Experts from the Royal United Services Institute (RUSI) have found that North Korea is increasingly using established criminal financial networks, rather than isolated infrastructure, to launder stolen cryptocurrency.

The pathways for moving these funds include over-the-counter (OTC) services, peer-to-peer (P2P) traders, illegal exchanges, mixers, cross-chain bridges, and scam-related platforms.

According to the authors, from January 2024 to September 2025, North Korea is estimated to have stolen at least $2.8 billion in virtual assets. The report states that these funds directly support the country's weapons of mass destruction program. Researchers point out that the conversion to fiat money is less understood than on-chain laundering.

From Hackers to Criminal Intermediaries

After the initial transfer of funds, North Korea can hand over cryptocurrency to external money launderers. According to ZeroShadow, during the laundering process following a $1.5 billion hack of the Bybit exchange in February 2025, an OTC and P2P trading network—many members of which were Chinese nationals—was involved. These intermediaries operated around the clock to move assets and ultimately helped convert the stolen cryptocurrency into fiat and cash. By September 2025, all funds stolen from Bybit had reportedly been cashed out, according to the international monitoring group MSMT.

Throughout this process, the cryptocurrency can pass through dozens of addresses and multiple blockchains, with ownership of the assets frequently changing hands. Researchers note that in some instances, the transfer of funds from North Korean operators to external launderers can be traced by characteristic changes in transaction behavior.

Identifying the Scam

Experts have highlighted the connection between North Korean funds and the crypto scam industry. RUSI reports that investigators have discovered signs of North Korean funds being mixed with proceeds from "pig butchering" scams—investment schemes where perpetrators build trust with victims before convincing them to invest in fake projects.

Significant roles are played by so-called guarantee marketplaces—underground platforms primarily operating in Chinese through Telegram. These platforms offer money-laundering services, technical tools, and mediation between participants in illegal operations.

Elliptic has identified instances where cryptocurrency from North Korean-related hacks has entered closed escrow deals on such platforms. For example, part of the funds from the WazirX attack was transferred via TRON, consolidated, and then sent to addresses linked to Xinbi Guarantee and the now-defunct Huione Guarantee. Such transactions potentially allow for the exchange of cryptocurrency for cash.

Breaking It Down and P2P Transactions

Another component of the scheme involves breaking down large sums. Instead of directly withdrawing millions of dollars through a single platform, funds are divided into numerous smaller transactions. According to one crypto service provider, North Korean operators may sell stablecoins in batches of about $7,000 on P2P marketplaces, receiving cash in return. This amount helps avoid AML monitoring. ZeroShadow has also recorded transaction breakdowns to around $30,000 to ensure that any potential freezing would only affect a small part of the funds.

To expedite this process, pre-prepared wallets are used, which can automatically distribute assets to specified addresses. Among the endpoints identified by researchers are P2P marketplaces in South Asia and unregulated crypto exchanges in Latin America.

As a result, after several stages, North Korean funds become nearly indistinguishable from other criminal cryptocurrencies. This, according to the study's authors, poses an additional challenge for exchanges and other crypto companies: once the funds have entered a broad network of criminal intermediaries, it becomes significantly harder to trace them back to the original attack.

Experts at RUSI believe that the main feature of the North Korean model is not the existence of a single "secret" laundering channel, but rather the ability to integrate stolen cryptocurrency into an already existing ecosystem of illegal exchangers, P2P networks, and crypto scams. This allows North Korea to utilize external infrastructure and significantly complicates the blocking of funds at the final stages of their conversion into cash.

As a reminder, in May, analysts at CertiK concluded that North Korean hacker groups have transformed cryptocurrency theft into a large-scale state operation, complete with their own money laundering infrastructure and a network of IT agents.