South Korea Hunts the Crypto Money That Arms Pyongyang
The G7 summit held in Évian-les-Bains, France, on June 17 and 18, 2026, produced a joint statement expressing "deep concern" over North
- The G7 summit held in Évian-les-Bains, France, on June 17 and 18, 2026, produced a joint statement expressing "deep concern" over North
- Introduction: a digital bridge between Seoul and North Korea's arsenal
- A signal sent from Évian-les-Bains
Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.
Introduction: a digital bridge between Seoul and North Korea's arsenal
A signal sent from Évian-les-Bains
The G7 summit held in Évian-les-Bains, France, on June 17 and 18, 2026, produced a joint statement expressing "deep concern" over North Korea's nuclear and ballistic missile programs. G7 leaders renewed their call for joint action against the cryptocurrency theft orchestrated by Pyongyang, a phenomenon that the United Nations and several blockchain analytics firms directly link to the regime's funding of weapons of mass destruction, according to a report published by Cointelegraph.
This latest warning is not an isolated one. It echoes the one issued at the June 2025 G7 summit in Canada, where the host nation had already urged members to jointly tackle the "North Korean regime's cryptocurrency thefts" that feed its arsenal. A year later, the picture has worsened: according to Chainalysis, North Korean hackers stole at least $2 billion in crypto assets in 2025 alone, bringing the cumulative total attributed to DPRK-linked actors to at least $6.75 billion.
Seoul, on the front line both geographically and technically
No country is more directly exposed than South Korea. Bordering Kim Jong-un's regime and home to one of the world's most active crypto-asset ecosystems, it serves as both a prime target and a testing ground for countermeasures. South Korea's National Intelligence Service (NIS) has built, together with private blockchain analytics firms, a real-time tracing capability for stolen funds, a partnership that has already, in the past, intercepted transfers before they vanished into the opacity of exchanges and cryptocurrency mixers.
This fight is not a theoretical exercise in regulatory compliance. Every dollar intercepted is a dollar that never reaches Pyongyang's missile production lines or proliferation labs. It is this direct, documented, quantified link that turns a question of financial cybersecurity into a full-blown matter of Western national security.
The damning figure: $6.75 billion since 2017
A steady escalation, documented year after year
The cumulative total of $6.75 billion stolen since 2017 is not a vague estimate: it comes from the cross-referenced work of Chainalysis, the UN Panel of Experts on North Korean sanctions, and several specialist firms such as Crystal Intelligence and TRM Labs. According to the Multilateral Sanctions Monitoring Team (MSMT), North Korea stole at least $1.19 billion in 2024, then $1.645 billion between January and September 2025 alone, driven in particular by the spectacular theft of $1.4 billion from the Bybit platform in February 2025.
The pace has not slowed in 2026. Data cited by CyberWireUSA already point to $1.4 billion stolen in the first quarter of this year alone. A CrowdStrike report published on May 15, 2026, named North Korean actors the largest cyber-threat group measured by the value of crypto assets stolen, with campaigns that deliberately prioritize high-value targets.
South Korean testimony at the UN
During a Security Council session devoted to the file, a South Korean representative said that a single domestic crypto company had more than $30 million stolen from it since the Panel of Experts' report was published, a stark reminder that the threat is not abstract but hits the peninsula's digital economy concretely. A separate report by Crystal Intelligence, dated May 15, 2026, and carried by Reuters, puts illicit crypto transactions traced in South Korea between 2021 and August 2025 at $7.1 billion, of which $6.4 billion is linked to a cross-border laundering technique called "hwanchigi."
The fake IT-worker scheme
Stolen identities, diverted salaries
On March 12, 2026, the U.S. Treasury Department sanctioned six individuals and two entities for their role in a scheme orchestrated by the North Korean government using fake IT workers to infiltrate Western companies. This network generated nearly $800 million in 2024 alone, a sum funneled directly into Pyongyang's weapons of mass destruction programs, according to the Office of Foreign Assets Control (OFAC).
The mechanics are chillingly simple: North Korean nationals, armed with falsified identities and sometimes assisted by deepfake-rigged job interviews, land remote developer or engineering jobs at American, European or Asian companies. Their salaries, often paid in stablecoins like USDC or USDT, are then converted and routed to Pyongyang through intermediaries based in China, Vietnam, Laos and even Spain.
Amnokgang, the shell company at the heart of the operation
Among the sanctioned entities is the Amnokgang Technology Development Company, founded in 1982, which manages teams of North Korean IT workers abroad and had seven cryptocurrency addresses on the Ethereum and Tron networks frozen. The Treasury's action also froze a total of 21 wallet addresses across several blockchains, including one belonging to Nguyen Quang Viet, the head of a Vietnamese company accused of converting roughly $2.5 million in cryptocurrency for the regime between mid-2023 and mid-2025.
