How North Korean Hackers Launder Crypto Across Chains
Imagine stealing $1.5 billion in a single afternoon and then making it vanish into thin air before the bank even realizes the vault is empty. That’s not a heist movie plot; it’s what happened when Lazarus Group, a cyber-espionage unit linked to North Korea, hit Bybit in February 2025. The sheer scale of this theft-surpassing all of North Korea’s combined crypto hauls from 2023-forced us to rethink how money moves in the digital age. We used to think blockchain transparency was our best defense. But if you can jump between blockchains faster than analysts can refresh their dashboards, transparency becomes just noise.
The Shift From Mixers to Bridges
For years, the go-to trick for hiding stolen crypto was using mixers like Tornado Cash or Sinbad. These services scrambled transaction trails by pooling funds from many users. But regulators caught on. Sanctions hit Tornado Cash, and enforcement agencies started freezing assets at the endpoints. So, the hackers adapted. They stopped trying to blur the lines within one chain and started hopping across different chains entirely. This method, known as cross-chain laundering, exploits the interoperability infrastructure meant to make DeFi easier for regular users. Instead of obscuring where the money went, they move it so fast and so often that tracking it becomes a logistical nightmare for compliance teams.
According to TRM Labs, a leading blockchain intelligence firm, this shift isn’t just a minor tweak-it’s a fundamental change in strategy. Between 2023 and 2025, we saw a massive surge in funds processed through cross-chain conversion services. The Lazarus Group alone became a dominant force behind a 111% spike in these transactions. Why? Because moving Bitcoin to Ethereum, then to Tron, and finally to an obscure layer-2 network breaks the direct link between the theft and the cash-out point. Each hop requires a new bridge contract interaction, adding layers of complexity that automated tools struggle to untangle in real-time.
Anatomy of a Cross-Chain Heist
Let’s look at the mechanics. It usually starts with a breach. Whether it’s a smart contract exploit or a compromised private key, the hackers drain wallets rapidly. In the early days, they might have sent those funds straight to a centralized exchange (CEX) to sell them. Today, they use a "flood the zone" technique. Nick Carlsen, a former FBI expert now at TRM Labs, describes this as overwhelming compliance teams with high-frequency transactions across multiple platforms. The goal isn’t just to hide; it’s to paralyze the response.
Here is a typical flow based on recent incidents:
- Initial Drain: Stolen assets (often stablecoins or ETH) are moved to fresh wallets controlled by the attackers.
- Bridge Hopping: Assets are swapped via bridges like Ren Bridge or Avalanche Bridge. For instance, Bitdefender reported that over 9,500 BTC passed through the Avalanche Bridge due to Lazarus activity.
- Token Swapping: ERC-20 tokens are converted to native assets (like Ether) or other chain-specific tokens (TRC-20 on Tron) using decentralized exchanges (DEXs).
- Obfuscation: Funds are routed through less-tracked blockchains or newly created tokens issued by the laundering networks themselves.
- Consolidation: Finally, the assets are often converted back to Bitcoin and held in stationary addresses, waiting for large-scale liquidation via Over-The-Counter (OTC) desks rather than public exchanges.
| Method | Primary Tool | Vulnerability | Current Status |
|---|---|---|---|
| Mixing Services | Tornado Cash, Sinbad | Sanctions, endpoint freezing | Declining usage due to enforcement |
| Cross-Chain Bridges | Avalanche Bridge, Ren Bridge | Complexity, speed of hops | Rising dominance, harder to trace |
| Direct Exchange | Binance, Coinbase | KYC checks, account freezes | Used only for final off-ramping |
| Obscure Chains | Stellar, XRP Ledger | Limited analytics coverage | Niche but growing tactic |
Why the Bybit Hack Changed Everything
The February 2025 Bybit incident wasn’t just big; it was a watershed moment. With losses estimated at $1.5 billion, it exceeded the total stolen by North Korea in 2023. The FBI attributed this to TraderTraitor, a subunit of the Reconnaissance General Bureau. What made this specific case alarming was the sophistication of the post-theft movement. Investigators traced multiple rounds of swaps between Bitcoin, Ethereum, BTTC, and Tron. Unlike previous attacks where funds were quickly liquidated, much of the stolen Bitcoin remained stationary after conversion. This suggests a strategic pause. The hackers weren’t panicking; they were staging. They had successfully laundered the funds into a form that was difficult to freeze and were likely preparing for a quiet exit through OTC markets, bypassing the scrutiny of retail exchanges.
