U.S. Treasury Targets North Korea’s Crypto Laundering Network

TheCryptoTimes发布于2025-11-04更新于2025-11-04

The U.S. Department of the Treasury on Tuesday expanded sanctions against a network of North Korea–linked bankers, companies, and facilitators accused of laundering proceeds from cybercrime and illicit IT-worker schemes. 

The Office of Foreign Assets Control (OFAC) designated eight individuals and two entities, including identified bankers and the Korean firm KMCTC, for moving and hiding cryptocurrency and other revenue that the Treasury says funds Pyongyang’s weapons programs.

“North Korean state-sponsored hackers steal and launder money to fund the regime’s nuclear weapons program,” Under Secretary for Terrorism and Financial Intelligence John K. Hurley said in the announcement. OFAC stated that the designated actors managed both crypto and fiat flows, and updated the Specially Designated Nationals (SDN) List with relevant cryptocurrency addresses tied to First Credit Bank.

How money laundering works, and how crypto changes it

Money laundering traditionally follows three steps:

  • Placement: introduce illicit proceeds into the financial system;
  • Layering: obscure the trail through multiple transfers and intermediaries;
  • Integration: reintroduce cleaned funds as apparently legitimate assets.

With cryptocurrencies, exploiters follow the same objectives but change the mechanics. Accounts (addresses) can be created in seconds, funds move across chains at low cost, and swapping, tumblers/mixers, and unregulated venues enable complex layering that obfuscates provenance.

U.s. Treasury Targets North Korea’s Crypto Laundering NetworkU.s. Treasury Targets North Korea’s Crypto Laundering Network
How crypto money laundering works. Source: UNODC


Unlike cash, crypto enables rapid, scriptable mass transfers that can be routed across dozens of services and jurisdictions, making traditional bank-centric tracking methods insufficient on their own.

The UN Office on Drugs and Crime estimates global money-laundering flows at 2–5% of GDP annually. Blockchain tracing firms and law enforcement increasingly warn that a large share of modern illicit proceeds now moves in crypto form, prompting new regulatory focus on exchange controls, on-chain analytics, and cross-border cooperation.

What OFAC targeted and why it matters

OFAC’s action names specific facilitators and entities tied to laundering networks:

  • North Korean bankers Jang Kuk Chol and Ho Jong Son managed $5.3 million in crypto tied to ransomware and IT-worker operations for First Credit Bank.
  • Korea Mangyongdae Computer Technology Company (KMCTC) and its president, U Yong Su, were sanctioned for running DPRK IT teams in China and laundering funds through proxy accounts.
  • Treasury also identified a wider network using shell firms, offshore reps, and foreign banks, including in China and Russia, to move North Korean money.

Treasury tied these networks to the DPRK’s broader playbook: state-directed cyber theft, sophisticated social-engineering hacks, and contract fraud using coerced or falsified identities among overseas IT workers. OFAC said North Korea-affiliated cybercriminals stole more than $3 billion in crypto over the past three years.

The designations invoke multiple executive orders aimed at countering cyber-enabled crimes and sanctions evasion and expand the SDN entries to include cryptocurrency addresses — a sign that Treasury is treating on-chain identifiers as actionable sanctions targets.

Methods cited in recent DPRK schemes

Treasury’s statement and related reporting highlight recurring DPRK tactics:

  • Fake IDs and proxies: DPRK IT workers hide nationality using false identities and local banking intermediaries.
  • Cross-border laundering: Funds move through shells, lax corridors, and unregulated exchanges to erase trails.
  • Crypto mixers and micro-transfers: Automated splits and merges obscure origins across countless wallets.
  • Remote-hire infiltration: Operatives pose as freelancers to access company systems and steal data or assets.

Past incidents reinforce these methods: law enforcement investigations have connected Lazarus-style groups to major heists and laundering channels that exploit lax controls at small exchanges or OTC desks. High-profile breaches and infiltration attempts have pushed some U.S. firms to tighten hiring and security policies.

Broader context: previous incidents and industry reaction

Treasury’s action comes amid a string of high-profile attacks and corporate responses this year. Exchanges and service providers have tightened onboarding and employee vetting after reported attempts by DPRK operatives to secure contractor roles inside crypto firms. Coinbase, for example, instituted stricter rules for personnel handling sensitive systems after reporting targeted approaches by DPRK IT operatives.

Internationally, incidents such as the Lykke breach and other Lazarus operations have shown how quickly platform failures can cascade into insolvency, regulatory scrutiny, and cross-border enforcement actions. The UK Treasury and EU authorities have repeatedly warned that unchecked stablecoin and crypto flows can pose systemic and cyber risks.