South Korean intelligence, in its annual report, tracks the growth of this human infrastructure: the number of people working in North Korea's cyber divisions is said to have risen from 6,800 in 2022 to 8,400 in 2024, a shadow army made up of IT infiltrators, cryptocurrency thieves and military hackers.
The precedents that prove the method
Operation Harmony and the hunt for the intercepted million
Recent history offers a revealing precedent for how Seoul actually operates. A CNN investigation revealed that in January, shortly after North Korea launched three ballistic missiles into the ocean, a team of South Korean operatives and American private detectives met quietly at the headquarters of the National Intelligence Service in Pangyo, South Korea's "Silicon Valley." Their target: part of the $100 million siphoned from the California-based crypto firm Harmony.
When the hackers transferred a fraction of the stolen funds to a dollar-linked account, the team alerted U.S. authorities, who were able to freeze the assets. The result of that fleeting window of opportunity: roughly $1 million seized. A drop in the bucket against the $100 million total, but proof that rapid cooperation between South Korean intelligence and blockchain analysts can produce concrete results.
ChipMixer and Sinbad, the laundering tools dismantled
This hunt is part of a broader series of operations. On March 15, the U.S. Department of Justice, working with European agencies, announced the shutdown of the cryptocurrency mixing service ChipMixer, used by North Korean actors to launder part of the roughly $700 million stolen in three separate cyberattacks, including the Harmony hack. Another service, Sinbad, was sanctioned by the U.S. Treasury in late 2023 for laundering a "significant portion" of several major thefts.
The historic hack of Upbit, South Korea's largest exchange, illustrates the scale of the threat: in November 2019, hackers linked to North Korea's Reconnaissance General Bureau stole roughly 342,000 Ether, a sum now valued at more than 1.47 trillion won. South Korean police did not formally confirm Pyongyang's involvement until November 2024, five years later, illustrating the slowness and complexity of these cross-border investigations.
South Korea's regulatory pushback
Rules among the strictest in Asia
Facing this sustained pressure, Seoul has toughened its regulatory arsenal. All virtual-asset service providers in the country must now maintain real-name verified bank accounts with domestic banking institutions, one of the strictest know-your-customer requirements in Asia. On March 6, 2026, South Korea's financial intelligence unit (FIU) took its harshest enforcement action to date against a local platform: a fine of $24.6 million and a six-month partial suspension for 6.65 million violations of anti-money-laundering rules.
On the same topic
ESSAY: Fourth Heat Wave — Europe Enters the Age…
On July 28, 2026, the New York Times reports that the…
ANALYSIS: Venezuela — a Transition Written in Washington, Negotiated…
It was Marco Rubio , the U.S. Secretary of State, who…
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
That penalty, dramatic as it was, was subsequently overturned by the Seoul Administrative Court in May 2026, a setback that illustrates the permanent tension between regulatory resolve and the appeal rights of private actors. Despite this, Crystal Intelligence's initial review of peer-to-peer exchanges conducted in March 2026 indicates that unregulated activity persists, particularly around certain privacy-focused cryptocurrencies deemed high-risk for laundering.
An international cooperation effort becoming institutionalized
A National Intelligence Service spokesperson confirmed to CNN the existence of a "rapid intelligence-sharing" initiative with allies and private entities to counter this threat, with particular attention paid to the mixing services North Korea uses to obscure the origin of its cryptocurrency. This trilateral cooperation, including the United States and Japan, had already produced a joint statement expressing concern over how the DPRK finances its programs "through theft and money laundering, as well as malicious cyber activity."
The U.S. Department of Justice, for its part, has launched civil forfeiture proceedings targeting more than $7.7 million in cryptocurrency, non-fungible tokens and digital assets linked to a laundering network run by North Korean actors, some of whom were employed as developers under false identities such as "Joshua Palmer" or "Alex Hong."
The Iranian precedent and the mirror of evaded sanctions
A method shared among pariah regimes
North Korea is not inventing anything new: it is refining methods already seen among other regimes under international sanctions, notably Iran, which has also built financial workaround circuits through cryptocurrency to dodge Western measures aimed at its nuclear program. This methodological convergence between Tehran and Pyongyang illustrates an unsettling reality: the tools of decentralized finance, designed to democratize access to money, are now being systematically hijacked by the regimes most hostile to the rules-based international order.
