Kim Jong-un, the Regime That Traded Gold for Stablecoins
Some reports slip by unnoticed. Others should wake up every foreign ministry in the West. The one published on June 29, 2026
- Some reports slip by unnoticed. Others should wake up every foreign ministry in the West. The one published on June 29, 2026
- Introduction: an isolated country, a digital currency
- A report that should unsettle
Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.
Introduction: an isolated country, a digital currency
A report that should unsettle
Some reports slip by unnoticed. Others should wake up every foreign ministry in the West. The one published on June 29, 2026 by the Chosun Ilbo clearly belongs to the second category. It documents, in black and white, how North Korea has turned its longstanding dependence on stolen currency into a sophisticated laundering system running through stablecoins — cryptocurrencies pegged to the US dollar that promise stability and relative anonymity.
This is not a technical footnote for decentralized-finance enthusiasts. It is the portrait of a regime that understood, faster than many democratic governments, how to exploit the cracks in a global financial system still poorly prepared for the digital-asset revolution. The central figure of this story has no clear media face: it is a state apparatus, the Office 221, front companies like Sinyang, and, in the background, Kim Jong-un, whose nuclear program depends directly on these parallel financial flows.
Why this portrait matters now
The shift is stark. According to Chainalysis, the crypto-analytics firm, 84 percent of crimes tied to virtual assets in 2025 involved stablecoins, compared with a share dominated at 72 percent by Bitcoin back in 2020. In five years, Bitcoin has fallen to just 16 percent of this criminal usage. The message is unambiguous: criminals, like rogue states, follow stability and efficiency, not speculation.
Office 221, the quiet heart of the system
A little-known but central unit
Office 221 is not a name found in mainstream geopolitics textbooks, and that is precisely the problem. This North Korean structure was identified by the Chosun Ilbo as having attempted, in 2024, to sell several tons of gold in order to obtain roughly 300 million dollars in Tether, the world's largest stablecoin by market capitalization.
The operation illustrates a clear logic: convert a traditional physical asset, gold, into a liquid digital asset that can be moved across borders without passing through the monitored international banking system. Sinyang, another North Korean company, reportedly attempted that same year to pay for Russian fuel directly in Tether, sidestepping the classic banking clearance mechanisms that Western sanctions can block.
The UN documents it, experts confirm it
In October 2025, a United Nations report had already detailed concrete cases in which North Korea actively used Tether in illegal transactions involving weapons and fuel. This is not a hypothesis floated by overzealous journalists: it is a reality documented by the very international body meant to oversee sanctions enforcement.
The UN Panel of Experts on North Korea has further estimated, in its annual reports, that a material share of funding for North Korea's ballistic missile and nuclear weapons programs comes directly from stolen cryptocurrency, according to an analysis relayed by the specialized platform sanctions.io.
Lazarus Group, Pyongyang's digital armed wing
A track record that induces vertigo
It is impossible to discuss North Korean financial crime without mentioning the Lazarus Group, the unit attached to North Korea's Reconnaissance General Bureau. According to the sanctions.io report published on June 10, 2026, actors linked to North Korea stole 2.02 billion dollars in cryptocurrency during 2025 alone, a 51 percent increase over the previous year.
The historical cumulative total now stands at 6.75 billion dollars. More striking still: through April 2026, roughly 76 percent of all major cryptocurrency thefts were attributed to North Korean hackers. These figures are not journalistic exaggeration; they come from a firm specializing in compliance and financial sanctions analysis.
The heist of the century: the Bybit affair
The most emblematic theft remains the one targeting the exchange Bybit, in February 2025: 1.5 billion dollars in Ethereum stolen, making it the largest cryptocurrency theft in history. The FBI attributed the operation to the TraderTraitor subgroup, linked to Lazarus Group.
The method is chillingly precise: attackers compromised the laptop of a developer working at SafeWallet, the multisignature infrastructure provider used by Bybit, manipulating the cold wallet signing process to redirect roughly 500,000 ETH to attacker-controlled addresses. Another exploit, targeting Kelp DAO in April 2026, siphoned off an additional 292 million dollars.
The laundering machinery explained
Four well-oiled steps
The sanctions.io report details a four-step laundering typology now well identified by analysts in 2026. First, a rapid cross-chain move: within hours of a theft, funds are shifted to Ethereum, where mixing and liquidity options are greater.
Next comes the use of alternative mixing services operating outside US jurisdiction, since Tornado Cash was taken offline. The third step is systematic chain-hopping: funds move from Ethereum to Avalanche, then Binance Smart Chain, then Bitcoin, via bridges and decentralized exchanges with no identity verification.
The final conversion into cash
The last step is conversion into real currency through over-the-counter desks, particularly in Southeast Asia and the Middle East, regions where regulatory coverage of crypto-to-fiat conversion remains thinner. This is where stablecoins play an essential anchoring role: their dollar-pegged value greatly simplifies these complex transactions.
