Summary

  • According to a recent report by the Royal United Services Institute (RUSI), North Korea has stolen at least $2.8 billion in cryptocurrency from January 2024 to September 2025, increasingly using organized crime networks for laundering.
  • Stolen assets are sometimes sold at a discount to third parties, or they appear mixed with funds from investment scams.
  • Cashing out often involves money mules from the Philippines, Indonesia, and China, who are recruited due to their cheap credentials.

A recent study by the Royal United Services Institute, a British defense and security think tank, reveals that North Korea is increasingly utilizing the same laundering networks as organized crime syndicates to process stolen cryptocurrency, complicating tracking efforts for investigators.

The regime is estimated to have taken at least $2.8 billion in digital assets between January 2024 and September 2025, with the report suggesting that these funds are likely used to support its weapons development program. Authors Allison Owen and Noémi També emphasize the conversion of these funds into cash rather than the well-known pathways through decentralized services.

Ownership of the stolen cryptocurrency often changes hands before it is converted, with some third parties purchasing these coins at discounted rates. One investigator noted that such transfers can be identified when stolen funds are found mixed with proceeds from schemes like "pig butchering" investment scams or associated with entities like Cambodia's Huione Group, which had its infrastructure seized by the Justice Department in June. Elliptic, which contributed data to the research, suggests that these transactions frequently occur on the Bitcoin blockchain.

Following the February 2025 Bybit hack, the incident response team at ZeroShadow discovered that North Korea was relying on a network of money launderers, over-the-counter brokers, and peer-to-peer traders, often involving Chinese nationals working continuously. The North Korean group responsible for the hack, TraderTraitor, utilized Chinese organized crime networks to facilitate the movement of funds and return cash.

This overlap presents a challenge for compliance teams, as the regime's illicit funds become intertwined with criminal networks, making it difficult to distinguish between financing for proliferation and regular money laundering.

Money Mules and Small Transactions

The accounts used to cash out the stolen funds typically belong to other individuals, with mules primarily sourced from the Philippines, Indonesia, and China, where credentials are inexpensive and can be acquired in bulk to open multiple accounts. Sources indicate that mules often claim they do not wish to know the true nature of their employers' operations.

Conversion of the stolen assets is done in small increments, with transactions of around $7,000 in stablecoins occurring on peer-to-peer platforms, which helps them avoid triggering bank scrutiny. ZeroShadow also reported that larger amounts are split into chunks of $30,000 to minimize the impact of potential freezes. Additional behaviors observed at exchanges, such as the use of Astrill VPNs and the filing of numerous support tickets by launderers, provide further clues about these activities.

Accessing Cash

The cashing out process rarely involves straightforward bank transfers, as proceeds from over-the-counter brokers are often funneled into accounts controlled by North Korea using UnionPay cards issued by Chinese banks. The report identifies 19 Chinese banks previously noted by the Multilateral Sanctions Monitoring Team as being utilized by the regime and its affiliates.

Of the approximately $1.5 billion taken from Bybit, 95% was processed through decentralized platforms, with the monitoring team confirming that all of it had been converted into fiat or hard currency by September 2025.

The authors advocate for enhanced regulatory frameworks concerning correspondent relationships between exchanges, standardized onboarding processes, secure channels for intelligence sharing, and the inclusion of a Virtual Asset Service Provider (VASP) identifier in payment messages to aid banks in identifying such transactions.

The situation for victims is starkly illustrated by Bybit's recent announcements: the exchange revealed on Monday that it has taken legal action against North Korea, successfully freezing identified assets and recovering $48.4 million, while also freezing an additional $30.5 million, amounting to roughly 5% of the total stolen funds.

Daily Debrief Newsletter

Stay updated with the latest news and original features delivered daily, including podcasts and videos.