Financial security analysts note that laundering techniques via mixers and decentralized exchanges circulate between state-linked criminal networks, know-how that spreads almost like a franchise of transnational crime. Russia, too, has been identified as a facilitator of certain North Korean cash-out operations, an intermediary that helped launder at least $60 million tied in part to the Bybit hack.
A convergence that worries Western services
This informal cooperation among regimes hostile to the West, whether deliberate or merely opportunistic, reinforces the need for a unified Western response that does not treat each file in isolation. Handling North Korean crypto financing on its own, without accounting for its connections to Iranian and Russian sanctions-evasion networks, is like fighting a fire while ignoring that it's spreading on the same wind.
Western intelligence services, from the U.S. Treasury to European agencies, are beginning to map these overlaps, but the pace of the institutional response still lags behind the pace of criminal adaptation.
The gray zones of international law facing cryptocurrency
Jurisdictions struggling to cooperate
The current international legal framework was not built for a world where digital assets cross dozens of jurisdictions in a matter of seconds. UN Security Council resolutions imposing sanctions on North Korea date from an era when illicit financial transfers mainly moved through traditional bank accounts, easier for national authorities to freeze and trace.
Today, a cryptocurrency mixer based nowhere and everywhere at once can undo months of investigative work in a few clicks. This technological asymmetry between the pace of criminals and the pace of regulators remains one of the biggest structural challenges in the fight against proliferation financing.
Toward harmonized international regulation?
Some experts argue for creating a harmonized international framework for crypto-asset regulation, modeled on the standards of the Financial Action Task Force (FATF) for traditional anti-money-laundering efforts. Such a framework would impose minimum identity-verification obligations on every exchange platform, regardless of its home jurisdiction, closing the loopholes exploited by North Korean networks.
But this harmonization runs into political and economic resistance: some offshore financial centers profit precisely from the regulatory fog they host, a business model they are in no hurry to abandon, even in the face of damning evidence of indirect complicity in nuclear proliferation financing.
What Washington expects from its Asian allies
Japan and South Korea, pillars of regional vigilance
The United States views Japan and South Korea as indispensable pillars of any effective strategy against North Korean crypto financing, thanks to their geographic proximity and their recognized technical expertise in financial cybersecurity. The trilateral statement among these three countries, expressing shared concern over the DPRK's financing methods, illustrates this reinforced regional security architecture.
This trilateral cooperation is not limited to diplomatic statements: it includes joint technical intelligence-sharing exercises and accelerated asset-freezing protocols when suspicious transfers are detected in real time, an operational capability proven during the Pangyo operation.
Pressure that must extend to Europe
While the Washington-Seoul-Tokyo axis remains central, several analysts believe Europe must step up its own vigilance, particularly given documented laundering cases passing through jurisdictions such as Spain. The G7, which includes several European powers, has certainly voiced collective concern, but few concrete, binding measures have been adopted continent-wide to strengthen oversight of European exchange platforms.
This European gap is a strategic blind spot that Pyongyang, always on the lookout for the least-watched loopholes, could exploit further as pressure tightens in Asia and North America.
The human stakes behind the abstract numbers
Lives shaped by a totalitarian system
Behind the dizzying statistics of billions of dollars stolen lie individuals, often young North Korean engineers trained from adolescence in state programs specializing in computer science, sent abroad under constant performance pressure, required to hand over most of their earnings to the regime under threat of reprisals against the families left behind.
This system, documented by several defectors and researchers specializing in North Korean human rights, resembles a form of digital forced labor, where individual technical skill serves exclusively the strategic interests of a totalitarian state apparatus, with no real benefit to the workers themselves beyond their own survival and that of their loved ones.
A dimension too often forgotten in the debate
This human dimension deserves to be recalled, because public debate focuses almost exclusively on the technical and geopolitical aspects of the file, leaving aside the reality of workers who very often have no real choice in their participation in this system. Understanding this dimension does nothing to diminish the seriousness of the threat to Western security, but it is a reminder that North Korea remains, first and foremost, a regime that exploits its own population as much as the loopholes of the international financial system.
This reality reinforces, if it needed reinforcing, the conviction that Western pressure must target the regime's structures rather than the individuals forced to survive within them, an essential nuance in any long-term sanctions strategy.
Lessons for Western regulators facing the urgency
A permanent race against the clock
The North Korean file illustrates an unavoidable truth for every Western regulator: decentralized finance evolves faster than public institutions' capacity to oversee it. Every new protocol, every new blockchain, every new privacy service potentially creates a new loophole exploitable by hostile state actors like North Korea, Russia or Iran.
American, South Korean and European authorities must invest massively in the technical training of their financial investigators, a field where demand for blockchain-analysis skills far outstrips the current supply of qualified personnel within government agencies.
