How DPRK Hackers Launder Crypto Across Chains

How DPRK Hackers Launder Crypto Across Chains

Imagine stealing $1.5 billion in a single afternoon. Now imagine trying to spend it without anyone noticing where it came from. That is the daily reality for DPRK hackers, state-sponsored cyber actors working for North Korea's Reconnaissance General Bureau. In February 2025, the Bybit exchange suffered a historic breach, losing over $1.4 billion to these operatives. But the heist was just the beginning. The real challenge for Pyongyang isn't grabbing the coins; it's cleaning them up fast enough to fund weapons programs before global watchdogs freeze their assets.

You might think cryptocurrency is anonymous. It’s not. Every transaction lives on a public ledger forever. So how do North Korean operatives move billions across Bitcoin, Ethereum, and Tron without getting caught? They don’t hide in one place. They hop. This strategy, known as cross-chain laundering, exploits the bridges that connect different blockchains. By rapidly swapping assets between networks, they break the digital trail, turning transparent ledgers into a maze of obfuscation. If you are tracking crypto crime or just want to understand why your favorite exchange keeps getting hacked, here is how the game actually works.

The Evolution From Mixers to Bridges

A few years ago, if you wanted to dirty up some stolen Bitcoin, you sent it through a mixer like Tornado Cash or Sinbad. These services pooled users' funds and spat them out randomly, making it hard to link inputs to outputs. For a while, this worked great for the Lazarus Group, the umbrella term for North Korea’s elite hacking units. But regulators got wise. Sanctions hit Tornado Cash. Exchanges started blocking addresses linked to mixers. Suddenly, the old playbook was risky.

Enter the cross-chain bridge. Instead of mixing coins within one network, hackers now move value between entirely different blockchains. TRM Labs data shows that since 2023, the use of cross-chain conversion services by North Korea surged by 111%. Why? Because moving from Ethereum to Avalanche, then to Bitcoin, creates gaps in visibility. Most analytics tools track one chain well but struggle when funds jump across five different ecosystems in minutes. The hackers exploit this fragmentation. They aren't just hiding money; they are drowning analysts in noise.

Anatomy of the "Flood the Zone" Technique

When the Bybit hack happened, compliance teams didn't just see one large transfer. They saw thousands of tiny, rapid-fire transactions hitting multiple platforms simultaneously. Nick Carlsen, a former FBI expert now at TRM Labs, calls this "flood the zone." The goal isn't subtlety. It's volume. By overwhelming monitoring systems with high-frequency swaps, the hackers create chaos. While analysts scramble to tag one address, the bulk of the funds has already moved through three other chains.

Here is the typical flow observed in recent attacks:

  • Initial Theft: Funds are drained from a centralized exchange or DeFi protocol (e.g., Ethereum mainnet).
  • Rapid Conversion: Stolen ERC-20 tokens are swapped for native ETH via decentralized exchanges (DEXs) to avoid smart contract scrutiny.
  • Cross-Chain Hop: Assets are bridged to less-analyzed networks like BitTorrent Chain (BTTC), Tron, or Solana using services like Ren Bridge or Avalanche Bridge.
  • Obfuscation Layer: On the new chain, funds are split into smaller amounts and mixed again or converted into stablecoins.
  • Final Destination: Eventually, most funds return to Bitcoin, often held in fresh wallets awaiting Over-The-Counter (OTC) liquidation.

This method relies on speed. Automation scripts execute these trades in seconds. Human traders can't keep up. By the time a human analyst flags a suspicious pattern, the money is already halfway around the world, technically speaking.

Comparison of DPRK Laundering Methods (2020 vs. 2025)
Feature Traditional Mixer Era (Pre-2023) Cross-Chain Bridge Era (2024-2026)
Primary Tool Tornado Cash, Sinbad, Wasabi Wallet Ren Bridge, Avalanche Bridge, Thorchain
Visibility Risk High (Sanctioned entities) Medium (Fragmented data sources)
Speed Moderate (Batch processing) Extremely High (Automated scripts)
Target Asset Ethereum (ERC-20) Multi-chain (BTC, ETH, TRX, SOL)
Analyst Challenge Linking input/output clusters Tracing hops across disparate ledgers
Robots crossing glass bridges between colorful blockchain islands

Why Centralized Exchanges Are Still Vulnerable

You might ask: If the tech is so good, why do they still steal from big exchanges? Because humans are weak links. Elliptic notes that the "weak point in cryptocurrency security is now human, not technological." Recent campaigns show a pivot toward social engineering. Hackers send fake job offers to executives. They compromise social media accounts. They trick individual high-net-worth holders into signing malicious transactions.

