NewsCryptoHow North Korea-Linked Crypto Hackers Launder Stolen Funds

How North Korea-Linked Crypto Hackers Launder Stolen Funds

Author: CryptoDaily·

Key Takeaways

  • •TRM Labs said the largest H1 2026 crypto heists often moved stolen funds through bridges first, followed by no-KYC swaps and later OTC or peer-to-peer cash-out routes.
  • •The Drift and KelpDAO incidents in April totaled about $577 million combined, making up the bulk of stolen value in the first half of 2026.
  • •Attackers commonly split funds into smaller transfers, convert them into liquid stablecoins or major cryptoassets, and reconsolidate them before cashing out.
  • •Canada’s FINTRAC issued a July 15, 2026 advisory urging enhanced screening and reporting for potential DPRK-linked sanctions-evasion activity.
  • •TRM Labs assessed that roughly 66% of H1 2026 crypto hack losses were connected to DPRK-linked activity.
How North Korea-Linked Crypto Hackers Launder Stolen Funds

North Korea-linked cryptocurrency hacking groups are using faster, more cross-chain laundering methods that can make stolen funds harder to intercept in the first hour after an exploit. According to blockchain analytics firm TRM Labs, the largest crypto heists in the first half of 2026 commonly followed a route built around bridges, no-KYC swaps, fragmentation, stablecoin consolidation and over-the-counter cash-out networks.

The typical pattern begins with funds drained from an exploit and sent to fresh, unlabeled addresses. The assets are then moved through cross-chain bridges and no-KYC swap services to break simple tracing heuristics, split into smaller transfers, converted into liquid stablecoins or major cryptoassets, and eventually cashed out through OTC brokers or peer-to-peer channels. Those brokers may convert the proceeds into U.S. dollars or yuan in smaller transfers intended to avoid attention.

TRM Labs said this approach dominated the largest 2026 heists. The method relies on speed, chain-hopping and counterparties that operate outside strict know-your-customer perimeters. The main sequence is: bridge first, swap often, fragment amounts, reconsolidate, prefer liquid stablecoins for exit after several hops, and use OTC or P2P cash-out rails with smurfed transfers. The time between exploit and bridge use is often short, making fast escalation critical for exchanges, protocols and investigators.

How a DPRK-Linked Laundering Run Typically Works

A laundering run usually starts with a compromise. The initial breach may involve a validator key leak, a bridge vulnerability or a governance permissions failure. After the compromise, the attacker drains funds to new addresses with no clear labels. That first transfer can be rapid and disorderly, but its immediate purpose is to remove the assets from the victim’s direct control.

The next phase is the scramble. Funds move to one or more cross-chain bridges, which provide both liquidity and distance from the source chain. Moving assets away from the original chain weakens heuristics that rely on chain-specific context. From there, funds may pass through no-KYC swap aggregators or high-liquidity decentralized exchanges to convert into stablecoins and other liquid assets. Amounts are divided into smaller packets and may be peeled through multiple wallets before being brought back together.

The final stage is the exit. After enough movement has been created on-chain, the flows often reach a human counterparty. That party is commonly an OTC broker willing to accept stablecoins and return fiat, or a broker that provides prefunded exchange accounts and cash-out services. According to CoinDesk, recent arrests in North Korea referenced cash conversions into U.S. dollars and yuan through Chinese OTC brokers, with transfers intentionally split into small amounts to remain under the radar.

The first hour is especially important. If stolen funds clear one or two bridges and reach liquid stablecoins, the window to freeze assets can narrow to minutes rather than days. Compliance and incident-response teams need contact lists and escalation plans ready before an exploit occurs.

Why April’s Exploits Drove H1 Losses

Infrastructure-level exploits can move large sums in a single incident. In April, the Drift and KelpDAO incidents together totaled roughly $577 million, with about $285 million and $292 million respectively. TRM Labs counted those two incidents as the bulk of stolen value in the first half of 2026 and assessed that about 66% of H1 2026 hack losses overall were tied to DPRK-linked activity.

Large drains compress the laundering timeline. Attackers typically do not leave nine-figure balances idle. They move quickly into bridges and no-KYC swaps, then divide flows into thinner strands. That early sorting and slicing can create sudden volume spikes on a small number of bridges, followed by a haze of mid-sized transfers across wallets and chains. The mechanics favor the party that acts faster.

