How DPRK Hackers Launder Crypto Across Chains

How DPRK Hackers Launder Crypto Across Chains

Imagine stealing over $1.5 billion in a single night and then making it vanish into thin air before the police even finish their coffee. That’s exactly what happened in February 2025 when hackers linked to North Korea drained Bybit of its Ethereum reserves. But here is the kicker: they didn’t just hide the money; they scrambled it across so many different blockchains that tracing it became a nightmare for investigators. This isn’t just about thieves taking coins. It’s about a state-sponsored operation using cutting-edge tech to fund weapons programs while dodging global sanctions.

You might think blockchain is transparent. Every transaction is public, right? Well, North Korean hackers have figured out how to break that transparency by jumping between chains. They use something called cross-chain bridges. These are tools that let you move assets from one blockchain (like Ethereum) to another (like Bitcoin or Solana). For legitimate users, this is convenient. For the Lazarus Group, it’s a smoke screen. By constantly swapping assets and hopping networks, they create a trail so messy that traditional tracking methods fail.

The Evolution From Mixers to Bridges

A few years ago, if you wanted to clean dirty crypto, you used a mixer. Services like Tornado Cash or Sinbad would pool your coins with others, mixing them up so no one could tell which coin was yours. It worked well until regulators caught on. The US Treasury sanctioned Tornado Cash, and other mixers faced similar heat. Suddenly, using a mixer looked suspicious. So, the DPRK hackers pivoted.

Instead of mixing within one chain, they started moving funds *between* chains. This shift happened around 2022-2023. According to data from TRM Labs, this change wasn’t accidental. It was a direct response to enforcement pressure. When mixers got blocked, the hackers moved to bridges. Platforms like Avalanche Bridge and Ren Bridge became their new playgrounds. Bitdefender reported that the Lazarus Group alone pushed more than 9,500 Bitcoin through the Avalanche Bridge. That’s a massive volume designed to overwhelm any analyst trying to follow the money.

Inside the Lazarus Group’s Playbook

Who are these guys? They aren’t random criminals working out of basements. They operate under the Reconnaissance General Bureau (RGB), specifically the 3rd Bureau. The FBI has identified a subunit called TraderTraitor as the primary force behind recent major heists. Their goal isn’t just theft; it’s revenue generation for the regime.

Think about the scale. In 2023, North Korean hackers stole roughly $660 million. In 2024, that number jumped to $1.34 billion. By 2025, reports suggest they’ve already surpassed $2 billion. A senior Biden administration official noted in 2024 that nearly half of North Korea’s foreign currency earnings now come from cybercrime. That means every stolen Bitcoin helps buy oil, food, or parts for missiles.

Their method is brutal in its simplicity. First, they exploit a vulnerability-often a smart contract bug or a social engineering trick-to drain a wallet. Then, they hit the "flood the zone" button. Nick Carlsen, an expert at TRM Labs, describes this as overwhelming compliance teams with rapid-fire transactions. They don’t wait. They swap ETH for BTC, then BTC for XRP, then maybe route some through Tron or Binance Smart Chain. Each hop adds a layer of complexity. By the time analysts realize what’s happening, the funds are scattered across five or six different ecosystems.

Stylized hackers hopping across bridges connecting colorful blockchain islands.

Why Cross-Chain Hopping Works

Why does this work so well? Because most analytics tools were built for single-chain analysis. If you’re tracking Ethereum, you see Ethereum. If you track Bitcoin, you see Bitcoin. Connecting the dots requires specialized software. While firms like Chainalysis and Elliptic have improved their tools, the sheer speed of DPRK operations often outpaces detection.

They also exploit less popular chains. You might expect them to stick to the big names, but sometimes they route funds through obscure blockchains where liquidity is lower and monitoring is weaker. Once the funds are there, they might convert them into stablecoins or native tokens issued by smaller decentralized exchanges. This fragmentation makes it incredibly hard to calculate the total value of stolen assets in real-time.