What comes next: enforcement and industry measures

The U.S. Treasury said it will continue to pursue the financial facilitators that enable DPRK schemes, emphasizing collaboration with law enforcement, financial-sector partners, and allied jurisdictions. 

The Treasury’s next steps include expanding the monitoring and designation of cryptocurrency addresses linked to sanctioned entities, increasing scrutiny of banking proxies and cross-border correspondent transactions, and intensifying pressure on exchanges, custodians, and over-the-counter (OTC) desks to strengthen KYC and AML screening while cooperating more closely on freezing and recovering illicit funds.

For crypto firms, the sanctions are a warning shot: tighten identity checks, strengthen on-chain tracking, and lock down fiat gateways, or risk becoming part of the laundering chain.

Bottom line

Treasury’s action signals a hardening stance: sanctions will target not only operational hackers but also the financial pipelines that let state-backed schemes convert stolen crypto into usable revenue.

As OFAC moves to tie on-chain identifiers to enforcement, both crypto firms and traditional banks face growing pressure to shore up controls or risk becoming conduits for illicit state financing. The enforcement push is likely to accelerate cross-border collaboration and, for the industry, force faster adoption of stronger compliance and operational defenses.

Also read: Curve Finance Warns DeFi Developers After $116M Balancer Hack


Mobile Only ImageMobile Only Image

热门币种推荐

你可能也喜欢

七个月后承认失败,Farcaster又在寻找接手方

去中心化社交协议Farcaster在不到七个月内将第二次更换运营团队。当前运营方Neynar的联合创始人Rishav Mukherji于8月18日宣布,已开始为Farcaster协议、其同名客户端应用、生态内的小程序与AI代币平台Clanker以及Neynar的开发者产品寻找新的归宿和运营团队。 Mukherji承认,Neynar未能实现年初设定的目标,现有团队不适合项目的下一阶段。他指出,Farcaster拥有紧密的社区,但其旗舰应用运营成本高昂,市场增长缓慢,这需要与Neynar不同的组织和资金结构来支撑。具体交接方案、时间及资金返还细节尚未确定,目前所有产品和服务将照常运行。 Farcaster由前Coinbase高管创办,旨在打造去中心化的社交身份与关系网络。其开发和运营公司Merkle Manufactory在五年内融资约1.8亿美元,并于今年1月将项目移交给Neynar。尽管Neynar接手后成功将基础设施成本降低了80%,并推进了协议的去中心化,但消费端用户增长的核心问题仍未解决,每月活跃用户数量远未达到可持续规模。 这是近期第二个主要Web3社交协议更换运营方,此前Lens协议也已将产品运营移交。这凸显了此类项目面临的共同挑战:底层协议可以开放运行,但面向普通用户的旗舰应用,其持续运营、产品开发和增长仍需依赖有实力的公司团队来承担成本和责任。Farcaster的第三次运营结构仍在形成中。

marsbit28分钟前

七个月后承认失败,Farcaster又在寻找接手方

marsbit28分钟前

交易

现货

热门文章

如何购买S

欢迎来到HTX.com!我们已经让购买Sonic(S)变得简单而便捷。跟随我们的逐步指南,放心开始您的加密货币之旅。第一步:创建您的HTX账户使用您的电子邮件、手机号码注册一个免费账户在HTX上。体验无忧的注册过程并解锁所有平台功能。立即注册第二步:前往买币页面,选择您的支付方式信用卡/借记卡购买:使用您的Visa或Mastercard即时购买Sonic(S)。余额购买:使用您HTX账户余额中的资金进行无缝交易。第三方购买:探索诸如Google Pay或Apple Pay等流行支付方法以增加便利性。C2C购买:在HTX平台上直接与其他用户交易。HTX场外交易台(OTC)购买:为大量交易者提供个性化服务和竞争性汇率。第三步:存储您的Sonic(S)购买完您的Sonic(S)后,将其存储在您的HTX账户钱包中。您也可以通过区块链转账将其发送到其他地方或者用于交易其他加密货币。第四步:交易Sonic(S)在HTX的现货市场轻松交易Sonic(S)。访问您的账户,选择您的交易对,执行您的交易,并实时监控。HTX为初学者和经验丰富的交易者提供了友好的用户体验。

3.6k人学过发布于 2025.01.15更新于 2026.08.06

如何购买S

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对S(S)币价的意见。

活动图片