The April incidents also focused attention on core crypto infrastructure. When bridges and staking wrappers are compromised or used as first-hop laundering routes, defenders can be forced into a reactive position. As a result, April saw fewer incidents but a disproportionately large dollar impact, consistent with the analytics reported for the year.

Bridges, No-KYC Swaps, Mixers and OTC Brokers

Cross-chain bridges and no-KYC swaps function as obfuscation tools. A bridge moves assets between chains, but it also changes the investigative context. Heuristics connected to the source chain lose precision once assets are moved elsewhere. No-KYC swaps and decentralized exchange aggregators extend that effect by converting assets without centralized onboarding requirements, often across several hops.

The main tools play different roles:

ToolPrimary roleObfuscation strengthBottlenecksCompliance risk
Cross-chain bridgeHop chains and escape heuristicsModerate to high when fast and splitLiquidity, bridge monitoring, pausingMedium; some bridges collaborate with law enforcement
No-KYC swap or DEXConvert assets without a centralized exchangeHigh if multi-hop and fragmentedSlippage, MEV leakage, on-chain surveillanceMedium; front ends may geoblock, but contracts do not
Mixers or tumblersBreak address links through pooled fundsVariable; larger pools help, while sanctions shrink optionsSanctions risk and pool sizeHigh if designated or sanctioned
OTC brokersFiat off-ramp and reconsolidationHigh if final settlement occurs off-ledgerKYC pressure and cash logisticsHigh; counterparty screening is a weak point

TRM Labs noted that the largest H1 heists routinely followed an order of bridge first, swap second and then onward movement to exchanges or OTC channels. Mixers have not disappeared, but bridges and swaps can be faster and do not depend on pool depth or sanctions lists in the same way.

Every additional hop gives the attacker more time. For defenders, the objective is to interrupt the route earlier, ideally before the second or third conversion into stablecoins.

Where Cash-Out Points Appear

Most laundering flows ultimately require a broker. OTC desks connect the crypto economy with the cash economy. They may take on the risk of handling tainted assets in exchange for fees and speed, using networks of shell accounts, money mules or cooperating exchangers.

CoinDesk’s reporting on July arrests in North Korea described suspects allegedly converting crypto into U.S. dollars and yuan through Chinese OTC brokers. Transfers were split into smaller amounts to avoid alarms. That pattern aligns with what analytics firms have said for years: on-chain layering can buy time, while off-chain layering attempts to end the trace.

Stablecoins are often used because they make pricing and settlement easier. However, cash-out desks generally follow liquidity. If demand exists for a specific token pair or banking corridor, funds may be routed accordingly. The risk surface lies in the broker’s network and screening practices, not only in the asset being used.

Signals Compliance Teams Monitor

Compliance teams are trying to respond to laundering patterns that move quickly. Useful indicators must fire fast while keeping false positives low enough to support action. Teams often combine machine-learning systems with simpler rules-based heuristics, and small transfers require attention because they may indicate smurfing.

Key signals include:

  • A fresh address moving to a bridge within minutes of a known exploit.
  • Multi-bridge chain-hopping within 12 hours, especially into high-liquidity stablecoins.
  • Bursts of small, regular transfers to broker-linked deposit addresses.
  • Patterns that match historical DPRK tactics, techniques and procedures logged by analytics vendors.
  • Use of specific no-KYC swap front ends shortly after a major incident.
  • Reconsolidation of split funds into a small number of exit wallets before off-ramping.

Regulatory guidance also intensified during the summer. Canada’s FINTRAC reiterated FATF concerns and urged enhanced anti-money-laundering and counter-terrorist-financing measures for potential DPRK-linked transactions on July 15, 2026. Reporting entities operating in that perimeter are expected to heighten screening for sanctions-evasion risk and report anomalies accordingly. FINTRAC’s advisory is available here.

No detection approach is perfect. However, a combination of a fast exploit watchlist, bridge-activity alerts, OTC deposit-label maps and a real 24/7 escalation path can improve the odds of intervention.

Regulatory and Analytics Response in 2026

Two developments stand out in 2026. First, analytics firms have been more explicit about the laundering routes used after major exploits. TRM Labs said bridges and no-KYC swaps were central to the largest H1 heists, giving exchanges and protocols clearer priorities for monitoring and response. TRM Labs’ H1 2026 crypto hack analysis is available here.

Second, regulators tightened their focus on sanctions risk. FINTRAC’s July advisory renewed pressure on reporting entities to screen for DPRK exposure and escalate red flags. Internationally, that direction is consistent with broader FATF messaging on beneficial ownership, cross-chain monitoring and OTC off-ramp gaps. Enforcement is not uniform across jurisdictions, but the policy direction is clear.

