North Korean intelligence has arrested a group of former military hackers. Investigators suspect them of stealing funds from two state banks and then laundering the proceeds through crypto. This time the victim of a North Korean cyberattack was the state itself, the same government that has spent decades profiting from similar schemes abroad. The story reads almost like a joke. A tool Pyongyang used for years against foreign exchanges turned against its own banking system.
What exactly happened?
According to South Korean outlet Daily NK, the DPRK's intelligence agency detained the suspects on July 12 at a safe house in Pyongyang. The outlet has spent years reporting on the country's internal affairs through a network of sources and contacts along the border, so its reports are usually taken seriously despite the impossibility of official confirmation from the North Korean side. Investigators say the detained men previously served in the army's cyber units and had access to the foreign-currency payment systems of two state banks. Discrepancies in approved currency transfers first raised suspicion. A second red flag came from suspicious IP activity that traced outside the country, even though the group tried to mask its real location using proxies and rented servers.
How did the laundering scheme work?
Stolen funds were converted into crypto and then moved through brokers in China. These brokers exchanged the assets for dollars and yuan on the spot, without going through major exchanges or asking many questions. Nothing moved in one large transfer, since that would have drawn attention from bank monitoring systems. The scheme relied on a handful of fairly simple tricks that financial security professionals already know well, and that criminal groups worldwide use far beyond state-sponsored hackers.
- Splitting transfers: the total sum was broken into small transactions to dodge automated monitoring triggers at banks and exchanges.
- Contacts in the border cities of Sinuiju and Hyesan swapped crypto for cash in real time, leaving no delay and no paper trail.
- Group members communicated through encrypted messaging apps and used unregistered phones.
- They also relied on Chinese wireless equipment to get online, making it far harder to trace any single person or address.
Daily NK does not disclose its sources inside the country, so these details cannot be independently confirmed for now. Still, the laundering route matches the methods North Korean hacking groups have used for years to cash out stolen crypto abroad, and that resemblance is exactly what lends the report extra credibility among analysts who track these cases.
Why does Pyongyang need crypto theft?
North Korea has lived under international sanctions for more than a decade, and the regime's usual financing channels are effectively closed. After a series of nuclear tests, the UN Security Council steadily tightened restrictions, hitting coal exports, textiles, and even overseas labor. The country ended up in a spot where ordinary trade barely brings in hard currency, forcing it to look elsewhere. UN sanctions monitors, who have tracked violations for years, estimate that crypto theft has become one of the regime's main sources of funding for its nuclear and missile programs.
Hacking units under military intelligence run almost like a separate branch of the economy, with their own budget and performance metrics. The best known among them, Lazarus Group and Bluenoroff, have spent decades hitting banks, exchanges, and DeFi protocols worldwide, bringing the regime hundreds of millions of dollars a year. In a system like that, even an internal corruption probe into the state's own cyber specialists looks like a logical extension of the same model: money is supposed to flow to the state, not stay in the pockets of the people who steal it. The arrest of its own staff, then, resembles a corporate purge more than a standard criminal case. Targeting banks specifically is nothing new for Pyongyang. Back in 2016, hackers tied to North Korea moved $81 million out of Bangladesh's central bank through the SWIFT system. Crypto simply added a newer, more convenient channel for moving money that is far harder to freeze or claw back.
Why does this story matter for the crypto market?
Groups linked to Pyongyang are behind some of the largest crypto thefts in the industry's history. Among them, the 2022 Ronin bridge hack, worth roughly $625 million, and the February 2025 attack on Bybit, where about $1.5 billion in ether disappeared. Both cases were later officially tied to North Korean hackers. Stolen funds typically move through Bitcoin and other assets, and lately through stablecoins like USDT more and more often.
The reason stablecoins are so popular is simple: high liquidity and fast transfers between exchanges worldwide make it easy to dissolve a large sum into thousands of small transactions. Centralized crypto exchanges with identity verification make cashing out harder, so bad actors increasingly turn to over-the-counter brokers and personal contacts, exactly as in this case with the state banks. Analytics firms like Chainalysis and TRM Labs track these transaction chains and help exchanges freeze suspicious wallets, but nobody has managed to stop laundering entirely.
For an average market user, this isn't a direct threat so much as a signal. Regulators in various countries keep tightening transaction monitoring because of schemes like this one, and that gradually shows up in fees and verification requirements even on legitimate platforms used by millions of ordinary people.
What happens next
Pyongyang has issued no official confirmation of the arrests, and one is unlikely to come anytime soon. The regime traditionally keeps internal investigations at this level quiet. If Daily NK's report is confirmed by other sources, it would mark a rare case of a state hacking machine getting burned by its own playbook. For now, the story stands as a reminder. Even inside the most closed system on earth, money has a habit of vanishing somewhere other than where everyone expects to find it.




Comments
Your email address will not be published. Required fields are marked *