
$2.8B in stolen crypto moved through networks shared with scam syndicates. RUSI paper tracks how North Korea converts coins to cash through mules, Chinese banks and OTC desks.
North Korea is routing stolen cryptocurrency through criminal ecosystems that also serve scam syndicates, a move that blurs the line between state-backed theft and ordinary financial crime. A new paper from the Royal United Services Institute says the regime pushed at least $2.8 billion in stolen virtual assets between January 2024 and September 2025, with researchers focusing on how those assets convert into cash.
Ownership of stolen coins changes hands before conversion, sometimes through discounted bulk purchases. Investigators told the authors those handovers become visible when stolen funds appear alongside proceeds from pig butchering scams or at addresses tied to entities like Cambodia's Huione Group, whose infrastructure the Justice Department seized in June.
Elliptic data suggests these transfers often happen on the Bitcoin blockchain. After the February 2025 Bybit hack, ZeroShadow responders watched the regime rely on launderers, over-the-counter desks and peer-to-peer traders, many of them Chinese nationals working round the clock.
TraderTraitor, the group behind the theft, used Chinese organised crime networks to move funds and return cash, further embedding state-linked theft inside commercial criminal infrastructure. Once inside those ecosystems, the markers of proliferation finance become hard to separate from standard crypto laundering patterns.
The accounts used to cash out typically belong to mules in the Philippines, Indonesia and China, where credentials are cheap enough to buy in bulk. Interviewees said many mules never learn who they are really working for. Conversion happens in small slices, with actors selling roughly $7,000 in stablecoins at a time on peer-to-peer marketplaces to stay below bank review thresholds.
ZeroShadow also found larger sums broken into $30,000 pieces so any single freeze would not be too damaging. Exchange behaviour offers clues, from Astrill VPN logins to launderers filing 50 to 70 support tickets to release a single held transaction.
Fiat rarely arrives through simple transfers. Over-the-counter brokers often deposit proceeds into North Korean-controlled accounts using UnionPay cards issued by Chinese banks. The paper lists 19 Chinese banks identified last year as used by the regime and its proxies.
Of the roughly $1.5 billion taken from Bybit, 95% moved through decentralised services, and all of it had been converted into fiat or hard currency by September 2025, the researchers said. Bybit's own update shows the scale: the exchange recovered $48.4 million and froze another $30.5 million, roughly 5% of what was stolen.
The authors call for clearer regulatory guidance on correspondent relationships, standardised onboarding questionnaires, secure intelligence-sharing channels and a VASP identifier in payment messages.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.