North Korea is changing how it launders stolen cryptocurrency, according to a new study from the Royal United Services Institute (RUSI). Decrypt reported that the UK think tank found Pyongyang no longer handles stolen digital assets on its own. Instead, it folds those funds into existing transnational criminal ecosystems, making financing tied to nuclear proliferation much harder to distinguish from routine money laundering.
$2.8 billion stolen in two years, with only about 5% recovered
RUSI said North Korea stole about $2.8 billion in cryptocurrency from January 2024 to September 2025. Roughly $1.5 billion of that came from the Bybit incident in February 2025 alone. The report said 95% of the stolen funds had already been moved through decentralized services, while only about 5% was ultimately recovered or frozen. That included around $48.4 million recovered and $30.5 million frozen.
The group behind the Bybit theft was identified as the North Korean hacking unit TraderTraitor. Chain News had previously reported that Bybit filed suit against North Korea and Lazarus to seek recovery tied to what it described as the largest hack on record.
Smaller transfers, proxy accounts, and cash-out routes through Chinese banks
The report laid out a detailed laundering playbook. Stolen crypto was sold at a discount to third parties, then mixed with proceeds from pig-butchering scams before being converted. To avoid bank scrutiny, funds were exchanged on P2P markets in stablecoin transactions of about $7,000 each, while larger sums were broken into chunks of about $30,000.
On the infrastructure side, North Korea was said to have bought large volumes of account credentials from proxies in the Philippines, Indonesia, and China. It also recruited stand-ins to hold and convert accounts, then used UnionPay cards issued by Chinese banks to turn crypto into fiat currency. The report named as many as 19 Chinese banks.
ZeroShadow and U.S. Justice Department actions
Incident response company ZeroShadow said organized crime in China was also involved. The U.S. Department of Justice, for its part, had already seized infrastructure linked to Cambodia-based Huione Group in June 2025.
RUSI’s central warning was straightforward: once North Korea’s state-backed theft operations become deeply intertwined with transnational criminal networks, using sanctions against a single entity to disrupt those money flows becomes increasingly difficult.

