North Korea Stole $2.8B in Crypto and Is Now Laundering It Through Crime Networks, RUSI Says

 

North Korean crypto hacking and money laundering network with Bitcoin, blockchain transactions and cybercrime imagery

Aug 12, 2026 – North Korean hackers stole at least $2.8 billion in cryptocurrency between January 2024 and September 2025, and they are now laundering the proceeds through scam syndicates and organized crime networks to make the funds harder to trace, according to a new report from the Royal United Services Institute .

The London-based defense and security think tank said the regime has built a complex laundering pipeline that spans multiple blockchains, Chinese-language markets, and traditional banks, increasingly relying on third-party criminal networks to convert stolen digital assets into fiat currency .

"The regime has pushed at least $2.8 billion in stolen virtual assets between January 2024 and September 2025, with researchers focusing on the moment those assets convert into cash."
— Royal United Services Institute report

 

The Scale of the Theft

The $2.8 billion figure aligns with estimates from the Multilateral Sanctions Monitoring Team (MSMT), which reported in October 2025 that North Korea stole approximately **$2.84 billion** in virtual assets during the same period . U.S. officials have described this as a "conservative low-end estimate," with the actual number likely higher .

The breakdown of stolen funds:

  • $1.65 billion stolen in 2025 alone 
  • $1.46 billion from the Bybit exchange in February 2025 — the largest single crypto heist in history 
  • $308 million from DMM Bitcoin in Japan 
  • $234 million from WazirX in India 
  • $50 million from Radiant Capital 

Chainalysis estimated that North Korean hackers stole $2.02 billion in cryptocurrency in 2025, a 51% year-over-year increase, with the group now holding more bitcoin than Tesla — funds it stole rather than bought .

 

How the Laundering Pipeline Works

The RUSI report focuses on how stolen crypto is converted into cash, revealing a sophisticated system that makes tracing increasingly difficult .

Key findings on the laundering process:

1. Third-party bulk purchases: In some cases, third parties buy entire batches of stolen assets at a discount before the funds are mixed with scam proceeds or money tied to criminal groups . Elliptic data suggests these transfers frequently occur on the Bitcoin blockchain .

2. Criminal network overlap: North Korean funds are increasingly laundered through the same networks used by scam syndicates, including "pig butchering" investment scams. Once proceeds mix with scam money, exchanges struggle to separate proliferation finance from ordinary laundering .

3. Money mules and fragmented cash-outs: The accounts used to cash out typically belong to mules recruited in the Philippines, Indonesia, and China, where identities are cheap enough to buy in bulk . Conversion happens in small slices:

  • ~$7,000 in stablecoins sold at a time on peer-to-peer marketplaces to stay below bank review thresholds 
  • Larger sums broken into $30,000 pieces so any freeze "would not be overly damaging" 

4. Fiat delivery through Chinese banks: OTC brokers deposit proceeds into North Korean-controlled accounts using UnionPay cards issued by Chinese banks. The MSMT last year identified 19 Chinese banks used by the regime and its proxies .

 

The Lazarus Group's Role

The thefts are attributed to North Korea's Reconnaissance General Bureau, with sub-clusters tracked as Lazarus Group, APT38, TraderTraitor, and AppleJeus .

The Bybit hack demonstrated their sophistication:

  • Attackers compromised the SAFE front-end UI that Bybit operations personnel used to approve transactions
  • Replaced transaction data with a malicious delegatecall that changed the wallet's implementation contract
  • Signers, seeing what looked like a legitimate transaction on their Ledger screens, approved it
  • Minutes later, the attacker drained ETH and ERC-20 tokens 

The FBI attributed the Bybit theft to TraderTraitor on February 26, 2025 .

 

Why This Matters for Crypto

The implications are significant:

  • National security threat: The stolen funds are used to finance North Korea's nuclear and ballistic missile programs 
  • Regulatory scrutiny: The report could accelerate stricter KYC requirements on OTC desks and peer-to-peer platforms 
  • Detection challenges: Once inside criminal ecosystems, proliferation finance becomes difficult to distinguish from standard money laundering 

The recovery challenge is stark: Bybit has recovered only $48.4 million** and frozen **$30.5 million more — about 5% of what was stolen .

 

The Bottom Line

North Korea has built the highest-value sustained cybercrime campaign in history. The RUSI report reveals that the regime is no longer just hacking exchanges — it has integrated its theft operations into the broader criminal economy, making it harder to track, harder to stop, and harder to recover stolen funds.

For the crypto industry, the report is a reminder that the same tools that enable borderless, permissionless finance also enable state-backed criminal enterprises. The methods are evolving. The response must as well.


CoinaiNews provides independent market analysis and coverage of cryptocurrency, technology, and financial markets. The information presented does not constitute financial advice.

 

Post a Comment

0 Comments