Regulated platforms impose strict identity verification, comparable to that of traditional banks. But the decentralized nature of blockchain makes it easy to move funds to off-platform wallets, where laundering becomes far simpler, according to the Chosun Ilbo.
The fake IT-worker program
From job application to infiltration
Another part of the North Korean apparatus deserves attention: the IT worker program. What began with agents applying for remote jobs at cryptocurrency companies has evolved into orchestrated fake hiring processes aimed directly at prestigious Web3 and artificial intelligence firms.
The goal is clear: obtain access credentials, source code, and internal VPN access. In March 2026, new OFAC designations — the US sanctions body — specifically targeted wallet addresses, front companies, and individuals tied to this program.
A permanent adaptation to sanctions
What strikes financial-security analysts is the regime's capacity to adapt. After OFAC designated the Lazarus Group on the specially designated nationals list on April 14, 2022, and after Tornado Cash co-founder Roman Storm was convicted in August 2025 for sanctions violations, Pyongyang never stopped adjusting its methods.
The UN Panel of Experts continues to document these operations in its annual reports with specific transaction analyses. The European Union and the United Kingdom also maintain consolidated sanctions lists modeled on UN designations.
A geopolitical backdrop that makes everything worse
North Korea is not acting alone
It would be naive to treat this parallel financial system as an isolated phenomenon. North Korea maintains growing economic and military ties with Russia, notably through the documented attempts to pay for Russian fuel in Tether via Sinyang. This convergence between sanctioned regimes illustrates a broader trend: the formation of an alternative financial ecosystem among states hostile to the Western-led international order.
China, though not directly named in the transactions documented by the Chosun Ilbo, remains historically the preferred transit route for a large share of North Korean financial flows, legal or otherwise. This sanctions-evasion architecture structurally benefits every actor seeking to weaken Western influence over the global financial system.
The risk of methodological contagion
What should worry us beyond the North Korean case is the possibility that other regimes, particularly Iran, could draw on this methodology for their own sanctioned financing needs. Stablecoin laundering mechanisms are not proprietary to Pyongyang: they are techniques replicable by anyone with the necessary technical skills.
Economic experts cited by the Chosun Ilbo flag precisely this systemic risk and call for stricter regulation, even as the crypto industry itself fears this could dilute the main advantage of stablecoins: enabling fast transactions outside traditional centralized financial networks.
The Western regulatory response, still timid
Tools that exist but remain insufficient
American authorities have not been entirely passive. OFAC regularly publishes blacklists of wallet addresses following major attribution events, as it did after the Bybit hack. The FBI has also issued public service announcements including wallet blocklists representing the most current public intelligence on active laundering addresses.
But these measures consistently arrive after the fact, never ahead of it. The sanctions.io report specifically recommends that crypto compliance teams monitor chain-hopping patterns, the use of bridges without identity verification, and new wallets receiving large transfers with no prior history.
Concrete recommendations from experts
Among the practical recommendations are real-time alerts for any deposit originating from addresses newly listed on OFAC or FBI blocklists, along with heightened scrutiny of transactions involving mixing services, even those not yet formally sanctioned.
Major centralized exchanges should, according to these same recommendations, impose mandatory holding periods on large withdrawals to new addresses and real-time OFAC screening as a baseline requirement. These measures exist in theory, but their application remains uneven across jurisdictions.
What this means for global security
The direct link to nuclear weapons
It bears repeating plainly: according to analyses from the UN Panel of Experts relayed by sanctions.io, funds from stolen cryptocurrency finance a material share of North Korea's ballistic missile and nuclear weapons programs. This is therefore not a purely financial or technical matter — it is a direct international security issue.
Every dollar laundered through Tether or any other stablecoin represents a potential additional dollar available to fund the military ambitions of Kim Jong-un's regime, in a context where the Korean peninsula remains one of the most militarized zones on the planet.
A threat that goes beyond North Korea alone
This case also illustrates a broader truth about the world of 2026: authoritarian regimes, whether North Korea, Iran, or potentially other hostile actors tomorrow, now have access to financial tools that let them bypass a sanctions system designed for a pre-crypto world. The West must urgently close this regulatory gap.
The technological competition between democracies and authoritarian regimes is no longer fought only on military or industrial ground, but also on the quieter terrain of digital financial engineering. It is a front too few Western citizens still perceive as a priority.
The crypto industry's ambiguous role
Between innovation and complacency
The cryptocurrency industry finds itself in a delicate position. On one hand, it fiercely defends the qualities of stablecoins: speed, low transaction costs, global accessibility. On the other, it must acknowledge that those same qualities make them the ideal laundering tool for actors like North Korea.
