North Korea uses crime networks to launder stolen crypto

A Royal United Services Institute report says North Korea uses criminal networks to launder cryptocurrency stolen in state-linked cyberattacks.

A Royal United Services Institute report finds hacking groups linked to North Korean state actors move stolen cryptocurrency through chains of intermediaries to obscure its source and convert it into usable assets.

The analysis covers incidents over recent years and describes a repeated pattern: after an initial theft assets are split, swapped across multiple blockchains, passed through privacy tools and relayed via brokers, decentralized exchanges, mixers, peer-to-peer trades and small exchanges.

Intermediaries include criminal brokers who take commissions, lightly regulated exchanges, over-the-counter brokers and individual money launderers who convert crypto into cash through informal channels. The report identifies cross-chain bridges, decentralized exchanges and so-called coin tumblers among the tools used to break links between source wallets and final recipients.

The networks operate across multiple jurisdictions and exploit gaps in compliance and international cooperation. Rapid on-chain transfers, use of privacy-enhancing services and off-chain cash-outs reduce the forensic trail and complicate tracing and recovery, the report says.

The report states the laundering aims to convert stolen tokens into fiat currency and goods that can be used by the North Korean regime. It notes previous government assessments that link proceeds from cyber-enabled theft to procurement networks and foreign currency reserves subject to sanctions.

Recommendations include stepped-up international information sharing, stricter enforcement of know-your-customer rules and travel-rule obligations, tighter controls at on-ramps and off-ramps, and better detection tools for tracing cross-chain movements and mixer use. It calls on exchanges to adopt consistent reporting and vetting practices.

Analysts referenced in the report point out that technical obfuscation and human intermediaries limit the effectiveness of on-chain measures alone. They identify background investigations, cross-border law enforcement action and private-sector tracing capabilities as complements to blockchain analytics.

The report follows other studies and official statements that link North Korean cyber operations to systematic efforts to raise funds through illicit means, and it highlights ongoing challenges for enforcing sanctions on virtual assets.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author