Once the funds are in the hacker's wallet, the technical laundering begins. But the initial breach often stems from simple phishing or compromised keys. This shift means that even if your exchange uses top-tier cold storage, an employee clicking a bad link can cost billions. The Bybit incident wasn't just a code failure; it was a complex web of operational security lapses that allowed TraderTraitor-a specific subunit of the RGB 3rd Bureau-to execute the drain.

The Role of Blockchain Analytics Firms

Tools like TRM Forensics and Chainalysis have had to evolve rapidly. Five years ago, tracing Bitcoin was straightforward. Today, investigators need cross-chain visualization. TRM introduced "Phoenix," a tool designed specifically to trace flows across bridges. Without such tools, the data is siloed. An analyst looking at Ethereum sees funds leave. An analyst looking at Tron sees funds arrive. Connecting the two requires sophisticated matching algorithms.

These firms work closely with law enforcement. In August 2023, the FBI released a list of Bitcoin addresses linked to the Lazarus Group, urging exchanges to halt transactions. This collaboration is critical. However, the arms race continues. As analytics improve, hackers use obscure blockchains-networks with fewer nodes and less coverage-to hide in the dark corners of the crypto ecosystem. They also issue their own tokens, creating synthetic layers that further confuse automated trackers.

A missile made of gold bars and crypto tokens rising from mountains

Geopolitical Stakes: More Than Just Money

Why does this matter to you if you don't live in Seoul or Washington? Because this money buys missiles. A UN report indicates that up to 50% of North Korea's foreign currency earnings come from cybercrime. The Wilson Center estimates that North Korean hackers stole $660.5 million in 2023, jumping to $1.34 billion in 2024, and exceeding $2 billion in 2025 alone. The Bybit heist alone surpassed all of 2023's combined thefts.

This revenue directly funds the regime's nuclear and ballistic missile programs. When you hear about sanctions being ineffective, look at the blockchain. The ability to launder billions through cross-chain swaps allows the DPRK to bypass traditional banking restrictions. It turns digital theft into geopolitical leverage. If the West wants to curb proliferation, it must crack down on the OTC desks and exchanges that facilitate the final off-ramp for these laundered assets.

What You Can Do as an Investor

If you hold crypto, you aren't immune to this wave. Here are practical steps to protect yourself from the fallout of DPRK-style operations:

  1. Check Your Exchange's Compliance: Does your platform use real-time cross-chain monitoring? Ask them. Smaller exchanges may lack the tools to flag rapid bridge hops.
  2. Beware of Job Scams: If a recruiter contacts you on LinkedIn offering a remote crypto role, verify their company independently. Don't click links in unsolicited messages.
  3. Use Hardware Wallets: Keep private keys offline. Even if a website is compromised, your hardware device won't sign a malicious transaction unless you physically approve it.
  4. Monitor Large Transfers: Use free explorers like Etherscan or Blockchair to watch for unusual activity in your wallet. Set alerts for large outbound transactions.

The landscape is shifting. We are no longer dealing with script kiddies testing passwords. We are facing nation-state actors with military-grade resources and a desperate need for cash. Understanding their methods helps you anticipate risks. Stay skeptical of easy opportunities, and always assume that every digital footstep is being watched-and possibly laundered.

What is the Lazarus Group?

The Lazarus Group is a computer-based attack organization sponsored by the government of North Korea. It operates under the Reconnaissance General Bureau (RGB), the country's primary intelligence agency. The group is responsible for major cyberattacks, including the Sony Pictures hack and numerous cryptocurrency thefts.

How do cross-chain bridges help launder money?

Cross-chain bridges allow assets to move between different blockchains (e.g., Ethereum to Bitcoin). By rapidly converting and moving funds across multiple chains, hackers break the direct transaction history. This makes it difficult for analytics firms to trace the full path of stolen funds in real-time, providing a layer of obfuscation.

Why did North Korea stop using mixers like Tornado Cash?

Regulatory pressure increased significantly after 2022. Tornado Cash and similar services were sanctioned by the US Treasury. Many exchanges began blocking deposits from addresses associated with these mixers. To avoid frozen assets, North Korean hackers shifted to cross-chain bridges, which were initially less regulated and harder to monitor comprehensively.

How much crypto has North Korea stolen recently?

According to Elliptic and TRM Labs, North Korea-linked groups stole over $2 billion in 2025 alone. This includes the record-breaking $1.4 billion Bybit hack in February 2025. In 2024, they stole approximately $1.34 billion across 47 incidents. These figures highlight a steady escalation in both frequency and scale of attacks.

What is the "flood the zone" technique?

"Flood the zone" is a tactic where hackers execute a massive number of small, rapid transactions across multiple platforms simultaneously. This overwhelms compliance teams and automated monitoring systems, making it difficult to identify the primary flow of funds amidst the noise. It prioritizes speed and volume over stealth.