TRM Labs says North Korean IT workers have laundered millions in USDC and USDT while secretly working for blockchain startups. North Korea continues to rely on crypto to quietly fund its weapons programs and the U.S. government is stepping up…TRM Labs says North Korean IT workers have laundered millions in USDC and USDT while secretly working for blockchain startups. North Korea continues to rely on crypto to quietly fund its weapons programs and the U.S. government is stepping up…

Here’s how North Korean hackers are still getting paid in crypto despite sanctions

4 min read

TRM Labs says North Korean IT workers have laundered millions in USDC and USDT while secretly working for blockchain startups.

North Korea continues to rely on crypto to quietly fund its weapons programs and the U.S. government is stepping up efforts to shut it down. On July 8, the U.S. Treasury’s Office of Foreign Assets Control sanctioned a North Korean hacker, Song Kum Hyok, who they say helped organize a widespread scheme involving fake remote workers at unsuspecting tech and crypto companies.

According to a recent report from blockchain forensic firm TRM Labs, Song was linked to Andariel, a cybercrime unit that’s part of North Korea’s military intelligence. They explained that he played a key role in placing IT workers — most of whom were actually North Korean operatives — into jobs at U.S. companies by using stolen American identities and fake documents.

Many of these jobs were in web3, crypto infrastructure, or blockchain-related software development.

TRM Labs said these workers operated from countries like China and Russia while pretending to be U.S.-based freelancers. They got paid in stablecoins such as USD Coin (USDC) and Tether (USDT). From there, the money appeared to have flowed through layers of wallets, mixers, and conversion services before ending up in the hands of the North Korean regime.

Analysts at TRM Labs pointed out that this is just the latest sign that North Korea’s Reconnaissance General Bureau — the same agency behind Lazarus and Bluenoroff — is still using cyber tactics to support military goals. Treasury officials, they noted, have been warning that crypto theft and identity fraud remain central to North Korea’s strategy for avoiding economic pressure.

The analysts explained that the scheme uncovered by OFAC relies heavily on fake personas. Song was allegedly responsible for building those fake identities, using stolen data from real U.S. citizens. Once hired, North Korean operatives may have worked for months or even years in U.S. companies under false names.

They also noted that OFAC sanctioned four companies and one other person connected to a Russia-based network that allegedly helped manage these fake IT jobs. These businesses reportedly signed long-term contracts with DPRK-linked firms and were aware they were dealing with North Korean workers.

Many of the workers targeted jobs in the crypto sector specifically, where payments were easier to anonymize. Once the crypto was received, TRM Labs analysts said, it was spread across several wallets and eventually converted into fiat using OTC brokers, some of whom have been previously sanctioned.

Cyber alliance

The latest OFAC’s action followed a series of coordinated moves by U.S. agencies, including the Department of Justice and the FBI. On June 5, 2025, the DOJ also filed a civil forfeiture complaint seeking to seize over $7.7 million in crypto, NFTs, and other digital assets believed to be linked to the same North Korean network.

TRM Labs says the workers used identities like “Joshua Palmer” and “Alex Hong” to get hired at crypto startups and other tech firms. They were paid in stablecoins, with proceeds routed through centralized exchanges, self-hosted wallets, and then on to higher-level regime figures like Kim Sang Man and Sim Hyon Sop, both already under U.S. sanctions.

The DOJ’s investigation, according to analysts, revealed that parts of the operation relied on infrastructure based in Russia and the UAE. Investigators found the use of local IP addresses and forged documentation, which helped the North Korean workers hide their true identities. This, they said, underscored just how international the scheme had become.

Here's how North Korean hackers are still getting paid in crypto despite sanctions - 1

Blockchain data reviewed by TRM showed that once funds reached mid-level wallets, the money was split into smaller portions, routed through privacy-enhancing tools, and eventually exchanged for fiat via OTC desks. One of those OTC brokers had already been sanctioned by OFAC in late 2024.

As for law enforcement efforts, the FBI and other agencies successfully seized a portion of the laundered digital assets, including USDC, ETH, and some high-value NFTs. The analysts described these seizures as part of a broader laundering strategy meant to break up the money trail and make detection far more difficult.

