BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Markets

North Korea Arrests Former Military Hackers Over Bank…

How Did The Hackers Target State Banks? North Korean authorities have arrested a group of former military hackers accused of stealing state funds from two government-controlled banks and laun

AnonymousCryptoCompass newsroom
July 26, 2026
5 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for markets coverage.

G7 Targets North Korea Over Escalating Crypto Heists

How Did The Hackers Target State Banks?

North Korean authorities have arrested a group of former military hackers accused of stealing state funds from two government-controlled banks and laundering the proceeds through cryptocurrency, according to a report citing an anonymous source in Pyongyang. The suspects allegedly breached internal systems belonging to the Central Bank of the Democratic People’s Republic of Korea and the Foreign Trade Bank. The group is accused of diverting foreign currency and funds connected to state trade before transferring the money through overseas crypto wallets. The Central Bank manages the country’s currency and state funds, while the Foreign Trade Bank handles foreign exchange and international transactions. Access to both institutions could have allowed the group to manipulate payment approvals and move funds intended for government-controlled trade. The report could not be independently verified, and North Korean authorities have not publicly confirmed the arrests. The country’s tightly controlled information system makes it difficult to assess the scale of the alleged theft or determine whether the investigation has identified all participants. The organizers were reportedly former members of military cyber intelligence units who recruited graduates from Kim Chaek University of Technology and Pyongyang University of Science and Technology. They allegedly used their technical training and knowledge of government networks to bypass internal controls.

How Was Cryptocurrency Used To Move The Funds?

The group reportedly divided the stolen money into small transfers and moved it to overseas crypto wallets to reduce the risk of detection. The suspects allegedly communicated through encrypted messaging applications, unregistered mobile phones and Chinese wireless equipment. Chinese brokers then helped convert the crypto assets into U.S. dollars and yuan, while contacts in the North Korean border cities of Sinuiju and Hyesan arranged cash settlements. The transactions were reportedly completed in real time, allowing the group to move value across borders without relying on conventional banking channels. This structure resembles laundering routes previously linked to North Korean cyber operations. Stolen digital assets are often transferred across several wallets, exchanged through intermediaries and converted into fiat currency through over-the-counter traders operating outside regulated exchanges. A multinational sanctions-monitoring report previously found that Chinese over-the-counter traders and financial institutions play a central role in converting cryptocurrency linked to North Korean operators into usable currency. These networks provide access to yuan and U.S. dollars while making it harder for investigators to trace the final recipients.

Investor Takeaway

The case shows that crypto laundering networks linked to North Korea may be used not only to monetize overseas hacks but also to move funds stolen from within the country. Exchanges and compliance teams face growing pressure to identify small, fragmented transfers before they reach cash-out brokers.

How Did North Korean Authorities Find The Group?

Officials reportedly became suspicious after detecting discrepancies in foreign-currency payment approvals in Pyongyang and attempts to access banking systems through overseas IP addresses. The State Information Bureau then opened an internal investigation into the irregular transactions. Investigators allegedly traced encrypted communications and cryptocurrency activity to a safe house in Pyongyang. The property was raided on July 12, and all members of the group were arrested, according to the report. Authorities reportedly seized computer equipment valued at hundreds of thousands of dollars, along with mobile phones registered under false identities. Armed guards were later deployed at both banks, while radio interception vehicles were stationed in parts of the capital. The source said the suspects are expected to receive severe sentences. “They were taught technology to protect the country, but they looted the state treasury,” the person said. The arrests are unusual because North Korea is better known for directing cyber units to steal cryptocurrency from foreign exchanges, bridges and financial companies. In this case, former state-trained specialists allegedly turned the same methods against domestic institutions.

What Does The Case Mean For Crypto Crime Monitoring?

North Korean hacking groups stole a record $2 billion in cryptocurrency last year, according to blockchain analytics data. TRM Labs estimated that groups linked to the country accounted for about 66% of stolen crypto funds in the first half of 2026, equal to roughly $643 million. The bank case suggests that the techniques developed by state-backed operators may spread beyond officially directed campaigns. Former personnel with access to technical training, trusted contacts and laundering networks can potentially use the same infrastructure for private theft. For crypto platforms, the main challenge is identifying transactions before stolen assets reach brokers capable of converting them into cash. Transfers divided across multiple wallets may appear too small to trigger basic monitoring systems, particularly when intermediaries use several exchanges and blockchains. The alleged use of Chinese brokers also reinforces the importance of monitoring off-platform cash-out networks. Even when exchanges freeze suspicious wallets, over-the-counter traders can provide alternative routes into fiat currency. North Korea’s response may focus on tightening access to bank networks and increasing surveillance of communications equipment. The wider crypto market, however, will remain exposed as long as brokers and informal settlement networks continue providing liquidity for stolen assets.