Key Takeaways
North Korea-linked crypto thefts rely on more than hackers moving stolen tokens between wallets. Wu Blockchain said investigations point to specialist intermediaries that accept traceable assets, supply replacement funds and connect cybercriminals with real-world payment networks.
The distinction helps explain why following stolen cryptocurrency does not necessarily reveal when the attackers get paid, or guarantee victims can recover their money.
The issue has resurfaced following Bitget’s September security incident.
Elliptic assessed the attack as highly likely linked to North Korea, citing connections to laundering addresses associated with earlier thefts, including Bybit. That remains an attribution assessment rather than a definitive finding.
+68
The February 2025 Bybit theft illustrates the scale of this financial infrastructure. The FBI attributed the approximately $1.5 billion attack to North Korea, saying stolen assets had been converted and dispersed across thousands of addresses on multiple blockchains.
Security firm zeroShadow subsequently reported that more than $1 billion from the theft had been laundered between February and June 2025. That estimate does not establish that the entire amount became fiat currency or represent the hackers’ net proceeds.
Elliptic’s six-month review suggested professional laundering networks were involved early. Under the suspected arrangement, intermediaries paid attackers the value of transferred funds minus fees, then assumed responsibility for processing the stolen assets.
The model transfers some financial risk to the middlemen. Once they accept the assets, subsequent freezes or seizures can threaten their own profits rather than necessarily depriving the original hackers of payment.
For investigators, that creates a second question beyond where the money went: when did control change hands, and what did the attackers receive in exchange?
Chainalysis’ September 2026 investigation into Xinbi’s vendor network described another mechanism: substituting stolen cryptocurrency with funds from separate criminal activity.
The company said North Korea-linked actors moved tens of millions of dollars from major thefts, including Bybit and WazirX, through the network.
Specialist vendors known as “Black U” launderers accepted traceable stolen assets and supplied stablecoins drawn from other illicit revenue streams, including romance scams and pig-butchering fraud.
Those replacement assets were not legally clean. Their connection to the original hack was simply harder to establish directly, while the stolen funds entered a broader pool of criminal transactions.
Swaps, cross-chain transfers and mixing services add further complexity. Changing assets and networks increases the work required to reconstruct transactions and can buy time before platforms receive alerts or restrict movement.
These operations do not automatically erase blockchain records. Nor does processing funds through a service prove that they have reached a bank account.
The decisive step often involves a counterparty willing to accept suspicious assets and deliver usable value elsewhere.
Elliptic found that hackers moved some traceable Bybit proceeds to Tron and converted them into USDT, then used suspected Chinese over-the-counter trading services to cash out. These intermediaries connect cryptocurrency holdings with fiat settlement channels.
Following those transfers still does not give investigators control over the assets.
Native bitcoin and ether have no central issuer that can directly freeze balances. Recovery generally depends on cooperating custodians, token issuers with freezing capabilities, or authorities obtaining lawful control.
Even seized funds require further legal proceedings before restitution.
In November 2025, the US Justice Department announced civil forfeiture actions involving more than $15 million in cryptocurrency linked to four platform thefts allegedly carried out by North Korea’s APT38. Authorities had already frozen and seized the assets and sought their eventual return to rightful owners.
Disrupting North Korea’s crypto revenues therefore requires identifying the intermediaries that turn visible stolen assets into spendable value.