How North Korea Cashes Out Stolen Cryptocurrency to Fiat in 2026

Aug 17, 2026

How North Korea Cashes Out Stolen Cryptocurrency to Fiat in 2026

How North Korea Cashes Out Stolen Cryptocurrency to Fiat in 2026

Imagine stealing $1.5 billion from a major exchange and having it vanish into thin air within three days. That is exactly what happened during the Bybit hack in February 2025, where Lazarus Group, North Korea's state-sponsored hacking unit, executed one of the largest cryptocurrency thefts in history. The real puzzle isn't how they stole the coins; it is how they turn those digital assets into usable cash without getting caught by international sanctions. This process, known as cashing out, has become a sophisticated industrial operation for the regime. It now funds roughly 20-30% of their foreign currency reserves, directly supporting weapons programs while evading United Nations Security Council restrictions.

The journey from stolen token to bank deposit is no longer a simple swap on an online platform. It involves a complex web of cross-chain bridges, decentralized finance protocols, and human networks operating in loosely regulated regions. Understanding this pipeline reveals just how adaptive the regime has become against tightening global financial controls.

Key Takeaways

  • Speed is the primary strategy: 78% of stolen assets are converted to fiat within 72 hours, down from 120 hours in 2021, to outrun blockchain analysts.
  • Cambodia is the top hub: Entities like Huione Group facilitate final conversions with minimal KYC, processing tens of millions in illicit flows.
  • IT workers are key assets: Thousands of North Korean employees abroad use false identities to create backdoors in exchanges for easy withdrawals.
  • Bitcoin remains the bridge: Despite DeFi complexity, 82% of final conversions target Bitcoin due to its deep liquidity and lower tracking friction compared to stablecoins.
  • Regulation is catching up: New frameworks like CARF have reduced successful cash-outs by 22% in early 2025, forcing the regime to develop new arbitrage techniques.

The Four-Stage Cash-Out Pipeline

The methodology documented by FinCEN and TRM Labs breaks down into four distinct technical phases. Each stage is designed to obscure the origin of the funds while moving them closer to traditional banking systems.

  1. Initial Theft: Most attacks (68%) rely on phishing or infrastructure compromise rather than breaking encryption. In the Bybit case, compromised internal credentials allowed access to cold wallets. Speed here is critical; assets must move before alerts trigger.
  2. Cross-Chain Movement: Stolen assets rarely stay on their original network. Hackers route tokens through bridges like Ren Bridge or Avalanche Bridge. In 2024, these bridges processed $1.2 billion in North Korean-linked transactions. This step fragments the transaction trail across multiple blockchains, making it harder for analysts to connect the dots.
  3. Conversion to Bitcoin: Bitcoin serves as the preferred intermediary because of its liquidity. After the Bybit hack, 87% of the stolen Ethereum was converted to Bitcoin within 72 hours. This standardization allows the funds to be moved to any exchange that supports BTC, regardless of the original asset type.
  4. Fiat Conversion: The final step involves swapping Bitcoin for US dollars, euros, or local currencies. This happens through third-party networks with weak Know Your Customer (KYC) requirements, often involving Over-The-Counter (OTC) desks or regional banks.

This pipeline relies on volume. Nick Carlsen, a former FBI expert at TRM Labs, describes the "flood the zone" technique, where hackers execute 400-500 high-frequency transactions daily. This overwhelms manual review processes and forces automated systems to flag too many alerts, causing analysts to miss the true signal.

Street market scene where a man exchanges dollars for a holographic bitcoin symbol

Geographic Hubs: Where Crypto Becomes Cash

You cannot cash out billions in secret if every exchange requires a passport scan. That is why geography matters more than technology in the final stage. Two regions dominate this landscape: Cambodia and China.

Cambodia has emerged as the primary fiat conversion center due to its loosely regulated financial sector. In May 2025, FinCEN designated the Huione Group as a primary money laundering concern. Between 2021 and 2025, $37.6 million in North Korean-linked cryptocurrency passed through Huione entities. Their subsidiaries play specific roles: Huione Guarantee provides infrastructure for scams, while Huione Crypto issues non-freezable stablecoins that convert illicit assets into legitimate-looking value. As of March 2025, there were 14 North Korean-controlled "crypto cafes" in Sihanoukville alone, each processing $500,000 to $2 million monthly in cash with no identification required.

China remains a secondary hub despite increased scrutiny. A February 2024 Department of Justice indictment revealed a network processing $250 million through 37 Chinese bank accounts with minimal documentation. However, the rise of Southeast Asian gambling platforms offers another vector. Macau-based casinos, for instance, accept cryptocurrency deposits with only 5% verification rates, compared to the standard 95% KYC requirements in regulated markets. This gap allows 15% of stolen funds to flow through gaming channels, effectively disguising illicit proceeds as casino winnings.

