On July 12, North Korean authorities arrested a group of former military hackers in Pyongyang. They are accused of stealing money from two state banks and laundering it through cryptocurrency channels.

The suspects reportedly targeted the Central Bank of the DPRK and the Foreign Trade Bank, hacking into their internal systems. The stolen funds were moved into crypto wallets abroad.

To convert these funds into usable currency, the hackers worked with brokers based in Chinese border cities like Sinuiju and Hyesan. These brokers exchanged crypto for U.S. dollars and Chinese yuan almost instantly.

The group used tactics to avoid detection, including splitting transactions into small sums, communicating via encrypted messaging apps, and utilizing unregistered phones and Chinese wireless gear.

North Korea's National Intelligence Agency detected suspicious overseas IP activity and anomalies in foreign currency payments, which led to the arrests at a safe house in Pyongyang.

This case stands out because it involves North Korean hackers stealing from their own government, a rare twist given the regime’s usual focus on foreign targets. Pyongyang’s cyber operations are widely known for attacking international crypto firms to bypass sanctions.

The laundering methods mirror those employed by North Korean hacking groups abroad. Previous reports identified Chinese over-the-counter traders as key facilitators in converting stolen crypto to fiat currency.

In 2025 alone, North Korean hackers stole a record $2 billion in cryptocurrency, according to blockchain analytics firm Chainalysis. Another firm, TRM Labs, estimates that through April 2026, actors linked to North Korea were behind 76% of all crypto hack and scam losses.