How North Korean hackers laundered $100M in stolen Bitcoin by using hundreds of automated transactions to “peel” small amounts off the original
Hackers working for Kim Jong-un have become experts at covering their tracks on the Bitcoin blockchain.
Context & Ripple Effects
This 2020 MIT Technology Review investigation documented the 'peel chain' — hundreds of automated transactions siphoning small amounts off a stolen hoard — as North Korea's baseline laundering craft. It sits at the start of an arc the related coverage traces forward: by 2023 researchers found operators renting cloud compute to mine fresh coins instead of touching mixers like Tornado Cash, which UN monitors tied to $147.5M laundered from the HTX hack.
The scale has grown alongside the tradecraft: Chainalysis now credits the regime's roughly 8,000 hackers with over $6B in stolen crypto over the past decade, and Washington has made cutting off that laundering pipeline an explicit sanctions priority because it funds weapons programs.
First-order effects
- Exchanges and compliance teams holding exposure to the stolen coins face hundreds of automated 'peel' transactions designed to fragment the trail below reporting thresholds, forcing manual tracing of each hop.
Second-order effects
- As peel chains became detectable, North Korea shifted to less scrutinized channels — mining stolen value into fresh coins via rented cloud compute rather than routing through mixers that analytics firms watch.
Third-order effects
- If the pattern holds, sanctions enforcement becomes a permanent arms race between state-sponsored launderers and blockchain forensics, with the US pressuring the chokepoints — mixers, exchanges, cloud providers — rather than the hackers themselves.
The trend: North Korea's crypto theft-and-laundering operation is evolving from on-chain obfuscation tricks toward infrastructure-level workarounds, making it the largest single driver of crypto-theft losses and a standing target of US financial enforcement.