According to the Chosun Ilbo, the crypto industry fears precisely that overly strict regulation could dilute the unique advantage of stablecoins — enabling fast transactions outside traditional centralized financial networks. This tension between commercial innovation and national security has not yet found a satisfying resolution.
Exchanges under pressure
Major exchanges find themselves on the front line. They must show regulators they have robust screening systems in place, while continuing to offer a competitive service against rivals that are sometimes less scrupulous, operating from jurisdictions with permissive regulation.
The case of Bybit, victim of the largest cryptocurrency theft in history despite its status as a regulated platform, shows that even the most serious players in the sector remain vulnerable to the growing sophistication of North Korean state-backed attacks.
Lessons for Western democracies
Investing in digital financial surveillance
This North Korean case should serve as a wake-up call for Western democracies. It is no longer enough to sanction after the fact: massive investment is needed in digital financial surveillance capabilities, training experts able to track blockchain flows in real time, and better coordinating efforts among OFAC, the UN, the European Union, and the United Kingdom.
The current fragmentation of sanctions regimes, even where they largely overlap, leaves exploitable gaps for actors as determined as the Pyongyang regime. Stronger coordination among allied jurisdictions would represent a significant step toward closing those gaps.
Strengthening international cooperation
Beyond technical measures alone, this case calls for deeper diplomatic cooperation among Western allies to financially isolate regimes that, like North Korea, use these techniques to fund weapons programs representing a direct threat to international security.
Transparency around these mechanisms, like that provided by the Chosun Ilbo report, is an essential first step. Without clear public information on the scale of the phenomenon, it becomes difficult to mobilize public opinion and policymakers around ambitious corrective measures.
Discover
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
BILLET: Altman and Huang Head to the Senate as…
According to Boursorama , Sam Altman of OpenAI and Jensen Huang…
The relative silence of the great powers
Washington amid competing priorities
It is also worth noting Washington's relative silence on this specific dossier, compared with the media attention devoted to other geopolitical crises. American authorities, absorbed by multiple simultaneous diplomatic and military fronts, may not be giving this financial question the attention it deserves.
This does not mean total inaction: the OFAC designations of March 2026 attest to that. But the pace of the regulatory response appears structurally slower than the pace of innovation among malicious actors, an imbalance that should alarm Western policymakers more than it currently does.
Europe, spectator more than actor
The European Union, for its part, keeps its sanctions lists aligned with those of the UN, but remains largely a follower rather than an initiator on this specific North Korean stablecoin dossier. A more proactive posture from European regulators would likely help close some of the gaps identified by compliance experts.
The United Kingdom, through its sanctions body OFSI, follows a similar trajectory of mirroring UN designations, without a particularly distinct initiative on the specific question of North Korean stablecoins at this stage.
The human factor behind the numbers
Engineers under duress
Behind these staggering numbers are individuals: North Korean developers and engineers recruited by force or economic necessity into this vast state cybercrime apparatus. The fake IT-worker program documented by sanctions.io suggests a pool of technical talent mobilized in service of geopolitical objectives far beyond their control.
We do not know, and it must be admitted honestly, to what extent these individuals act out of ideological conviction, regime coercion, or simple economic survival in a system where refusing to cooperate with the state can carry grave consequences for them and their families.
The system's indirect victims
Nor should we forget the indirect victims of this system: users of platforms like Bybit whose funds were compromised, Web3 companies targeted by fake recruiters, and more broadly the public's trust in an already reputationally fragile crypto ecosystem.
Every major documented theft, every new sanctions-evasion technique revealed, erodes a little more of the trust needed for cryptocurrencies to one day fulfill their original promise of financial inclusion rather than serve as a favored tool for the world's worst regimes.
Toward an inevitable technological race
Artificial intelligence enters the equation
One final element deserves mention: the growing sophistication of the social-engineering methods used by Lazarus Group, including fake Zoom interviews, fraudulent Calendly links, and rigged code-review requests, suggests increasing use of automated tools, potentially assisted by artificial intelligence, to industrialize these compromise campaigns.
On the same topic
OPINION: ChatGPT Takes Your Pulse — Public Health Entrusted…
OpenAI states, on the page announcing the launch of "Health in…
EDITORIAL: Measles — America Gives Up a Twenty-Six-Year-Old Public…
There is a line , in a table the CDC updates…
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
This technical evolution signals a likely escalation in the months ahead, where the adaptation speed of malicious actors could accelerate further, making the task facing Western compliance and security teams ever more complex.
An issue that goes beyond finance alone
At its core, this North Korean stablecoin dossier is just one facet of a much larger challenge: the West's ability to maintain its technological edge and regulatory pace against adversaries who have neither ethical scruples nor democratic constraints to slow their malicious innovation.
