Overview
- The Multilateral Sanctions Monitoring Team’s Oct. 22 assessment tallies $1.19 billion in 2024 and about $1.65 billion from January through September 2025.
- Major breaches cited include Bybit in the UAE and DMM Bitcoin, WazirX, BingX and Phemex, with several compromises traced to third-party custody providers such as SafeWallet, Ginco and Liminal.
- Laundering routes involve Chinese nationals, UnionPay rails, Russian intermediaries and Cambodian platforms including Huione Group’s Huione Pay; the U.S. Treasury has sanctioned Huione.
- The report links the operations to state-backed groups like Lazarus and TraderTraitor, highlighting social engineering, supply-chain intrusions and use of AI tools to refine attacks.
- Investigators say 1,000–2,000 North Korean IT workers operate from at least eight countries and remit roughly half their earnings, prompting calls to restore broader U.N. oversight.