RUSI says North Korea is using criminal laundering networks to cash out stolen crypto

RUSI says North Korea is using criminal laundering networks to cash out stolen crypto

N
News Editor
2026-08-11 12:02:42
A new paper from the Royal United Services Institute says North Korea is increasingly routing stolen cryptocurrency through the same laundering channels used by scam syndicates and organized crime, making it harder for investigators and compliance teams to distinguish proliferation-linked funds from routine criminal proceeds. The researchers estimate the regime stole at least $2.8 billion in virtual assets between January 2024 and September 2025, and they focus on the moment those assets are turned into cash rather than their already well-documented movement through decentralized services. The paper points to handoffs to third parties, use of mule accounts in the Philippines, Indonesia, and China, and repeated sales of small stablecoin amounts on peer-to-peer markets to stay below bank review thresholds. It also cites findings tied to the February 2025 Bybit hack, where incident responders said North Korea’s TraderTraitor group relied on launderers, OTC desks, and P2P traders, often Chinese nationals, to move funds and return cash. The paper also references U.S. action against infrastructure linked to Cambodia’s Huione Group and notes that Bybit has recovered or frozen only about 5% of the assets taken.

North Korea is increasingly pushing stolen cryptocurrency through the same laundering networks used by scam syndicates and organized crime, obscuring the trail investigators rely on, according to a research paper published this month by the Royal United Services Institute (RUSI), a British defense and security think tank.

RUSI says North Korea is using criminal laundering networks to cash out stolen crypto 2

The paper says the regime stole at least $2.8 billion in virtual assets between January 2024 and September 2025. Those funds are assumed in the paper to support its weapons program. Authors Allison Owen and Noémi També focus on the point where the money is converted into cash, rather than the better-documented movement of funds through decentralized services.

Ownership changes before cash-out

The researchers say ownership often changes hands before stolen assets are converted. In some cases, a third party buys the stolen coins outright at a discount. One investigator told the authors that such a handoff can be inferred when the funds later appear mixed with proceeds from activities such as pig-butchering investment scams, or at addresses tied to entities linked to Cambodia’s Huione Group. The U.S. Department of Justice seized Huione-related infrastructure in June.

Elliptic, which supplied data for the paper, believes those handoffs often happen on the Bitcoin blockchain.

Bybit hack highlighted overlap with organized crime

After the February 2025 Bybit hack, incident responders at ZeroShadow found that the regime was relying on a network of launderers, over-the-counter desks, and peer-to-peer traders. The paper says many of those operators were Chinese nationals working around the clock.

According to the study, TraderTraitor, the North Korean group behind the theft, used Chinese organized crime groups to move the money and return cash at the end of the process.

That overlap is the core compliance problem raised by the paper. Once North Korean proceeds enter broader criminal ecosystems, signs associated with proliferation finance become difficult to separate from ordinary laundering activity.

Mule accounts and fragmented transfers

The accounts used for cashing out usually belong to someone else. The paper says mules are recruited mainly in the Philippines, Indonesia, and China, where credentials are cheap enough to buy in bulk and use to open accounts at scale. Interviewees said the people acting as mules are typically told little about who they are really working for and often want no deeper involvement.

Cash-out activity is broken into small pieces. Actors sell roughly $7,000 of stablecoins at a time on peer-to-peer marketplaces, staying below thresholds that would trigger bank review. ZeroShadow also found larger sums split into $30,000 chunks so that a freeze "would not be overly impactful."

The paper says exchange-side behavior provides more signals. Examples include logins through Astrill VPN and the fact that launderers now file 50 to 70 support tickets to get a single held transaction released.

How proceeds reach fiat

Fiat does not usually arrive through a simple bank transfer, the paper says. Instead, proceeds from OTC brokers are often deposited into North Korea-controlled accounts using UnionPay cards issued by Chinese banks.

The paper lists 19 Chinese banks that the Multilateral Sanctions Monitoring Team identified last year as having been used by the regime and its proxies.

Of the roughly $1.5 billion stolen from Bybit, 95% moved through decentralized services. The monitoring team reported that by September 2025, all of it had been converted into fiat or hard currency.

Regulatory proposals and recovery efforts

The authors call for regulatory guidance on correspondent relationships between exchanges, standardized onboarding questionnaires, secure intelligence-sharing channels, and a virtual asset service provider, or VASP, identifier in payment messages so receiving banks can recognize those transfers.

The paper also shows what recovery looks like for victims. Bybit said on Monday that it had sued North Korea and obtained an order freezing identified assets. The exchange said it had recovered $48.4 million and frozen another $30.5 million, together about 5% of the amount taken.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
80

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.