North Korea has stolen at least $2.8 billion in crypto between January 2024 and September 2025, with the funds presumed to contribute to the financing of the regime's armament program. However, Pyongyang is no longer working alone, with its loot now passing through the same networks as investment scams and organized crime in Asia.
The stolen crypto often changes hands before being converted into cash, with intermediaries buying the loot at a reduced price and then taking charge of its laundering. The funds then reappear mixed with the products of other scams or on addresses associated with criminal networks.
Crypto Laundering Mechanism
According to Elliptic, these transfers of ownership frequently occur on Bitcoin, making it difficult for platforms and investigators to distinguish North Korean money from the product of other criminal activities.
The hacking of Bybit in February 2025 illustrates this mechanism, with the North Korean group TraderTraitor relying on money launderers, over-the-counter brokers, and peer-to-peer traders to move the stolen assets.
Money Laundering Process
The final stage of the laundering process involves opening accounts in the names of third parties, with 'mules' recruited mainly in the Philippines, Indonesia, and China. The operators then fractionate the sales, with around $7,000 of stablecoins sold in each transaction on peer-to-peer platforms to remain under banking control thresholds.
Certain behaviors provide clues, such as the use of Astrill VPN or the opening of 50 to 70 tickets with the customer service to unblock a single transaction. The receipts of the brokers are then transferred to accounts controlled by Pyongyang, including through UnionPay cards issued by Chinese banks.