The urgent need for a common Western doctrine
Beyond technical resources, what is still missing is a common political doctrine. Western allies would benefit from establishing standardized rapid-response protocols for suspicious transfers, rather than reacting case by case according to the varying capabilities of each national jurisdiction.
Such a common doctrine would send a clear signal to Pyongyang, Moscow and Tehran: the window of opportunity to launder stolen funds shrinks as Western coordination tightens, making every cryptocurrency theft operation more costly and riskier for the regime commissioning it.
Kim Jong-un and the openly offensive posture
Missile tests confirming the military trajectory
Kim Jong-un personally oversaw ballistic missile tests, according to North Korean state media cited by Reuters on April 19, 2026, calling for a "stronger offensive posture." This rhetoric cannot be separated from the financing: every dollar laundered through crypto circuits directly fuels the infrastructure that makes these tests possible. The link between financial cybercrime and ballistic proliferation is no longer an analyst's hypothesis, it is a causal chain documented by the U.S. Treasury itself.
According to Deutsche Welle, this insistence on a strengthened military posture fits into a context where Pyongyang seeks to demonstrate its resilience against international sanctions, precisely by relying on alternative revenue like cryptocurrency theft to circumvent the financial isolation imposed by UN resolutions.
Pyongyang denies, the evidence piles up
In a statement published on May 3 by the state agency KCNA, a spokesperson for North Korea's Foreign Ministry accused the United States of spreading "false accusations" about the North Korean cyber threat. This systematic denial contrasts sharply with the accumulation of technical evidence: blockchain tracing, identified wallet addresses, sanctions documented by name, and above all guilty pleas secured in the United States against accomplices in the scheme, including an American citizen from Arizona who ran a "laptop farm" that generated more than $17 million for the regime.
The latest annual threat assessment from the Office of the Director of National Intelligence (ODNI), presented to Congress on March 18, 2026, states that North Korea "probably stole $2 billion" in crypto assets in 2025 alone, an assessment that confirms, at the highest level of U.S. intelligence, the scale of the problem.
The murky role of Chinese banks
At least fifteen institutions identified
The Multilateral Sanctions Monitoring Team report is unambiguous on one point: at least fifteen Chinese banks have been identified as having been used to launder funds linked to illegal North Korean IT work or cyberattacks. DPRK actors rely heavily on over-the-counter brokers based in China to convert their stolen cryptocurrency into hard cash, a crucial step that turns a traceable digital asset into money that is nearly untraceable.
A U.S. Treasury action in November 2025 sanctioned eight individuals and two organizations accused of helping Pyongyang launder more than $3 billion in cryptocurrency over three years, including North Korean bankers who oversaw millions of dollars in transactions for First Bank and Korea Daesong Bank. These figures confirm that China is not a passive actor in this shadow economy, but rather a transit ground that has become indispensable to the regime.
A responsibility Beijing refuses to accept
Despite these repeated findings, no significant sanctions have ever targeted Chinese banking institutions directly, only individuals or occasional representatives. This asymmetry feeds legitimate skepticism: how else to explain that flows of several billion dollars consistently pass through the same country without any lasting institutional consequence for the banks involved?
The question points to a broader geopolitical dynamic: China, like Russia and Iran, indirectly benefits from the weakening of the Western sanctions regime against North Korea, even while officially claiming to support UN resolutions.
The American guilty pleas that expose the network
The Arizona laptop farm
In the United States, several court cases have laid bare the scheme's inner workings. Christina Marie Chapman, a 44-year-old American citizen from Arizona, pleaded guilty in 2025 to running a "laptop farm" for three years that facilitated the fraudulent employment of North Korean operatives. Her operation touched more than 300 American companies and generated more than $17 million for the North Korean government.
In December 2024, the Department of Justice indicted fourteen North Korean nationals for generating at least $88 million over six years. A month later, two Americans were indicted for placing North Korean operatives at more than 60 U.S. companies, generating more than $800,000 in illegal revenue.
An average take of $300,000 per worker
According to U.S. government estimates, a typical team of North Korean IT workers can bring in up to $3 million a year, with each individual worker generating an average of $300,000 annually, all of it funneled to the North Korean government and its weapons programs. This discreet, diffuse criminal business model proves remarkably profitable compared with the spectacular cyberattacks that draw more regulatory attention.
It is precisely this discretion that makes the phenomenon so hard to root out: unlike a massive hack like Bybit's, the infiltration of IT workers blends into the normal economy of remote work, a sector that has been booming since the pandemic.
