
Former military hackers arrested for stealing from state banks and laundering via crypto. The cash-out route through China brokers mirrors patterns sanctions monitors have flagged.
North Korean authorities detained former military hackers accused of stealing from state-owned banks and washing the proceeds through cryptocurrency, CoinDesk reported July 25, citing Daily NK and an unnamed source in Pyongyang.
The suspects allegedly broke into internal systems at the Central Bank of North Korea and the Korea Trade Bank, siphoning foreign currency and trade funds, the report said. They moved the money into overseas crypto wallets to cover the trail.
Investigators believe the funds traveled through China-based brokers, converted into dollars and yuan, and cashed out with help from intermediaries in the border cities of Sinuiju and Hyesan. Those areas have long-running informal finance channels that facilitate trade and currency exchange, the report said.
To avoid detection, the suspects split transfers into smaller chunks and executed conversions in near real time, the source said. They also used encrypted messaging apps, unregistered phones, and Chinese wireless equipment.
North Korea's intelligence service caught the suspects July 12 at a hideout in Pyongyang. The trigger was a discrepancy in foreign-currency payment approvals combined with suspicious activity from overseas IP addresses, the source said.
How the alleged laundering worked
The route mirrors patterns sanctions monitors have flagged for years when tracking how North Korean-linked groups convert stolen crypto into spendable cash. Multinational oversight reports repeatedly point to Chinese over-the-counter traders and financial entities as the crucial middlemen that turn digital assets into fiat, exploiting gaps between formal compliance rules and the realities of cross-border cash settlement.
The suspects used what compliance officers call "structuring" – breaking large sums into smaller transactions that slide under reporting thresholds. They made those moves in near real time, limiting the window for investigators to connect the dots. Encrypted messaging and burner phones added another layer.
The cash-out infrastructure, not the on-chain theft itself, is often the weakest link in these operations. A blockchain hack grabs headlines. Turning stolen tokens into dollars or yuan that can buy goods requires human intermediaries, physical cash networks, and border crossings. That is where the trail can be picked up.
Scale of the problem
The arrests come as outside estimates of North Korea's crypto theft keep climbing. Chainalysis said North Korean hackers stole a record $2 billion in cryptocurrency last year. TRM Labs estimated that through April, North Korean actors accounted for 76% of all losses from crypto hacks and scams.
Those figures have intensified pressure on exchanges and OTC desks to tighten know-your-customer and anti-money-laundering controls. The U.S. Treasury and United Nations sanctions monitors have repeatedly flagged Chinese OTC brokers as key nodes in North Korea's cash-out pipeline.
What the arrests signal
The reported crackdown suggests Pyongyang is willing to police its own people – even former military hackers – when stolen funds risk exposing internal controls or creating a trail back to the regime. That is unusual for a government that has historically tolerated or directed cyber theft as a revenue source.
For the crypto market, the case reinforces a point that compliance teams have been making for years: the highest-leverage vulnerability is not the on-chain theft but the off-chain conversion. OTC brokers, payment rails, cash settlement agents, and nested services are where illicit crypto becomes spendable currency. Those nodes are harder to audit than blockchain transactions and more resistant to real-time monitoring.
The alleged use of structuring, encrypted apps, and border-city intermediaries also suggests North Korean-linked actors are updating their tactics. Compliance systems that flag only large transfers or known wallet addresses may miss the pattern of small, rapid conversions spread across multiple broker relationships.
North Korea's intelligence apparatus nabbed the suspects after spotting a discrepancy in foreign-currency payment approvals and linking it to suspicious IP addresses. That combination – financial controls plus cybersecurity telemetry – is the same approach sanctions monitors have recommended for years. It may be getting harder for even well-connected insiders to move money without leaving a trace.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.