North Korea is increasingly laundering stolen cryptocurrency through established criminal networks, according to a research paper from the Royal United Services Institute cited by Decrypt. The paper says the regime stole at least $2.8 billion in virtual assets between January 2024 and September 2025, with funds assumed to support its weapons program.
The finding matters for crypto firms because it complicates compliance work. Once stolen North Korean funds are mixed with proceeds from investment scams or routed through the same brokers, peer-to-peer traders and over-the-counter desks used by organized crime, the paper warns that the signals of proliferation finance become harder to separate from broader money laundering.
RUSI’s authors focus on the cash-out stage, where ownership can change before conversion. In some cases, third parties may buy stolen coins at a discount; in others, investigators see funds appear alongside proceeds from scams or addresses linked to entities such as Cambodia’s Huione Group. Elliptic, which supplied data for the research, believes some of these handovers often happen on Bitcoin.
The paper also describes a reliance on money mules, especially in the Philippines, Indonesia and China, where credentials can be purchased cheaply and used to open accounts at scale. Decrypt reported that laundering can involve relatively small stablecoin sales on peer-to-peer marketplaces, as well as larger sums broken into chunks to reduce the impact of potential freezes.
RUSI’s recommendations include clearer regulatory guidance for exchange relationships, standardized onboarding questionnaires, secure intelligence-sharing channels and payment-message identifiers for virtual asset service providers. The Bybit case shows the limits of recovery: after a roughly $1.5 billion theft, Decrypt reported that Bybit had recovered $48.4 million and frozen another $30.5 million, together about 5% of what was taken.