For over a decade, North Korea’s cyber units have been the boogeyman of the crypto world, draining exchanges and bridges to bankroll the regime, often sending shockwaves across the crypto market — and the crypto heatmap. Now, for the first time on record, that arsenal has reportedly been turned inward. The state’s own hackers allegedly robbed the state.
The story broke on July 23 via Daily NK, the Seoul-based outlet that runs a network of sources inside North Korea. Citing an anonymous contact in Pyongyang, reporter Yoon HyeSeong described a group that breached the internal networks of the Chosun Central Bank, which oversees currency issuance and state funds, and the Foreign Trade Bank, which handles the country’s foreign payments. Two of the most guarded institutions in the country, cracked from the inside.
It is no longer a secret that the North Korean government closely monitors everything from economic calendar events to cryptocurrency markets, while also attempting to infiltrate financial institutions and crypto platforms to exploit their vulnerabilities.
Here is the twist that has reportedly rattled Pyongyang’s elite: the ringleaders weren’t foreign spies. According to Daily NK’s source, they were discharged veterans of a cyber unit under the Reconnaissance and Intelligence General Bureau, the military intelligence body behind the regime’s espionage operations.
After leaving the service, they recruited young prodigies from Kim Chaek University of Technology and Pyongyang University of Science, then built a private crypto network to enrich themselves.
The playbook mirrored the one North Korea has long used on everyone else. They split state trade funds and foreign currency into tiny amounts to slip past monitoring, moved the money into overseas crypto wallets, and cashed out through brokers in China. Border contacts in Sinuiju and Hyesan exchanged the coins for U.S. dollars and Chinese yuan in real time, according to Daily NK.
The scheme unraveled over small discrepancies. Officials started noticing some irregularities in foreign-currency payment approvals and flagged odd overseas IP access. Investigators then followed the encrypted transaction traffic, which ultimately led them to a safe house in Pyongyang.
They raided it on the night of July 12, while operators were still laundering money on their keyboards. Agents reportedly seized burner phones and computer gear valued at hundreds of dollars.
What followed read like a state of panic. Armed intelligence personnel ringed the Foreign Trade Bank’s headquarters and the central bank’s computing center, cut off outside access entirely, and sent signal-detection vehicles across the capital to sniff out rogue frequencies, according to Daily NK.
One caveat matters. Cointelegraph and other outlets have not been able to independently verify the report, and information leaving North Korea is nearly impossible to confirm. The allegations should therefore be treated as a single-source report rather than established fact.
However, the claim is consistent with a well-documented pattern. It is easy to imagine that, given their daily involvement in illegal financial transactions, North Korean agents might succumb to temptation sooner or later.
