On February 21st 2025, Dubai-based exchange Bybit fell victim to the largest confirmed crypto theft in history. Across just two transactions, approximately $1.46 billion in Ether (ETH) and ERC-20 tokens were transferred to a single attacker-controlled address . Elliptic was one of the first to publicly call the exploit a North Korean act.
In our February blog, we explained how initial stolen assets were distributed across multiple addresses for the first stage of laundering. In this article we’ll some of the other techniques and methods employed to launder the funds to eventual endpoints, with a particular focus on those which differed from North Korea’s usual laundering tactics, techniques and procedures.
zeroShadow’s recent report indicates that over $1 billion of the stolen funds have now been laundered. It is unlikely that funds remained in the control of DPRK operatives at all stages. Professional ‘laundering as a service’ operations are thought to have been employed from early stages of the laundering, with ‘North Koreans receiving the face value of the funds to be laundered, minus their fee, at the point of exchange’.
This theory is bolstered by multiple reports of ‘user’ complaints being raised on occasions when Bybit stolen funds have been frozen by services, i.e., launderers seeking to maximise their own, personal profits as opposed to recovering a loss for their client.
The speed and scale of the laundering has been noteworthy. DPRK theft funds have been known to sit dormant for weeks and months before laundering begins.
The prompt movement of Bybit funds are likely, in part, due to the amount of attention the exploit received. Many in the crypto and intel community undertook a call to arms–including Elliptic’s creation of a free API , as well as the exploit receiving inevitable attention from law enforcement agencies. Bybit itself also set up a bounty program , all of which added to the motivation for DPRK to launder with a higher degree of urgency.
These factors are also likely to have contributed to the notable complexity of laundering undertaken. Multi-chain laundering and the use of obfuscation services are standard amongst most exploits.
Conversely, some efforts to reduce laundering fees were observed in parts of laundering. This again may indicate different teams being responsible for different pools of stolen funds. Fee-reducing tactics included:
Interestingly, even though the deposits were never processed, the services still charged notable handling fees. This suggests the technique may not have been designed specifically to hide the transactions, but still offered the benefit as a side effect.
Funds swapped to the Bitcoin blockchain were sent through Wasabi Wallet (a CoinJoin-based privacy wallet) and various mixers . In particular, much higher usage of Wasabi, as a proportion of total funds laundered, were noted in laundering the proceeds of the Bybit hack than in any DPRK-attributed hack. In contrast, usage of Tornado Cash was lower for the Bybit hack than for many DPRK hacks.
More individual mixers and privacy wallets were used to launder the proceeds of the Bybit hack overall than in most other DPRK-attributed hacks, including Cryptomixer, Jambler mixers and Coinomize.
The exception to this is in the period surrounding the Coinex hack in September 2023. During the just over three month period leading up to that hack, DPRK conducted four additional crypto hacks, resulting in a total of nearly $300 million in funds to launder . Unsurprisingly, in laundering the proceeds of these hacks, we also saw diversification in DPRK’s use of mixing services during this time. Furthermore, this collection of hacks occurred shortly after Chip Mixer was taken down; just two months after the CoinEx theft, another DPRK mixer of choice ( Sinbad.io) was also taken down .
These closures also potentially led to DPRK’s previously unprecedented usage of a higher number of mixing and obfuscation services than in hacks, to a level not seen again until the similarly unprecedented volume of funds laundered from the Bybit hack. Another mixer utilized by DPRK in laundering the proceeds of the Bybit and other hacks ( Yomix.io ) also ceased to exist during the Bybit hack laundering period.
Bybit laundering has also seen a novel way to obfuscate the movement of at least $24M of stolen funds. Similar methods have been observed in DRPK theft laundering, with the premise being much the same. The technique involves stolen funds which, at this stage, had been swapped to USDT.
Of course, the common end goal of an exploit is to convert digital assets to fiat currencies. Where the above described techniques have been able to be untangled and deciphered, funds have been seen to reach the Tron blockchain.
Once laundered to Tron, stolen Bybit funds have ultimately been converted to USDT and cashed out via suspected Chinese over-the-counter trading services, or ‘OTCs’.
Such services are responsible for the swapping of cryptoassets for millions of dollars in fiat currency yearly, with unscrupulous services asking little or no questions of their customers. Many of these services also have forward exposure to now infamous Huione Group entities, as previously reported by Elliptic .
Despite this huge windfall, DPRK has continued to amass funds via several other thefts in 2025. Known DPRK tactics include:
So far in 2025, Elliptic is aware of over a dozen other DPRK-attributed thefts with a combined total victim loss of over $1.75B.
Elliptic took action to ensure that addresses associated with this exploit are available to screen and trace using our -generation holistic blockchain analytics solutions. Customers will be able to ensure that they do not inadvertently process funds originating from – or being sent to – the entity or individuals responsible for this theft.
Our industry-leading blockchain coverage – surpassing 65 blockchains – has proven crucial to ensuring that the cross-chain and cross-asset laundering techniques currently being observed across the hackers’ laundering operations remain traceable. Any associated risks or exposure to virtual asset services, across any blockchain, can therefore be detected and prevented in real time.
us to schedule a demo and see how we can help your organization stay ahead of the latest risks and trends.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
