North Korea Hackers' Evolving Playbook Unravels Cryptocurrency Money-Laundering Schemes
North Korea-linked hackers have been using a complex money-laundering scheme to move stolen cryptocurrency funds, according to recent research. This playbook has evolved over time and has become increasingly difficult for regulators to catch.
The typical flow of funds involves draining assets from an exploit, pushing them through cross-chain bridges and no-KYC swaps to fragment exposure, consolidating into liquid stablecoins, and then cashing out through OTC brokers who convert the funds into dollars or yuan in small chunks.
TRM Labs has flagged this exact route as dominating the largest heists of 2026. The pattern relies on speed, chain-hopping, and counterparties outside strict KYC perimeters. Bridge first, swap often, fragment amounts, then reconsolidate, this is the mantra of DPRK laundering.
A recent advisory from FINTRAC (Canada) reiterated FATF concerns and urged enhanced AML and CFT measures for potential DPRK-linked transactions in July 2026. Regulators are pulling the sanctions thread tighter, making it harder for hackers to operate undetected.