RUSI finds North Korea increasingly uses organised‑crime laundering networks to cash out stolen cryptocurrency. The think tank estimates at least $2.8 billion was stolen between January 2024 and September 2025, with ownership often transferred before conversion. The February 2025 Bybit hack — about $1.5 billion stolen — shows how OTC desks, P2P traders and account mules are used to structure conversions below review thresholds. RUSI calls for clearer regulatory guidance, a VASP identifier in payment messages, and secure intelligence sharing to help banks and investigators spot illicit flows.
North Korea Turns to Organized‑Crime Networks to Launder Stolen Cryptocurrency, RUSI Warns

The Royal United Services Institute (RUSI) reports that North Korea is increasingly routing stolen cryptocurrency through the same money‑laundering networks used by scam syndicates and organised crime, making it harder for investigators to trace the funds. In a new research paper, Allison Owen and Noémi També focus on how the regime converts virtual assets into cash, rather than the earlier, better‑documented stages that move funds through decentralised services.
Scope and Scale
RUSI estimates the regime stole at least $2.8 billion in virtual assets between January 2024 and September 2025. The paper says these proceeds are widely assumed to support the regime's weapons programme. Rather than being cashed out directly, ownership of funds frequently changes hands before conversion — sometimes with third parties buying stolen coins at a discount.
How Laundering Networks Work
Investigators and forensic firms contributing to the research, including blockchain‑forensics firm Elliptic and incident responders at ZeroShadow, describe an ecosystem of launderers, over‑the‑counter (OTC) desks and peer‑to‑peer traders. These networks often include Chinese organised crime groups, and employ account mules recruited mainly in the Philippines, Indonesia and China. Mules commonly sell credentials or open accounts at scale, then dissociate from the activity.
Conversion tactics are deliberately structured to evade detection: actors typically sell roughly $7,000 of stablecoins at a time on peer‑to‑peer marketplaces to stay below review thresholds, while larger sums are split into chunks of about $30,000 so that an account freeze would have limited impact. On exchanges, laundering produces additional signals such as VPN logins (for example via Astrill) and an unusually high number of support tickets — sometimes 50 to 70 — filed to release a single held transaction.
Case Study: The February 2025 Bybit Hack
RUSI's analysis of the February 2025 Bybit breach shows how these networks operate in practice. The group known as TraderTraitor was behind the theft; roughly $1.5 billion was taken in the incident. The report says about 95% of that sum moved through decentralised services, and monitoring teams found that, by September 2025, the bulk had been converted into fiat or hard currency.
ZeroShadow found that the regime leaned on a combination of launderers, OTC desks and peer‑to‑peer traders — often Chinese nationals working around the clock — to turn cryptocurrency into cash. Fiat rarely moves by simple bank transfer: proceeds from OTC brokers are often deposited into North Korean‑controlled accounts via UnionPay cards issued by Chinese banks. The Multilateral Sanctions Monitoring Team identified 19 Chinese banks last year as being used by the regime and its proxies.
RUSI and interviewees also note handovers inferred when illicit funds appear mixed with proceeds from scams such as 'pig butchering' or at addresses linked to entities like Cambodia's Huione Group; the US Department of Justice seized Huione infrastructure in June.
Policy Implications and Recommendations
RUSI warns that once North Korean proceeds enter criminal ecosystems, markers of proliferation finance increasingly blend with ordinary money‑laundering indicators, making compliance and law enforcement work harder. The paper urges regulators and industry to take several steps:
- Provide clearer guidance on correspondent banking relationships with exchanges and virtual asset service providers (VASPs).
- Standardise onboarding questionnaires and customer due diligence across platforms.
- Introduce a VASP identifier in payment messages so receiving banks can flag suspect flows more readily.
- Establish secure, standardised channels for intelligence sharing between industry and authorities.
What This Means For Victims
Remedies for victims remain limited. Bybit said it had sued North Korea and won a court order freezing identified assets: the exchange recovered $48.4 million and froze a further $30.5 million, together roughly 5% of the funds lost in the attack. That outcome illustrates both the difficulty of full recovery and the partial effectiveness of legal and asset‑freezing actions.
Conclusion
RUSI's paper highlights how state‑sponsored theft is being blended into criminal money‑laundering ecosystems, complicating detection and prosecution. Improved regulatory standards, stronger cross‑border cooperation and better intelligence sharing are essential to disrupt the pipelines that turn stolen crypto into usable cash.
Help us improve.


































