North Korea is increasingly pushing stolen cryptocurrency through the same laundering networks used by scam syndicates and organized crime, obscuring the trail investigators rely on, according to a research paper published this month by the Royal United Services Institute (RUSI), a British defense and security think tank.

The paper says the regime stole at least $2.8 billion in virtual assets between January 2024 and September 2025. Those funds are assumed in the paper to support its weapons program. Authors Allison Owen and Noémi També focus on the point where the money is converted into cash, rather than the better-documented movement of funds through decentralized services.
Ownership changes before cash-out
The researchers say ownership often changes hands before stolen assets are converted. In some cases, a third party buys the stolen coins outright at a discount. One investigator told the authors that such a handoff can be inferred when the funds later appear mixed with proceeds from activities such as pig-butchering investment scams, or at addresses tied to entities linked to Cambodia’s Huione Group. The U.S. Department of Justice seized Huione-related infrastructure in June.
Elliptic, which supplied data for the paper, believes those handoffs often happen on the Bitcoin blockchain.
Bybit hack highlighted overlap with organized crime
After the February 2025 Bybit hack, incident responders at ZeroShadow found that the regime was relying on a network of launderers, over-the-counter desks, and peer-to-peer traders. The paper says many of those operators were Chinese nationals working around the clock.
According to the study, TraderTraitor, the North Korean group behind the theft, used Chinese organized crime groups to move the money and return cash at the end of the process.
That overlap is the core compliance problem raised by the paper. Once North Korean proceeds enter broader criminal ecosystems, signs associated with proliferation finance become difficult to separate from ordinary laundering activity.
Mule accounts and fragmented transfers
The accounts used for cashing out usually belong to someone else. The paper says mules are recruited mainly in the Philippines, Indonesia, and China, where credentials are cheap enough to buy in bulk and use to open accounts at scale. Interviewees said the people acting as mules are typically told little about who they are really working for and often want no deeper involvement.
Cash-out activity is broken into small pieces. Actors sell roughly $7,000 of stablecoins at a time on peer-to-peer marketplaces, staying below thresholds that would trigger bank review. ZeroShadow also found larger sums split into $30,000 chunks so that a freeze "would not be overly impactful."
The paper says exchange-side behavior provides more signals. Examples include logins through Astrill VPN and the fact that launderers now file 50 to 70 support tickets to get a single held transaction released.
How proceeds reach fiat
Fiat does not usually arrive through a simple bank transfer, the paper says. Instead, proceeds from OTC brokers are often deposited into North Korea-controlled accounts using UnionPay cards issued by Chinese banks.
The paper lists 19 Chinese banks that the Multilateral Sanctions Monitoring Team identified last year as having been used by the regime and its proxies.
Of the roughly $1.5 billion stolen from Bybit, 95% moved through decentralized services. The monitoring team reported that by September 2025, all of it had been converted into fiat or hard currency.
Regulatory proposals and recovery efforts
The authors call for regulatory guidance on correspondent relationships between exchanges, standardized onboarding questionnaires, secure intelligence-sharing channels, and a virtual asset service provider, or VASP, identifier in payment messages so receiving banks can recognize those transfers.
The paper also shows what recovery looks like for victims. Bybit said on Monday that it had sued North Korea and obtained an order freezing identified assets. The exchange said it had recovered $48.4 million and frozen another $30.5 million, together about 5% of the amount taken.

