North Korea Arrests Its Own Elite Hackers After They Drained State Banks and Laundered Crypto
North Korea's spy agency arrested former state-trained hackers who drained the central bank and laundered proceeds through crypto — a rare case of Pyongyang turning inward.
North Korea’s intelligence agency arrested a ring of former state-trained cyber operatives on July 12, accusing them of hacking the country’s central bank and at least one other state bank before laundering the proceeds through cryptocurrency — a rare case of Pyongyang turning its enforcement apparatus against its own hackers.
Investigators traced encrypted transaction traffic to a Pyongyang safe house and seized equipment at the time of the arrests, according to Daily NK. The suspects allegedly moved stolen funds through shell accounts, converted the proceeds into cryptocurrency, and relied on brokers and border-area contacts — including Chinese intermediaries — to cash out. Small transfers were used to evade detection, the standard technique for fragmenting large sums before they hit an exchange.
The method isn’t the story. The targets and the perpetrators are. The accused are described as former state cyber operators — insiders who previously worked inside the regime’s own hacking apparatus. North Korea has spent years building one of the most aggressive state-sponsored crypto theft programs anywhere, deploying units like the Lazarus Group to drain foreign exchanges, DeFi protocols, and individual wallets. Turning that enforcement inward suggests either a genuine effort at internal accountability or a power struggle within the regime’s cyber infrastructure, where lucrative operations have historically run with near-total impunity.
The arrests land against a backdrop of staggering numbers. The FBI’s Internet Crime Complaint Center attributed approximately $1.5 billion stolen from crypto exchange Bybit on or around February 21, 2025, to North Korean actors, per an IC3 public service announcement. TRM Labs, cited by BankInfoSecurity, reported that North Korean hackers were responsible for 76% of all crypto losses during the first four months of 2025. Analysts cited by Firstpost put total North Korean crypto theft at roughly $2 billion for the year, with the Bybit heist accounting for the bulk of it.
Those numbers reframe July 12 as something bigger than a domestic policing matter. If Pyongyang’s own operatives are willing to target state banks — the financial spine of the regime itself — it raises hard questions about how much control central authorities actually exercise over the sprawling network of hackers, IT workers, and money launderers they have spent years cultivating. The regime has relied on these networks to generate hard currency under sanctions pressure. The problem: the same skills and infrastructure that make them effective abroad can be turned inward the moment discipline cracks or loyalties fracture.
The laundering playbook described in the Daily NK report is not new. On June 5, 2025, the U.S. Department of Justice filed a civil forfeiture complaint targeting more than $7.7 million in digital assets tied to a separate North Korean IT worker laundering network, TRM Labs reported. That case involved operatives posing as remote IT workers to infiltrate Western companies, then routing wages and stolen funds through crypto mixers and intermediary wallets. The Pyongyang safe-house operation described by lazarus.day runs a compressed version of the same logic: breach, convert, fragment, cash out.
Markets haven’t flinched. The Fear & Greed Index sits at 26 out of 100 — firmly in Fear territory — with total market capitalization at $2,287.23 billion as of this report. BBTC$64,421.00▲0.50% trades at $64,442, up 0.5% over 24 hours. EETH$1,877.80▲0.90% holds at $1,878, up 0.9%. Neither asset moved materially on the North Korea news, which remains a niche story outside specialist security circles. Still, the arrests put a sharper point on a structural risk that never goes away: the same borderless infrastructure enabling legitimate crypto commerce gives state actors and rogue operatives a frictionless rail for moving stolen capital.
For North Korea watchers, the most telling detail is what the regime chose to surface. Pyongyang rarely acknowledges internal crime. Cyber offenses committed by its own trained personnel? Almost never. The fact that state media or leaked reporting made this case public at all suggests authorities wanted a signal sent — to rival factions inside the intelligence apparatus, to the broader hacker community, or to foreign governments tracking North Korean crypto flows. The regime built a formidable offshore theft machine. Whether it can stop that machine from cannibalizing its own treasury is now an open question.
Watch for whether these arrests trigger follow-on enforcement actions inside North Korea, or whether the case quietly dissolves into the opacity that typically swallows Pyongyang’s internal security operations. Either outcome will tell analysts something real about how much discipline remains in a system that has spent years incentivizing its sharpest technical minds to steal first and answer questions never.