How North Korean Hackers Launder Stolen Crypto Funds

By bonuz NewsroomPublished October 10, 2026
How North Korean Hackers Launder Stolen Crypto Funds

Bitget revised the scale of a September 2026 security breach to approximately $387.5 million (USD), as investigators traced how North Korea-linked hackers turn stolen crypto into usable cash. The case matters because it shows how billions in stolen digital assets slip past exchanges and regulators every year.

What actually happened

On 25 September 2026, Bitget said it had revised the value of assets moved to attacker addresses from roughly $351.6 million (USD) to approximately $387.5 million (USD). The company said the change reflected additional accounting for transfers involving Zcash and TRON, not a new theft, and that some assets had been frozen with help from industry partners, according to WuBlockchain. Blockchain analytics firm Elliptic said the same day that the attack was 'highly likely' linked to North Korea, citing ties to laundering addresses used in earlier North Korea-related thefts. In the February 2025 Bybit case, the US Federal Bureau of Investigation attributed a $1.5 billion (USD) theft to North Korea. Security firm zeroShadow said more than $1 billion (USD) of those funds was laundered between February and June 2025. Elliptic separately tracked about $200 million (USD) in Bybit funds through the exchange service eXch.

How we got here

The Bybit theft in February 2025 set the pattern now being studied in the Bitget case. zeroShadow and Elliptic both found that professional intermediaries, not the original attackers, often handle the bulk of laundering work. In September 2026, Chainalysis documented the Xinbi merchant network, which accepted traceable stolen funds and gave clients a separate pool of stablecoins mixed with proceeds from other scams. This fund-substitution model lets attackers step back from direct handling of stolen assets. It also means funds tracked on-chain may change hands early, with intermediaries absorbing the risk of freezes while paying attackers a smaller, laundered amount upfront.

Why this matters for you

For exchange users, the case is a reminder that a hack's headline number can change weeks later as investigators refine their accounting. For builders, it shows why transaction monitoring alone cannot stop laundering, since intermediaries supply clean stablecoins that mix proceeds from several crimes. For holders, it raises the question of counterparty risk at any platform that unknowingly accepts funds from these networks. Regulators and compliance teams may face pressure to treat OTC desks and unverified exchange services, not just the original attacker wallets, as points of enforcement. Recovery remains slow. The US Department of Justice has seized more than 15 million USDT linked to North Korea-related thefts, but full restitution still requires further legal steps.

The bigger question

If stolen funds remain traceable on-chain long after a theft, why does recovery still depend so heavily on voluntary cooperation from exchanges, token issuers, and law enforcement across borders? Blockchain analysis can map where money went and roughly when control changed hands. But turning that map into frozen or returned assets still requires institutions to act in coordinated, timely ways. Until that gap closes, large-scale thefts may keep outrunning the systems built to stop them.

What to watch

Bitget has not yet released a full technical investigation report on the September 2026 incident. Elliptic's attribution to North Korea remains an assessment, not a confirmed finding. Watch for updates on frozen assets tied to the $387.5 million (USD) total, and for further US Department of Justice action following its prior seizure of over 15 million USDT. Bonuz will track how these laundering networks intersect with the broader crypto infrastructure users rely on daily.

Keep reading