North Korean authorities have arrested a group of former cyber operators and IT specialists, accused of hacking two state-owned banks and laundering the funds through cryptos. South Korean media Daily NK revealed the matter on July 25, citing an anonymous source in Pyongyang. A case that shakes up the usual narrative of North Korean cyberattacks, until now systematically directed outwards.

In brief
- A group of former North Korean cyber agents arrested for hacking the central bank and the Foreign Trade Bank, according to Daily NK
- Stolen state funds were converted into cryptos and then laundered through brokers based in China
- This is an extremely rare case where North Korean state operators are accused of attacking their own government
North Korea strikes within its own walls
According to the specialized media Daily NK, based in Seoul, the suspects infiltrated the internal networks of the North Korean central bank and those of the Foreign Trade Bank, two strategic institutions of the regime. They then converted the funds into digital assets and recycled them through intermediaries located in China.
Cointelegraph was unable to independently verify the report. Daily NK relies on a network of sources inside the country, a notoriously difficult exercise given the absolute control that Pyongyang exercises over information.
The case nonetheless remains credible in view of the history: in June 2026, Consensys, the company behind the MetaMask wallet, discovered that a developer linked to North Korea had infiltrated its teams.
The procedure described uses patterns known to international law enforcement. Internal hacking, conversion to cryptos, laundering via Chinese brokers. The difference this time lies in the target: not a foreign exchange platform nor a DeFi protocol, but the very coffers of the North Korean state.
A track record of cyberattacks worth billions
For more than a decade, Pyongyang has remained the number one suspect in the largest digital heists on the planet.
The Lazarus group, an elite North Korean intelligence unit, notably looted $620 million from the Ronin Network bridge in 2022, before carrying out the historic heist of $1.5 billion on the Bybit platform in February 2025.
The U.S. Treasury Department estimates the annual return on cyber operations for the regime to be between $1 billion and $2 billion. A windfall that finances the ballistic program and allows international sanctions to be circumvented. In 2026, the analysis company Chainalysis even attributed 76% of crypto thefts recorded worldwide to actors linked to North Korea, according to a report relayed by Cointelegraph.
The novelty of the Daily NK affair lies not in the method, but in the target. Until now, North Korean operators have targeted foreign infrastructure. This time, the line between aggressor and victim seems to have become blurred within the regime itself.
When the poacher becomes a gamekeeper
If Daily NK’s report is confirmed, this case marks a troubling precedent. Agents trained by the State, experienced in the most advanced hacking techniques, would have turned their skills against their own sponsor. A scenario which raises the question of the loyalty of these units, often deployed under extreme pressure.
Laundering through Chinese brokers highlights another reality: China still functions as a hub for the recycling of stolen cryptos, despite repeated calls from the FATF. OTC trading platforms and nominee networks continue to thrive there.
It remains to be seen whether Pyongyang will make this wave of arrests public. Transparency has never been in the catalog of Kim Jong-un’s regime, but the leak via Daily NK indicates that the story has already crossed borders.
In short, this affair exposes North Korea trapped in its own cybercriminal machine. On the one hand, a regime which uses piracy as a lever for economic survival. On the other, agents who have become uncontrollable, capable of turning their arsenal against the State which trained them. A revealing paradox, while Pyongyang already rejects accusations attributing to it 76% of global crypto thefts in 2026.
Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.