This event highlighted a critical gap: our tools are still catching up. While firms like Chainalysis and Elliptic have improved their cross-chain analytics, the volume of data generated by a $1.5 billion flood is staggering. The Wilson Center noted that this isn’t just a crypto problem; it’s a global security issue. A UN report indicated that nearly half of North Korea’s foreign currency earnings now come from cybercrime, directly funding their weapons program. When you steal billions and wash them clean across five different blockchains, you’re not just buying luxury cars; you’re financing missiles.
The Human Element in Technical Attacks
While the laundering is technical, the entry points are increasingly human. CoinDesk pointed out a strategic pivot in 2025: while exchanges remain targets, there’s a marked rise in attacks on individuals. High-net-worth holders and executives are being targeted with sophisticated phishing campaigns, fake job offers, and social media compromises. Elliptic stated that "the weak point in cryptocurrency security is now human, not technological." Hackers rely on deception more than code exploits. If they can trick a CEO into signing a malicious transaction, they don’t need to break the encryption. They just walk out the front door with the keys.
This evolution means that traditional cybersecurity measures aren’t enough. You can have the best hardware wallet, but if your executive assistant clicks a link in a spoofed LinkedIn message, the funds are gone. And once they’re gone, they enter the cross-chain vortex described above, making recovery nearly impossible without proactive intervention from law enforcement and analytics firms.
How Analysts Fight Back
So, how do you track ghosts? The industry has responded with specialized tools. TRM Labs introduced cross-chain analytics in 2019, allowing investigators to visualize funds moving across multiple assets in one view. In 2022, they launched TRM Phoenix, designed specifically to automatically trace flows through bridges. These tools are essential because manual tracing is no longer feasible. When thousands of transactions occur in minutes across six different chains, you need automation to spot the patterns.
However, it’s an arms race. As analytics improve, the hackers adapt. They start using obscure blockchains where data coverage is thin. They create new tokens solely for laundering purposes. They exploit refund addresses to redirect assets to fresh wallets, breaking the chain of custody. It’s a cat-and-mouse game where the mouse keeps changing its shape. The current trend shows that despite the swift movement of assets, most converted Bitcoin remains largely stationary. This indicates that the hackers are confident in their ability to hold value until they find the right moment to cash out, likely through channels that offer privacy and high liquidity.
Key Takeaways
- Scale is escalating: DPRK crypto theft jumped from $660 million in 2023 to over $2 billion in 2025.
- Methods are evolving: A clear shift from mixers to cross-chain bridges like Avalanche and Ren.
- Human error is the new vector: Social engineering is increasingly used to gain initial access.
- Geopolitical stakes are high: Stolen funds directly support North Korea’s military programs.
- Analytics must adapt: Single-chain tracking is obsolete; cross-chain visualization is mandatory.
What is cross-chain laundering?
Cross-chain laundering is a method of hiding the origin of stolen cryptocurrency by moving it between different blockchain networks (e.g., from Ethereum to Bitcoin). This uses interoperability protocols called bridges, which makes it difficult for analysts to track the continuous flow of funds compared to staying on a single chain.
Who is the Lazarus Group?
The Lazarus Group is a state-sponsored cyber-espionage organization associated with North Korea's Reconnaissance General Bureau. They are responsible for numerous high-profile hacks, including the Sony Pictures attack and major cryptocurrency thefts, often operating under aliases like TraderTraitor.
Why did North Korea stop using mixers?
Mixers like Tornado Cash faced increased regulatory scrutiny and sanctions. Enforcement actions allowed authorities to freeze funds at mixer endpoints. To evade this, hackers shifted to cross-chain bridges, which offer more complex paths and fewer centralized chokepoints for seizure.
How much crypto has North Korea stolen recently?
Estimates vary, but reports indicate over $2 billion was stolen in 2025 alone. The Bybit hack in February 2025 accounted for approximately $1.5 billion of this total, making it the largest crypto heist in history.
Does cross-chain laundering make crypto untraceable?
No, it doesn't make it untraceable, but it makes it significantly harder and slower to trace. Public ledgers still record every transaction. However, the complexity requires advanced, automated cross-chain analytics tools to reconstruct the path, which can take time-time during which funds may be moved again or cashed out.