On July 12, North Korean authorities arrested a group of ex-cyber soldiers who allegedly hacked into two state banks. The Chosun Central Bank and the Foreign Trade Bank reportedly suffered repeated thefts. The stolen money was laundered through foreign cryptocurrency wallets.

These suspects are believed to be former members of North Korea’s military intelligence cyber units. They allegedly siphoned state trade funds in small portions, then converted the proceeds into US dollars and Chinese yuan via crypto channels. This internal betrayal shines a harsh light on the risks within Pyongyang’s digital warfare structure.

Tracking the Crypto Trail

Investigators managed to intercept encrypted transaction signals, pointing back to a safe house in Pyongyang, where computers and disposable phones were confiscated. This laundering method mimics tactics North Korean hackers have used on foreign crypto exchanges and decentralized finance platforms for years.

The country’s cyber operations are closely linked with the Lazarus Group, the notorious hacking collective behind massive cryptocurrency thefts worldwide. In 2026 alone, Lazarus-linked hackers have been tied to hacks totaling $577 million, accounting for 76% of all tracked crypto heist losses globally.

The fallout for North Korea could be significant. Cyber operatives with such expertise are invaluable but also pose an internal security threat. Their knowledge of state cyber infrastructure and tactics makes betrayal especially dangerous. History suggests the regime may tighten controls or launch purges within its cyber ranks to contain this internal rot.