Coordination has also improved behind the scenes. Exchanges can coordinate more quickly on freezes, some bridges can pause or throttle suspicious flows, and incident-response channels are less improvised than they were several years ago. These measures do not prevent every attack, but they reduce the period during which launderers can move funds with little interference.

TRM Labs’ H1 2026 chart of monthly value stolen by attack vector showed that April’s infrastructure and key-compromise thefts, including Drift and KelpDAO, concentrated the bulk of stolen dollars and illustrated the laundering-attack-vector concentration investigators must trace.

Steps Protocols, Exchanges and Users Can Take

Protocols do not need new cryptography to make laundering harder. They need practical controls that reduce exploit size and slow unauthorized movement. Useful measures include rate limits on sensitive contract functions, time-locked administrative actions, emergency pause mechanisms, external audits and live bug bounties. Key management should be treated like production secrets.

Exchanges and OTC desks can improve deposit intelligence before funds arrive rather than after. That includes taint-aware scoring at mempool time where possible, triage for bridge-originated flows and withdrawal controls on fresh accounts that receive suspect funds in the first 24 hours. Incident playbooks should include named contacts and phone numbers, not only internal documentation.

Users can reduce the chance of becoming the entry point for an exploit by limiting token approvals, avoiding default approvals on unfamiliar decentralized applications and reviewing revokes regularly. Phishing remains a common source of ecosystem losses.

Common Errors in Response

Focusing only on mixers can miss the current pattern. DPRK-linked flows often use bridges and swaps first, so those early hops are where freeze opportunities may be strongest.

Ignoring small transfers is another mistake. Smurfing into numerous sub-$1,000 or sub-$10,000 chunks is part of the method. Alerts should be built around patterns as well as transfer size.

Assuming the exit will always occur through a major centralized exchange can also mislead investigators. Cash-outs frequently use OTC brokers before any centralized-exchange contact.

Speed is central. If escalation takes a day, the most useful window may already be gone. Response processes need to operate in minutes.

Finally, teams should avoid applying a one-size-fits-all Tornado-era rulebook to cross-chain traffic. Heuristics must be calibrated by chain, bridge and liquidity conditions.

Frequently Asked Questions

Do DPRK-linked hackers still use mixers?

They do, but less predictably. Sanctions designations and smaller pool sizes have made mixers riskier and sometimes less effective. Recent patterns have favored bridges and no-KYC swaps first, followed by selective mixer use when pool size and risk make it viable.

Why do flows reconsolidate before cash-out?

Reconsolidation simplifies operations. Brokers often prefer to receive funds in a small number of wallets they control or monitor. After spreading funds to complicate surveillance, launderers may gather them into fewer addresses for OTC settlement or fiat conversion.

Can funds be frozen after a bridge hop?

It is possible, but more difficult. Some bridges and exchanges will act on strong signals, but certainty drops after assets reach liquid stablecoins and pass through multiple swaps. Coordinated action during the first one or two hops is generally the best opportunity, especially when the source exploit is confirmed and tagged quickly.

How did H1 2026 compare with prior years?

TRM Labs counted 207 hacks totaling about $972 million in H1 2026 and assessed roughly 66% as tied to DPRK-linked actors. The period had fewer very large incidents, but higher per-incident dollar values, with a handful of infrastructure compromises dominating losses.

What changed in regulation during the summer?

Regulators issued more explicit warnings and expectations. Canada’s FINTRAC renewed guidance on screening for DPRK exposure and escalating suspected sanctions evasion. That position aligns with global FATF messaging focused on OTC gaps and cross-chain scrutiny.

Are OTC brokers always complicit?

No. Some OTC desks maintain strong compliance programs and reject tainted funds. The risk is greater among informal or lightly supervised brokers operating across borders. The July case reported by CoinDesk described brokers who allegedly helped convert stolen funds into fiat and split transfers to avoid detection.

Would mandatory bridge KYC solve the issue?

Mandatory bridge KYC could help in some areas, but it would not address the core problem. Attackers may route through permissionless bridges or proxy through unwitting users. Practical gains are more likely from better monitoring, faster incident response and targeted enforcement against recurring off-ramps than from blanket KYC at every hop.

Disclaimer: This article is provided for informational purposes only. It is not offered or intended as legal, tax, investment, financial or other advice.