Aug 12, 2026 – North Korean hackers stole at
least $2.8 billion in cryptocurrency between January 2024 and
September 2025, and they are now laundering the proceeds through scam
syndicates and organized crime networks to make the funds harder to trace,
according to a new report from the Royal United Services Institute .
The London-based defense and security think tank said the
regime has built a complex laundering pipeline that spans multiple blockchains,
Chinese-language markets, and traditional banks, increasingly relying on
third-party criminal networks to convert stolen digital assets into fiat
currency .
"The regime has pushed at least $2.8 billion in
stolen virtual assets between January 2024 and September 2025, with researchers
focusing on the moment those assets convert into cash."
— Royal United Services Institute report
The Scale of the Theft
The $2.8 billion figure aligns with estimates from the
Multilateral Sanctions Monitoring Team (MSMT), which reported in October 2025
that North Korea stole approximately **$2.84 billion** in virtual assets during
the same period . U.S. officials have described this as a
"conservative low-end estimate," with the actual number likely
higher .
The breakdown of stolen funds:
- $1.65
billion stolen in 2025 alone
- $1.46
billion from the Bybit exchange in February 2025 — the largest single
crypto heist in history
- $308
million from DMM Bitcoin in Japan
- $234
million from WazirX in India
- $50
million from Radiant Capital
Chainalysis estimated that North Korean hackers
stole $2.02 billion in cryptocurrency in 2025, a 51% year-over-year
increase, with the group now holding more bitcoin than Tesla — funds it stole
rather than bought .
How the Laundering Pipeline Works
The RUSI report focuses on how stolen crypto is converted
into cash, revealing a sophisticated system that makes tracing increasingly
difficult .
Key findings on the laundering process:
1. Third-party bulk purchases: In some cases, third
parties buy entire batches of stolen assets at a discount before the funds are
mixed with scam proceeds or money tied to criminal groups . Elliptic data
suggests these transfers frequently occur on the Bitcoin blockchain .
2. Criminal network overlap: North Korean funds are
increasingly laundered through the same networks used by scam syndicates,
including "pig butchering" investment scams. Once proceeds mix with
scam money, exchanges struggle to separate proliferation finance from ordinary
laundering .
3. Money mules and fragmented cash-outs: The
accounts used to cash out typically belong to mules recruited in the
Philippines, Indonesia, and China, where identities are cheap enough to buy in
bulk . Conversion happens in small slices:
- ~$7,000 in
stablecoins sold at a time on peer-to-peer marketplaces to stay below bank
review thresholds
- Larger
sums broken into $30,000 pieces so any freeze "would not be
overly damaging"
4. Fiat delivery through Chinese banks: OTC brokers
deposit proceeds into North Korean-controlled accounts using UnionPay cards
issued by Chinese banks. The MSMT last year identified 19 Chinese banks used
by the regime and its proxies .
The Lazarus Group's Role
The thefts are attributed to North Korea's Reconnaissance
General Bureau, with sub-clusters tracked as Lazarus Group, APT38,
TraderTraitor, and AppleJeus .
The Bybit hack demonstrated their sophistication:
- Attackers
compromised the SAFE front-end UI that Bybit operations personnel used to
approve transactions
- Replaced
transaction data with a malicious delegatecall that changed the wallet's
implementation contract
- Signers,
seeing what looked like a legitimate transaction on their Ledger screens,
approved it
- Minutes
later, the attacker drained ETH and ERC-20 tokens
The FBI attributed the Bybit theft to TraderTraitor on
February 26, 2025 .
Why This Matters for Crypto
The implications are significant:
- National
security threat: The stolen funds are used to finance North Korea's
nuclear and ballistic missile programs
- Regulatory
scrutiny: The report could accelerate stricter KYC requirements on
OTC desks and peer-to-peer platforms
- Detection
challenges: Once inside criminal ecosystems, proliferation finance
becomes difficult to distinguish from standard money laundering
The recovery challenge is stark: Bybit has recovered
only $48.4 million** and frozen **$30.5 million more — about 5% of
what was stolen .
The Bottom Line
North Korea has built the highest-value sustained
cybercrime campaign in history. The RUSI report reveals that the regime is no
longer just hacking exchanges — it has integrated its theft operations into the
broader criminal economy, making it harder to track, harder to stop, and harder
to recover stolen funds.
For the crypto industry, the report is a reminder that
the same tools that enable borderless, permissionless finance also enable
state-backed criminal enterprises. The methods are evolving. The response must
as well.
CoinaiNews provides independent market analysis and
coverage of cryptocurrency, technology, and financial markets. The information
presented does not constitute financial advice.

0 Comments