North Korea Weaponizes Criminal Networks to Launder Billions in Stolen Cryptocurrency: RUSI
A new research paper reveals how North Korea funnels stolen crypto through organized crime syndicates, making it increasingly difficult for compliance teams and law enforcement to trace illicit funds.
Billions Stolen, Funneled Through Organized Crime
North Korea orchestrated the theft of at least $2.8 billion in cryptocurrency between January 2024 and September 2025, according to groundbreaking research published this month by the Royal United Services Institute, a respected British defence and security think tank. The research, conducted by Allison Owen and Noémi También, suggests these digital assets are being diverted to support the regime’s weapons programs. Rather than moving funds directly through decentralized finance protocols—a well-documented path that investigators have learned to track—North Korea has adopted a more sophisticated approach: channeling stolen crypto through the same criminal networks that move proceeds from investment scams and other organized crime activities.
The Criminal Handoff: Where Theft Becomes Invisible
RUSI’s analysis reveals a multi-step laundering process designed to obscure the origins of stolen funds. Before conversion to fiat currency, ownership of the cryptocurrency frequently changes hands. Third parties acquire the stolen coins at substantial discounts, often in transactions that coincide with proceeds from schemes such as “pig butchering” investment frauds, or at addresses connected to entities like Cambodia’s Huione Group, whose infrastructure the Justice Department seized in June. This handoff creates an intentional fog that makes it difficult to distinguish regime-stolen assets from other criminal proceeds.
The complexity intensifies at the conversion stage. Money mules—recruited primarily from the Philippines, Indonesia, and China—facilitate the critical transition from cryptocurrency to cash. These individuals operate accounts nominally in their own names, though they work on behalf of the regime or its intermediaries. Their credentials are purchased in bulk because they cost so little to acquire at scale, enabling rapid account creation across multiple exchanges and peer-to-peer platforms.
The Compliance Challenge: When Proliferation Finance Becomes Indistinguishable From Crime
ZeroShadow incident responders tracking the aftermath of the February 2025 Bybit hack discovered that TraderTraitor, the North Korean group responsible for the massive theft, partnered extensively with Chinese organized crime syndicates to move funds and convert them to usable cash. The regime relies on a sprawling network of over-the-counter desks, peer-to-peer traders, and launderers—many working around the clock—to process the stolen billions into conventional currency.
This deliberate blending of North Korean proliferation finance with conventional organized-crime money laundering creates a critical problem for compliance teams worldwide: once regime proceeds enter criminal ecosystems, the telltale markers of state-sponsored theft become virtually indistinguishable from routine money laundering. Transactions are deliberately fragmented—roughly $7,000 portions of stablecoins sold on peer-to-peer markets to stay below thresholds that trigger banking review—while larger conversions are split into $30,000 chunks to minimize the impact of potential account freezes.
As North Korea’s sophisticated laundering operation demonstrates, the cryptocurrency industry’s future depends on building compliance infrastructure capable of distinguishing legitimate transactions from state-sponsored theft and organized crime.
Source: RUSI, via Decrypt. Not financial advice.