North Korea has increasingly turned to organized crime networks to launder cryptocurrency stolen through cyberattacks, according to a report from the Royal United Services Institute, a London-based defense and security think tank. Decrypt reported the findings on August 11, citing RUSI's analysis of how Pyongyang moves its illicit digital funds.
North Korea has long relied on state-linked hacking units, including groups associated with the Lazarus Group, to steal cryptocurrency from exchanges, bridges, and individual wallets. Those thefts have funded weapons programs and helped the country evade international sanctions. Laundering the proceeds, however, has grown harder as blockchain analytics firms and exchanges have improved their tracing capabilities.
The RUSI report suggests that North Korean operatives are now leaning on established criminal networks to handle the laundering process rather than managing every step themselves. Outsourcing this work to organized crime groups can offer North Korea additional layers of separation between the original theft and the eventual conversion of stolen funds into usable currency.
Criminal networks often have existing infrastructure for moving illicit money across borders, including access to shell companies, informal value transfer systems, and contacts in jurisdictions with weaker financial oversight. Tapping into that infrastructure could make it more difficult for investigators to trace funds back to their origin.
This shift, as described in the report, reflects a broader pattern in how state-linked actors adapt their tactics when law enforcement and private-sector tracing tools close off previous laundering routes. Crypto-focused investigators have noted in the past that North Korean operations frequently change methods, including the use of mixers, chain-hopping, and peer-to-peer trading, to stay ahead of detection.
The report does not specify which criminal networks are involved or provide detailed figures on the volume of funds laundered through this method. It focuses instead on describing the strategic shift in how North Korea is believed to be structuring its laundering operations.
North Korea has been linked by multiple governments and private security firms to some of the largest cryptocurrency thefts in the industry's history. Those incidents have prompted exchanges and regulators to invest more heavily in blockchain forensics and sanctions compliance tools over the past several years.
Market Impact
For cryptocurrency exchanges and custodians, the reported shift underscores the ongoing need for robust sanctions screening and transaction monitoring, particularly around funds with suspected links to North Korean hacking operations. If criminal networks are increasingly involved in laundering stolen crypto, compliance teams may need to widen the scope of their risk indicators beyond wallet addresses tied directly to known state-linked hacking groups.
The development also has implications for law enforcement and blockchain analytics providers, who may need to adapt tracing methods to account for laundering routes that pass through traditional organized crime infrastructure rather than purely on-chain tools like mixers. No specific market price impact has been reported in connection with these findings.
The RUSI report points to an evolving laundering strategy by North Korea, one that blends state-sponsored hacking with organized crime logistics. As tracing technology advances, further adaptation by illicit actors is likely, keeping pressure on exchanges, regulators, and investigators to keep pace.
Frequently Asked Questions
What did the RUSI report say about North Korea and crypto laundering?
The report found that North Korea is increasingly relying on organized crime networks to launder cryptocurrency stolen through hacking operations, rather than handling the process solely through state-linked channels.
Why would North Korea outsource laundering to criminal networks?
Criminal networks often have existing infrastructure, such as shell companies and informal money transfer systems, that can add distance between stolen funds and their eventual use, making tracing harder.
Does the report name specific criminal groups involved?
According to the reporting on RUSI's findings, no specific criminal networks were named, and the report focused on describing the strategic shift rather than detailed operational specifics.
How has North Korea funded operations with stolen crypto in the past?
North Korea has been linked to major cryptocurrency thefts through hacking groups such as Lazarus Group, with stolen funds previously tied to sanctions evasion and weapons program funding.