P2P traders, many of whom were Chinese citizens. These intermediaries moved assets around the clock and ultimately helped convert the stolen cryptocurrency into fiat and cash. By September 2025, according to the international monitoring group MSMT, all funds stolen from Bybit had been cashed out.
Cryptocurrency may pass through dozens of addresses and several blockchains, with asset ownership changing multiple times. Researchers note that in some cases, the transition of funds from North Korean operators to third-party launderers can be identified by characteristic changes in transaction behavior.
The Scam Connection
Experts highlighted the connection between North Korean funds and the crypto scam industry. According to RUSI, investigators found signs of mixing North Korean funds with proceeds from “pig butchering” scams—investment schemes where fraudsters first establish trust with victims and then persuade them to invest in fake projects.
So-called guarantee marketplaces play a crucial role—underground platforms, primarily operating through Chinese-language Telegram channels. They offer money laundering services, technical tools, and mediation between participants in illegal operations.
Elliptic discovered instances where cryptocurrency from North Korean-related hacks ended up in closed escrow deals on such platforms. For example, part of the funds from the WazirX attack was transferred through TRON, consolidated, and then sent to addresses associated with Xinbi Guarantee and the now-defunct Huione Guarantee. Such deals potentially allow for exchanging cryptocurrency for cash.
Splitting and P2P
Another element of the scheme is splitting large sums. Instead of withdrawing millions of dollars through a single platform, funds are broken into many smaller transactions. According to a crypto service provider, North Korean operators may sell stablecoins in batches of about $7,000 through P2P marketplaces, receiving cash in return. This amount helps avoid AML monitoring. ZeroShadow also recorded transaction splitting to about $30,000, so that any potential freeze would affect only a small portion of the funds.
Pre-prepared wallets are used to accelerate this process, automatically distributing assets to designated addresses. Researchers identify P2P marketplaces in South Asia and unregulated crypto exchanges in Latin America as endpoints.
As a result, after several stages, North Korean funds become nearly indistinguishable from other criminal cryptocurrency. According to the study’s authors, this creates an additional problem for exchanges and other crypto companies: once funds enter a broad network of criminal intermediaries, tracing back to the original attack becomes significantly more challenging.
RUSI experts believe the main feature of the North Korean model is not the existence of a single “secret” laundering channel, but the ability to integrate stolen cryptocurrency into the existing ecosystem of illegal exchanges, P2P networks, and crypto scams. This allows North Korea to use foreign infrastructure, significantly complicating the blocking of funds in the final stages of conversion to cash.
In May, CertiK analysts concluded that North Korean hacker groups have turned cryptocurrency theft into a large-scale state operation with their own money laundering infrastructure and network of IT agents.