Lessons for Western companies
Strengthening identity verification
Cybersecurity experts now recommend that Western companies considerably strengthen their identity-verification procedures for remote hiring, particularly for technical positions tied to decentralized finance and cryptocurrency. Deepfake-rigged video interviews, fabricated references and falsified identity documents are now standard warning signs that HR departments must learn to systematically spot.
The FBI and several partner agencies have already seized digital assets linked to these laundering networks, including USDC and ETH tokens and high-value non-fungible tokens, showing that rapid post-detection action remains possible even after the initial fraudulent hire.
Public-private cooperation as a bulwark
Blockchain analytics firms like Chainalysis, TRM Labs and Crystal Intelligence now play a nearly institutional role in detecting these schemes, working in close coordination with Western and Asian governments. This public-private cooperation is one of the rare bright spots in this file: it proves that a coordinated response, even against an organized state adversary, can produce tangible, measurable results.
Still, this cooperation must extend well beyond the narrow circle of aligned Western and Asian powers, to include more jurisdictions through which North Korean funds pass, notably Vietnam, Laos and certain peripheral European states such as Spain.
Discover
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
BILLET: Altman and Huang Head to the Senate as…
According to Boursorama , Sam Altman of OpenAI and Jensen Huang…
Conclusion: digital vigilance as the new frontier of deterrence
A fight that is only beginning
The sequence of recent months, from the G7 summit in Évian-les-Bains to the U.S. Treasury's sanctions, by way of the damning reports from Chainalysis and Crystal Intelligence, draws a clear conclusion: North Korean military financing through cryptocurrency is no longer a blind spot in international security. It is an active front, where South Korea, on the geographic front line, has built internationally recognized expertise in tracing and intercepting stolen funds.
But victory is far from secured. The $6.75 billion accumulated since 2017 by North Korean actors shows that, despite sanctions, laundering-service shutdowns and strengthened international cooperation, the pace of theft keeps rising year after year. The fight against this shadow economy will require Western coordination far more systematic than the mere accumulation of summit communiqués.
The West facing its own regulatory lag
This file illustrates a broader truth: Western democracies, however quick they are to denounce cyber threats from Pyongyang, Beijing, Moscow or Tehran, must also accelerate their own regulatory reforms on crypto assets. Every poorly supervised exchange, every mixing service not sanctioned in time, every company duped by a fake IT worker becomes a breach exploited by a regime that has made digital fraud a pillar of its strategic and military survival.
The solidarity displayed among Seoul, Washington and G7 partners must now translate into measurable results: more funds intercepted, more networks dismantled, and above all, a tangible reduction in the flow of currency fueling Kim Jong-un's ballistic tests.
By Maxime Marquette, columnist
Columnist's transparency note
My sources and my limits
This column draws on public reports from the U.S. Treasury Department, analyses from specialist firms such as Chainalysis, Crystal Intelligence and TRM Labs, and reporting from CNN, Reuters, Cointelegraph and Deutsche Welle. I did not have access to classified South Korean intelligence documents or to sources inside the North Korean regime: my analysis therefore remains dependent on information made public by Western governments and blockchain analytics companies, each of which has its own institutional or commercial interest in documenting this threat.
My acknowledged biases
I am openly in favor of a firm Western posture toward the regimes of Pyongyang, Moscow, Tehran and Beijing, and I regard South Korea as an essential strategic partner for the West in Asia. This editorial orientation changes nothing about the figures cited, all of which are attributed and sourced, but it inevitably colors the tone of my personal comments, identified in italics in the text.
Sources
Primary sources
Reuters — Kim Jong-un oversees ballistic missile tests, April 19, 2026
U.S. Treasury Department — Sanctions against North Korean fake IT-worker fraud network, March 12, 2026
Cointelegraph — G7 calls for joint action against North Korean crypto theft, June 18, 2026
Secondary sources
Deutsche Welle — Kim Jong-un calls for stronger offensive posture, April 2026
Reuters/Crystal Intelligence — South Korea traces $7.1 billion in illicit crypto assets, May 15, 2026
Binance Square — U.S. freezes crypto network that funneled $800 million to Pyongyang, March 12, 2026
CNN — Inside South Korea's interception operation against North Korean crypto hackers
Wikipedia — The North Korean fake IT-worker scheme
Get the geopolitics analyses
Conflicts, powers, alliances: the MadMax thread without the noise.
Cite this article
Maxime Marquette (2026). South Korea Hunts the Crypto Money That Arms Pyongyang. MadMax. https://mad-max.co/en/article/la-coree-du-sud-traque-l-argent-crypto-qui-arme-pyongyang
Enjoyed this piece? Get the next one.
One chronicle a week, straight to your inbox. No noise.
This article was generated with AI assistance, under human supervision.
Comments
Be the first to weigh in.