NewsCryptoNorth Korea Increasingly Uses Organized Crime Networks to Launder Stolen Crypto, RUSI Paper Finds

North Korea Increasingly Uses Organized Crime Networks to Launder Stolen Crypto, RUSI Paper Finds

Author: Decrypt·

Key Takeaways

  • North Korea stole at least $2.8 billion in cryptocurrency between January 2024 and September 2025, with proceeds believed to support the country's weapons programme.
  • Stolen digital assets are converted into fiat currency through human networks including money mules recruited primarily in the Philippines, Indonesia, and China, as well as Chinese organized crime groups.
  • Launderers deliberately conduct conversions in small increments—approximately $7,000 in stablecoins at a time—to stay below thresholds that would trigger bank scrutiny.
  • The Multilateral Sanctions Monitoring Team has identified 19 Chinese banks whose UnionPay cards are used to deposit illicit proceeds into North Korean-controlled accounts.
  • Bybit has sued North Korea over the February 2025 hack, recovering $48.4 million and freezing an additional $30.5 million, representing roughly 5% of the $1.5 billion stolen.
North Korea Increasingly Uses Organized Crime Networks to Launder Stolen Crypto, RUSI Paper Finds

North Korea stole at least $2.8 billion in cryptocurrency between January 2024 and September 2025 and is increasingly laundering those funds through the same networks used by scam syndicates and organized crime, according to a research paper published this month by the Royal United Services Institute (RUSI), a British defence and security think tank. The figure represents a significant share of all cryptocurrency stolen globally during that period and underscores the growing role of digital asset theft as a revenue stream for the heavily sanctioned state.

The paper, authored by Allison Owen and Noémi També, shifts focus to the point where stolen digital assets are converted into fiat currency — a stage that has received less attention than the well-documented flow of funds through decentralized services such as mixers and cross-chain bridges. Because transactions on public blockchains are traceable by design, much of the prior research and enforcement effort has focused on on-chain laundering. The harder problem, the paper argues, is the final step: turning cryptocurrency into spendable cash through human networks that operate largely outside the visibility of blockchain analytics.

According to the report, the stolen proceeds are assumed to support North Korea's weapons programme — a category of illicit finance known as proliferation finance, which the Financial Action Task Force, the global anti-money-laundering watchdog, identifies as among the most serious threats to the international financial system.

Ownership Transfers Before Cashing Out

Ownership of stolen cryptocurrency frequently changes hands before conversion, the paper finds. Third parties sometimes purchase the stolen coins outright at a discount. One investigator told the authors that such handovers can be detected when funds surface mixed with proceeds from "pig butchering" investment scams, or at addresses linked to entities such as Cambodia's Huione Group, whose infrastructure the U.S. Justice Department seized in June. Elliptic, the blockchain analytics firm that supplied data for the research, assesses that these handovers frequently occur on the Bitcoin blockchain.

After the February 2025 Bybit hack — at approximately $1.5 billion, the largest cryptocurrency exchange theft on record — incident responders at ZeroShadow observed the regime relying on a network of launderers, over-the-counter desks, and peer-to-peer traders — often Chinese nationals operating around the clock. TraderTraitor, the North Korean group responsible for the Bybit theft, reportedly used Chinese organized crime groups to move funds and return cash.

This overlap between state-sponsored theft and transnational criminal networks presents a significant challenge for compliance teams. Once North Korea's proceeds enter criminal ecosystems, the indicators of proliferation finance become difficult to distinguish from ordinary money laundering activity, complicating the obligations that banks and exchanges face under international sanctions regimes.

Money Mules and Structured Conversions

The accounts used for cashing out typically belong to money mules recruited mainly in the Philippines, Indonesia, and China, where banking credentials are inexpensive enough to acquire in bulk and open accounts at scale. Interviewees told the authors that once mules learn who they are actually working for, they generally wish to discontinue their involvement.

Conversions are carried out in small increments. Actors sell approximately $7,000 in stablecoins at a time on peer-to-peer marketplaces, staying below thresholds that would trigger bank review. ZeroShadow also found that larger sums were broken into $30,000 chunks so that a potential freeze "would not be overly impactful." Further behavioral signals appear at the exchange level, including Astrill VPN logins and the 50 to 70 support tickets that launderers now file to get a single held transaction released.

Reaching Fiat Currency

Fiat proceeds rarely arrive through straightforward bank transfers. Instead, funds from over-the-counter brokers are often deposited into North Korean-controlled accounts using UnionPay cards issued by Chinese banks. The paper identifies 19 Chinese banks that the Multilateral Sanctions Monitoring Team flagged last year as being used by the regime and its proxies. The team, composed of member states including the United States, South Korea, and Japan, was formed to continue sanctions monitoring after the mandate of the United Nations Panel of Experts expired in April 2025.

Of the roughly $1.5 billion stolen from Bybit, 95% moved through decentralized services. The monitoring team reported that all of those funds had been converted into fiat or hard currency by September 2025.

Recommendations and Victim Recovery

The authors call for regulatory guidance on correspondent relationships between exchanges, standardized onboarding questionnaires, secure intelligence-sharing channels, and the inclusion of a Virtual Asset Service Provider (VASP) identifier in payment messages so receiving banks can identify them.

The practical outcome for victims is stark. Bybit announced Monday that it had sued North Korea and obtained a court order freezing identified assets. The exchange has recovered $48.4 million and frozen an additional $30.5 million — together representing approximately 5% of the total amount stolen.