Laundering Method Comparison: Mixers vs. Cross-Chain Bridges
Feature Mixers (e.g., Tornado Cash) Cross-Chain Bridges (e.g., Avalanche Bridge)
Primary Mechanism Pools and shuffles coins within one chain Converts assets from one blockchain to another
Detection Risk High (Sanctioned/Flagged addresses) Medium (Looks like normal user activity)
Speed Slow (Requires waiting periods) Fast (Automated swaps)
Regulatory Scrutiny Very High Growing but fragmented

The Human Element in Technical Attacks

Here is a twist you might not expect. While the laundering is technical, the initial theft is increasingly human. CoinDesk noted a strategic shift toward targeting individuals rather than just large exchanges. Why? Because executives and high-net-worth holders often have huge balances but weaker security protocols than institutional platforms.

Hackers use phishing emails, fake job offers, and compromised social media accounts to steal private keys. It’s low-tech deception leading to high-tech laundering. An executive clicks a bad link, loses access to their wallet, and the Lazarus Group immediately starts the cross-chain shuffle. This approach broadens the attack surface significantly. You can patch a smart contract, but you can’t easily patch a human error.

Art Deco artwork showing missiles rising from stacks of cryptocurrency blocks.

Global Security Implications

This isn’t just a crypto problem. It’s a geopolitical one. The United Nations has stated that North Korea’s weapons program is largely funded by these cyber operations. When the Bybit hack happened, it wasn’t just investors losing money. It was a transfer of wealth directly supporting nuclear proliferation efforts.

The international community is scrambling to respond. The FBI has intervened by urging exchanges to freeze known hacker wallets. But because the funds move so fast across borders and chains, freezing them is like trying to catch water with a sieve. Exchanges need better real-time data sharing. Analytics firms need to integrate cross-chain visibility into their core products faster. And regulators need to understand that blocking one bridge doesn’t stop the flow-it just redirects it.

What Comes Next?

The arms race continues. As soon as law enforcement figures out one bridge, hackers find another. We are likely to see more automation in their laundering processes. Instead of manual swaps, they may use sophisticated bots that execute complex multi-hop strategies in seconds.

For the average crypto user, this means vigilance is key. Don’t click suspicious links. Use hardware wallets. And be aware that while blockchain is transparent, it isn’t infallible against determined, state-backed adversaries who treat obfuscation as a science.

What is the Lazarus Group?

The Lazarus Group is a computer hacking organization originating in North Korea. It is associated with the Reconnaissance General Bureau (RGB), the country's primary foreign intelligence agency. They are responsible for numerous high-profile cyberattacks, including the Sony Pictures hack and multiple cryptocurrency thefts.

Why do North Korean hackers use cross-chain bridges?

They use cross-chain bridges to move stolen assets between different blockchains (like Ethereum to Bitcoin). This technique, known as "chain-hopping," breaks the direct transaction trail, making it much harder for blockchain analytics firms and law enforcement to trace the origin and destination of the funds compared to staying on a single chain.

How much crypto has North Korea stolen recently?

Estimates vary, but reports from firms like TRM Labs and Elliptic suggest North Korean hackers have stolen over $2 billion in cryptocurrency in 2025 alone. This follows approximately $1.34 billion in 2024 and $660 million in 2023. The February 2025 Bybit hack alone accounted for over $1.5 billion.

Are mixers still used for laundering?

Usage has declined significantly. Due to sanctions on services like Tornado Cash and increased scrutiny, hackers shifted towards cross-chain bridges starting around 2022-2023. However, they may still use mixers in combination with bridges to add extra layers of obfuscation.

How does this affect global security?

Cybercrime revenue is believed to fund a significant portion of North Korea's foreign currency needs, including its nuclear and missile programs. Therefore, successful crypto thefts directly contribute to the regime's ability to sustain its military capabilities despite international sanctions.

LATEST POSTS