North Korea’s $2.8B Crypto Theft Machine Relies on Professional Launderers, RUSI Finds
North Korean hackers are increasingly handing off stolen cryptocurrency to professional intermediaries, who blend it with other criminal proceeds and convert it into conventional currency. Between January 2024 and September 2025, North Korea stole at least $2.8 billion in digital assets, according to a new report from the Royal United Services Institute (RUSI).
Tracing the Path From Blockchain to Traditional Finance
The report’s authors traced the movement of funds between the blockchain and the traditional financial system. North Korean threat groups rely on exchanges, over-the-counter and direct sellers, shell accounts, and pre-existing criminal networks to move stolen assets. Intermediaries can purchase stolen cryptocurrency at a discount, then launder it themselves and convert it into conventional currency. As a result, tracing funds back to North Korea becomes progressively harder to detect.
The Bybit Hack: $1.5 Billion Fully Laundered
A telling example is the February 2025 breach of the Bybit exchange, in which nearly $1.5 billion was stolen. To move the funds, attackers enlisted an entire network of launderers and traders, many of whom were Chinese nationals. According to the report’s analysis, by September 2025 the entirety of the funds stolen from Bybit had already been converted into conventional currency or cash. Bybit itself previously published a detailed timeline of the incident.
Huione Group: A Key Laundering Node
Another critical link in the chain is Cambodia’s Huione Group. In 2024, one wallet linked to Huione received approximately $35 million in cryptocurrency traced back to the hack of the Japanese exchange DMM. Huione Pay’s customers could deposit cryptocurrency and withdraw it as conventional cash. In 2025, the U.S. Treasury’s Financial Crimes Enforcement Network (FinCEN) designated Huione Group as a key node used to launder proceeds from North Korean cyber operations, and subsequently severed the group’s access to the U.S. financial system entirely.
Mass Use of Straw Persons and Stolen Identities
The report’s authors also describe how attackers rely extensively on straw persons to register accounts. To do so, they purchase other people’s documents and credentials, frequently sourcing them from residents of the Philippines, Indonesia, and China. Under a more expensive variant of the scheme, ties to the document’s actual owner are maintained, allowing that individual to complete a re-verification check should a trading platform grow suspicious.
Near-Instant Fund Distribution After Major Heists
Following a major theft, funds can be distributed almost instantaneously. Researchers describe pre-configured wallet structures that automatically disperse assets across numerous addresses, including unregulated platforms. As a result, financial institutions are encouraged to share suspicious address data collaboratively, scrutinize intermediaries more carefully, and include cryptocurrency platform identifiers within bank transfer records. The report’s authors argue that without linking banking data to on-chain activity, detecting these laundering chains will only grow more difficult over time.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.