North Korea has shifted its laundering strategy, now relying on established crime networks to clean stolen cryptocurrency, according to fresh analysis. The approach means that once the proceeds of hacks are mixed with money from scams and other illegal operations, exchanges can no longer tell the difference between proliferation finance and ordinary laundering.
How the mixing works
The process is straightforward in theory, messy in practice. Stolen coins get pushed through a series of wallets, often crossing into services that blend funds from multiple sources. By the time the money lands on a major exchange, it carries no clear fingerprint of its origin. It just looks like another deposit.
That's the point. North Korea's cyber units have long been accused of funding weapons programs with digital heists. But the laundering side has evolved. Instead of moving funds directly, they now tap into criminal networks that already handle dirty money at scale. Those networks mix stolen crypto with proceeds from phishing schemes, romance scams, and ransomware payouts.
Why exchanges can't separate it
Compliance teams at exchanges rely on blockchain analytics to flag suspicious addresses. That works when a theft is fresh and the funds haven't moved far. But once the coins are blended, the trail goes cold. A wallet that received stolen funds might also hold money from a dozen other crimes. There's no clean way to split one from the other.
This isn't a technical gap that a software update can close. It's a structural problem. The mixing services and criminal networks are designed to create ambiguity, and they're good at it. For an exchange, the practical choice is often between freezing a broad set of accounts or letting everything through. Neither is great.
Regulators are watching
Regulators have taken notice. The concern isn't just that North Korea gets its money. It's that the laundering infrastructure now serves multiple criminal enterprises at once, and the overlap makes enforcement harder across the board. A single transaction could fund a weapons program, a drug ring, and a pig-butchering scam simultaneously.
Some jurisdictions have pushed for stricter know-your-customer rules and faster reporting of suspicious activity. But the reality is that the mixing happens before funds reach regulated exchanges. By the time a compliance officer sees the transaction, the damage is done.
The trend isn't likely to reverse soon. As long as crypto offers pseudonymity and cross-border movement, criminal networks will keep using it. The question is whether exchanges and regulators can build better tools to trace funds through the mixers, or whether they'll keep playing catch-up.
For now, the burden falls on exchanges to tighten their screening processes. But without a way to untangle mixed funds, they're working with one hand tied behind their backs.




