North Korea Now Launders Stolen Crypto Through Criminal Networks, RUSI Report Finds

Silhouetted hacker in a dark server room with streams of digital coins flowing through a network, illustrating North Korea's crypto laundering pipeline


North Korea Now Launders Stolen Crypto Through Criminal Networks, RUSI Report Finds

North Korea has stopped trying to launder its stolen cryptocurrency alone. According to a new report from the London-based Royal United Services Institute (RUSI), the country's cyber operatives now push billions of dollars in hacked digital assets through the same criminal financial networks used by scam syndicates and organized crime — Chinese money launderers, over-the-counter (OTC) desks, peer-to-peer traders, and armies of low-cost money mules.

The finding matters because it changes the rules of the game for investigators. Instead of chasing a single secret laundering channel, defenders now face stolen funds being absorbed into an existing underground economy that spans blockchains, Chinese-language Telegram markets, and traditional banks.

What Happened

The RUSI report, published in August 2026, estimates that North Korea stole at least $2.8 billion in virtual assets between January 2024 and September 2025 — roughly 3.96 trillion Korean won. More striking than the headline figure is how the money moved afterward.

"North Korea depended on a network comprising money launderers, over-the-counter traders, and peer-to-peer traders for cash conversion," the report states, adding that "most of these facilitators were Chinese nationals working around the clock to move funds."

This is a deliberate strategic shift. Earlier heists were often followed by a recognizable pattern of mixing and bridge-hopping tied to known North Korean wallets. Today, the regime increasingly hands assets to third-party laundering groups — including Chinese crime syndicates — which then convert them to cash using infrastructure the state never has to build or control directly.

How the Laundering Pipeline Works

The report describes a multi-stage pipeline that makes stolen crypto progressively harder to trace:

Layering Through Illicit Services

Immediately after a theft, funds are moved through cross-chain bridges, no-knowledge-verification swaps, and mixing protocols to fragment and obscure the trail. Chainalysis data shows the DPRK prefers Chinese-language money movement services and typically works in tranches of under $500,000, following a distinct 45-day laundering cycle after major heists.

Handoff to Criminal Facilitators

Once the trail is scrambled, assets are transferred to third-party launderers. These facilitators run OTC desks and P2P operations, often staffed around the clock, that convert cryptocurrency into fiat currency in small, smurfed transfers designed to avoid triggering bank alerts.

Money Mules by the Thousands

At the bottom of the pipeline sit money mules recruited mainly in the Philippines, Indonesia, and China, where bank credentials sell cheaply enough to be purchased in bulk. The report notes that account holders for cash-out operations frequently originate from those countries, giving launderers a rotating pool of disposable banking identities.

Cash-Out Through Traditional Banking Rails

The final stage moves funds into the conventional financial system. Citing the Multilateral Sanctions Monitoring Team (MSMT) — a body comprising 11 countries including South Korea, the United States, and Japan — the report says fiat currency received from OTC traders is often deposited into North Korea-controlled bank accounts via UnionPay cards issued by Chinese banks.

The Role of 'Guarantee Marketplaces'

A distinctive feature of the new model is the so-called guarantee marketplace — underground platforms, primarily operating through Chinese-language Telegram channels, that broker trust between parties in illegal transactions. These marketplaces offer money laundering services, technical tools, and mediation, effectively industrializing the process of moving stolen funds.

RUSI analysts argue the defining characteristic of the North Korean model is not a single secret channel but the ability to integrate stolen cryptocurrency into the existing ecosystem of illegal exchanges, P2P networks, and crypto scams. This allows Pyongyang to use foreign infrastructure while complicating the blocking of funds in the final cash-out stages.

The Bybit Connection

The report points to the February 2025 Bybit hack — the largest single crypto theft on record — as a turning point. Incident responders at ZeroShadow found the regime relying on a network of launderers, OTC desks, and P2P traders in the aftermath, with TraderTraitor, the North Korean group behind the theft, working with Chinese organized crime groups to move the money and return cash.

Russia also plays a supporting role. According to MSMT blockchain analysis cited in the report, DPRK actors worked with a Russia-based broker to cash out at least $60 million in cryptocurrency, including some funds stolen in the Bybit heist.

Why It Matters

The scale of the problem is growing, not shrinking. Chainalysis estimates that North Korean hackers stole $2.02 billion in cryptocurrency during 2025 alone — a 51 percent year-over-year increase that pushed their all-time total past $6.75 billion — despite a dramatic reduction in the number of attacks.

  • Sanctions evasion at scale: The laundering pipeline converts stolen assets into usable fiat, funding state programs that remain under international sanctions.
  • Harder attribution: When funds pass through third-party criminal networks, linking them back to the DPRK becomes significantly more difficult for exchanges and investigators.
  • Blurred lines with cybercrime: North Korea's integration into the broader criminal economy means takedowns of scam infrastructure now double as takedowns of state-sponsored laundering capacity — and vice versa.

What the Industry and Regulators Can Do

The report offers no silver bullet, but it points to concrete pressure points along the pipeline:

  1. Disrupt the cash-out stage. Since mule accounts are the weakest link, banks and exchanges should improve detection of smurfed transfers and flag accounts linked to high-risk jurisdictions.
  2. Target guarantee marketplaces. Coordinated takedowns of Chinese-language Telegram laundering markets, alongside scam infrastructure, would raise the cost of moving stolen funds.
  3. Strengthen OTC and P2P oversight. Regulators should push for transaction reporting from OTC desks and P2P platforms, which currently operate in a regulatory gray zone in much of Asia.
  4. Share intelligence faster. The MSMT model works; expanding it to more jurisdictions and speeding up the exchange of wallet blacklists would shorten the window in which stolen funds can be moved.

The Bigger Lesson

North Korea's evolution from lone-wolf hacker operations to a buyer of laundering services reflects a broader truth about the crypto underground: expertise is now a commodity. The regime does not need to build its own mule networks or Telegram markets — it can rent them from a criminal economy that already exists, at a price measured in stolen digital assets.

For defenders, that means the fight is no longer about tracking one adversary's infrastructure. It is about hardening the entire ecosystem of financial intermediaries, from no-KYC swaps to rural bank accounts in Southeast Asia, against a customer that pays in other people's money.

Until that ecosystem closes its seams, the $2.8 billion figure will likely keep climbing.

Previous Post Next Post