TRM Labs says the U.S. government’s latest action sends a message that crypto remains a high-risk channel for sanctions evasion, especially when it comes to North Korean operations. The blockchain intel firm warned that companies hiring remote developers — especially in the blockchain space — need to take extra care in verifying who they’re really dealing with.

Market Opportunity
USDCoin Logo
USDCoin Price(USDC)
$1.0019
$1.0019$1.0019
+0.06%
USD
USDCoin (USDC) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

The post CEO Sandeep Nailwal Shared Highlights About RWA on Polygon appeared on BitcoinEthereumNews.com. Polygon CEO Sandeep Nailwal highlighted Polygon’s lead in global bonds, Spiko US T-Bill, and Spiko Euro T-Bill. Polygon published an X post to share that its roadmap to GigaGas was still scaling. Sentiments around POL price were last seen to be bearish. Polygon CEO Sandeep Nailwal shared key pointers from the Dune and RWA.xyz report. These pertain to highlights about RWA on Polygon. Simultaneously, Polygon underlined its roadmap towards GigaGas. Sentiments around POL price were last seen fumbling under bearish emotions. Polygon CEO Sandeep Nailwal on Polygon RWA CEO Sandeep Nailwal highlighted three key points from the Dune and RWA.xyz report. The Chief Executive of Polygon maintained that Polygon PoS was hosting RWA TVL worth $1.13 billion across 269 assets plus 2,900 holders. Nailwal confirmed from the report that RWA was happening on Polygon. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 The X post published by Polygon CEO Sandeep Nailwal underlined that the ecosystem was leading in global bonds by holding a 62% share of tokenized global bonds. He further highlighted that Polygon was leading with Spiko US T-Bill at approximately 29% share of TVL along with Ethereum, adding that the ecosystem had more than 50% share in the number of holders. Finally, Sandeep highlighted from the report that there was a strong adoption for Spiko Euro T-Bill with 38% share of TVL. He added that 68% of returns were on Polygon across all the chains. Polygon Roadmap to GigaGas In a different update from Polygon, the community…
Share
BitcoinEthereumNews2025/09/18 01:10
TRM Labs Becomes Unicorn with 70M$: BTC Fraud Risk

TRM Labs Becomes Unicorn with 70M$: BTC Fraud Risk

The post TRM Labs Becomes Unicorn with 70M$: BTC Fraud Risk appeared on BitcoinEthereumNews.com. TRM Labs Reaches 1 Billion Dollar Valuation Blockchain intelligence
Share
BitcoinEthereumNews2026/02/05 03:33
Bitcoin Set For ‘Promising’ Q4, Next Two Weeks Could Be Decisive

Bitcoin Set For ‘Promising’ Q4, Next Two Weeks Could Be Decisive

The post Bitcoin Set For ‘Promising’ Q4, Next Two Weeks Could Be Decisive appeared on BitcoinEthereumNews.com. Rubmar is a writer and translator who has been a crypto enthusiast for the past four years. Her goal as a writer is to create informative, complete, and easily understandable pieces accessible to those entering the crypto space. After learning about cryptocurrencies in 2019, Rubmar became curious about the world of possibilities the industry offered, quickly learning that financial freedom was at the palm of her hand with the developing technology. From a young age, Rubmar was curious about how languages work, finding special interest in wordplay and the peculiarities of dialects. Her curiosity grew as she became an avid reader in her teenage years. She explored freedom and new words through her favorite books, which shaped her view of the world. Rubmar acquired the necessary skills for in-depth research and analytical thinking at university, where she studied Literature and Linguistics. Her studies have given her a sharp perspective on several topics and allowed her to turn every stone in her investigations. In 2019, she first dipped her toes in the crypto industry when a friend introduced her to Bitcoin and cryptocurrencies, but it wasn’t until 2020 that she started to dive into the depth of the industry. As Rubmar began to understand the mechanics of the crypto sphere, she saw a new world yet to be explored. At the beginning of her crypto voyage, she discovered a new system that allowed her to have control over her finances. As a young adult of the 21st century, Rubmar has faced the challenges of the traditional banking system and the restrictions of fiat money. After the failure of her home country’s economy, the limitations of traditional finances became clear. The bureaucratic, outdated structure made her feel hopeless and powerless amid an aggressive and distorted system created by hyperinflation. However, learning about…
Share
BitcoinEthereumNews2025/09/18 23:00