North Korea's Crypto Hackers Evade Detection with Sophisticated Laundering Tactics
North Korean cryptocurrency hackers have become increasingly skilled at laundering stolen funds, making it harder for authorities to track their movements. According to TRM Labs, a leading analytics firm, the largest heists in the first half of this year followed a specific pattern: bridge first, swap second, and then onward to exchanges or OTC brokers.
The playbook has evolved over time, with hackers now using cross-chain bridges and no-KYC swaps to fragment and scramble exposure. This allows them to move funds quickly and avoid detection. The end-to-end flow of laundering involves draining funds from an exploit, pushing assets through cross-chain bridges and no-KYC swaps, consolidating into liquid stablecoins, and then cashing out through OTC brokers who convert the funds into dollars or yuan in small chunks.
Regulators have turned up the heat on North Korea-linked activity, which dominated losses in the first half of this year. The Canadian Financial Transactions and Reports Analysis Centre (FINTRAC) has urged enhanced anti-money laundering (AML) and counter-terrorism financing (CFT) measures for potential DPRK-linked transactions.
Compliance teams are fighting speed, trying to identify signals that fire fast and cut false positives enough to act. These signals include fresh-address to bridge hops within minutes of a known exploit, multi-bridge chain-hopping within 12 hours, and bursts of small, regular transfers to broker-linked deposit addresses.