It is a stark reminder that national security in the twenty-first century is fought as much in lines of code and digital wallets as on traditional battlefields.
The Iranian precedent to watch closely
A convergence of sanctioned regimes
The North Korean case should not be viewed in isolation from a broader movement. Iran, also subject to severe international sanctions for decades, has likewise explored similar evasion mechanisms through cryptocurrency, according to several compliance analyses referenced in the sanctions.io report. The logic remains identical: turn a traditional asset blocked by sanctions into a fluid, transferable digital asset.
This methodological convergence between Tehran and Pyongyang illustrates a phenomenon Western analysts are only now beginning to map seriously: the emergence of genuine shared know-how among pariah regimes on best practices for digital financial evasion. This is no longer merely a bilateral matter between the United States and North Korea, but a systemic issue involving several simultaneous adversaries of the Western-led international order.
Russia, the quiet financial accomplice
The documented attempts by Sinyang to pay for Russian fuel in Tether also confirm that Russia participates, at least passively, in this parallel financial ecosystem. Moscow, itself under massive Western sanctions since the invasion of Ukraine, shares with Pyongyang a common structural interest: weakening the effectiveness of the dollar-based sanctions system and Western financial institutions.
This convergence between Russia, North Korea, and potentially Iran outlines the contours of an informal financial bloc, united not by shared ideology but by a shared interest in circumventing Western financial dominance. It is a development Western strategists can no longer afford to underestimate, given that its implications extend well beyond the Korean peninsula alone.
Conclusion: a portrait meant as a warning
An elusive but not invincible regime
The portrait that emerges of financial North Korea in 2026 is that of a paradoxical regime: diplomatically isolated, economically impoverished for its population, yet formidably agile in the field of emerging financial technologies. Office 221, the Lazarus Group, and front companies like Sinyang together form an apparatus that has managed to turn the constraint of sanctions into an opportunity for criminal innovation.
But this regime is not invincible. Repeated OFAC designations, growing coordination between Western intelligence agencies and blockchain analysis firms like Chainalysis, and increased vigilance from major exchanges show that a coordinated response remains possible, provided the necessary resources are committed.
What the West must remember
The main lesson of this case is simple to state but hard to implement: the pace of technological innovation among hostile regimes today outstrips the pace of the Western regulatory response. Closing this gap will require sustained investment, stronger international coordination, and political will that, for now, still seems insufficient given the true scale of the threat.
North Korea's nuclear program does not finance itself. Every dollar laundered through a stablecoin is a dollar that potentially fuels that program. That may be the single most important sentence to remember from this dossier, and the one that should guide the priorities of Western decision-makers in the months ahead.
By Maxime Marquette, columnist
Columnist's transparency note
Who I am and my acknowledged biases
I am a columnist, not a cybersecurity or blockchain-analysis expert. I write from an openly pro-Western position: I believe Western democracies, despite their imperfections, represent a preferable international order to the one regimes like North Korea, China, Iran, or Russia would offer. This conviction shapes my analysis, even as I strive to rely only on facts corroborated by reliable sources.
I have no privileged access to Western intelligence services or to internal North Korean contacts. Everything advanced in this profile comes from reports published by the Chosun Ilbo, specialized analysis from sanctions.io, and public data from companies like Chainalysis.
What I do not know, and my method
I do not know with certainty the exact proportion of North Korea's nuclear financing that comes specifically from stablecoins versus other illicit revenue sources. The figures cited in this text come from the best publicly available estimates, but the clandestine nature of these operations makes precise quantification difficult, if not impossible.
My method is to cross-reference multiple independent sources, prioritize reports from recognized organizations like the UN or specialized analysis firms, and explicitly flag areas of uncertainty rather than filling them with assumptions. I have invented no figure, no quote, no testimony in this article.
Sources
Primary sources
Chosun Ilbo, North Korea Leverages Stablecoins for Sanctions Evasion — June 29, 2026
Sanctions.io, The Lazarus Group and DPRK Crypto Theft in 2026 — June 10, 2026
Secondary sources
Reuters, regional context on threats from authoritarian regimes in Asia — July 3, 2026
Institute for the Study of War, China Taiwan Update — July 2, 2026
USA Today, context on US government transparency issues — July 2, 2026
Anadolu Agency, context on Western defense coordination — June 29, 2026
Get the tech columns
AI, platforms, digital power: the next analyses straight to your inbox.
Cite this article
Maxime Marquette (2026). Kim Jong-un, the Regime That Traded Gold for Stablecoins. MadMax. https://mad-max.co/en/article/kim-jong-un-le-regime-qui-a-troque-l-or-contre-les-stablecoins
Enjoyed this piece? Get the next one.
One chronicle a week, straight to your inbox. No noise.
This article was generated with AI assistance, under human supervision.
Comments
Be the first to weigh in.