Comparison of Primary Cash-Out Hubs
Hub Primary Method KYC Stringency Estimated Volume (Recent)
Cambodia Crypto cafes & OTC desks Very Low (0-5%) $500k-$2m per cafe/month
China Bank account networks Moderate (Bypassed via insiders) $250m+ (Indicted network)
Macau/Southeast Asia Casino deposits Low (5%) 15% of total stolen funds

The Human Element: IT Workers as Backdoors

Technology enables the theft, but people enable the exit. North Korea has deployed thousands of IT workers abroad, primarily in China, Russia, and Southeast Asia. These individuals generate an estimated $600 million annually for the regime according to the UN Panel of Experts. But their role in crypto cash-out is even more direct.

These workers assume false identities-89% using falsified Indian or Vietnamese profiles-to gain employment at cryptocurrency exchanges and fintech firms. Once inside, they create backdoors for fund movement. CSIS documented 27 cases in 2024 where North Korean IT workers at Chinese exchanges enabled direct wallet-to-bank transfers with only 12-hour notification periods. This bypasses the standard 72-hour fraud detection window used by most institutions.

They also employ location masking techniques using VPNs to appear as legitimate remote workers based in the US or Europe. When working as freelancers, they secure cryptocurrency payment contracts under fake profiles, then convert the digital assets to fiat through local exchange networks with minimal oversight. This human layer is difficult to sanction because these workers look like ordinary tech employees until the funds start moving.

Analyst tracing blockchain paths while a disguised thief sprints away with puzzle pieces

Evolving Tactics: From Mixers to DeFi Arbitrage

The era of simple mixing services is ending. The September 2022 sanctions against Tornado Cash eliminated a tool that had processed $1.2 billion in stolen funds between 2019 and 2022. Without it, the regime shifted toward speed-based laundering and decentralized finance (DeFi) innovations.

Today, 73% of stolen assets pass through at least three different blockchain networks before cash-out. The June 2023 Atomic Wallet hack demonstrated this sophistication: after stealing $100 million, hackers executed 1,842 cross-chain transactions within 48 hours, funneling funds through 17 different OTC desks with average transaction sizes kept below $10,000 to avoid reporting thresholds.

Looking forward, the focus is on "stablecoin arbitrage laundering." A March 2025 CSIS investigation revealed that the regime is testing methods where stolen assets are converted to non-sanctionable stablecoins like USDC through decentralized exchanges. They then exploit price discrepancies between regional exchanges to generate clean fiat with minimal transaction trails. Additionally, the FBI warned in April 2025 that North Korea has recruited 37 blockchain developers from defunct projects to build custom cross-chain protocols capable of processing $500 million+ transactions while maintaining plausible deniability.

Why Interdiction Is Getting Harder

You might think improved blockchain analytics would solve this problem. While tools like Chainalysis and TRM Labs have improved tracking capabilities by 40% since 2022, North Korea's adaptation speed has increased by 65%. This creates a widening gap in effective interdiction.

The biggest bottleneck remains the final fiat conversion point. Only 3-5% of global cryptocurrency exchanges maintain sufficiently lax KYC procedures to facilitate large-scale withdrawals without triggering alerts. This scarcity drives the regime to establish its own infrastructure, such as the crypto cafes in Cambodia. However, regulatory pressure is starting to bite. The implementation of the Crypto-Asset Reporting Framework (CARF), which requires exchanges to share beneficiary information across 100+ jurisdictions, led to a 22% decrease in successful North Korean cash-outs in Q1 2025 compared to Q4 2024.

Treasury Secretary Janet Yellen stated in May 2025 that the window for these operations is closing rapidly, with projected success rates declining to 40% by 2027. Yet, experts caution that the regime will continue adapting until cryptocurrency itself becomes fully regulated or obsolete. For now, the race between forensic analysis and creative laundering continues, with the stakes being billions in stolen assets and the funding of nuclear programs.

What is the most common method North Korea uses to steal cryptocurrency?

The most common method is phishing or infrastructure compromise, accounting for 68% of attacks. Rather than breaking encryption, hackers often trick employees or exploit weak security protocols in exchange infrastructure to gain access to private keys.

Why do North Korean hackers prefer converting to Bitcoin first?

Bitcoin is the preferred intermediary because of its high liquidity and widespread acceptance. Converting various stolen tokens into Bitcoin standardizes the assets, allowing them to be easily moved to any exchange or OTC desk that supports BTC, regardless of the original currency stolen.

How do IT workers help North Korea cash out crypto?

North Korean IT workers employed at exchanges and fintech firms use their privileged access to create backdoors. They can enable direct wallet-to-bank transfers with short notification periods, bypassing standard fraud detection windows and facilitating quick fiat conversion.

What role does Cambodia play in cryptocurrency laundering?

Cambodia is the primary fiat conversion hub due to its loosely regulated financial sector. Entities like Huione Group and numerous "crypto cafes" in Sihanoukville process large volumes of cash transactions with little to no identification required, making it an ideal endpoint for laundering stolen assets.

Is blockchain analysis able to stop North Korean cash-outs?

Blockchain analysis has improved significantly, increasing tracking capabilities by 40% since 2022. However, North Korea's adaptation speed has increased by 65%, creating a gap. While regulations like CARF have reduced successful cash-outs, the regime continues to evolve tactics, making complete interdiction difficult.

Write a comment