Join our Newsletter — 33% off our NHI Course

Why do North Korea-linked actors rely on mixers and DeFi platforms after a crypto theft?

They use mixers to obscure the origin of stolen funds and DeFi platforms to convert less liquid assets into more usable ones. Swapping tokens into Ether or Bitcoin expands the set of mixers and exchanges that can be used for laundering. The combination reduces traceability operationally, even though blockchain records still allow investigators to reconstruct the movement path.

Why mixers matter after a theft

Mixers are used because stolen cryptocurrency is only valuable to the thief if it can be moved without being trivially linked back to the theft. Once coins sit in a transparent ledger, the actor has to break the obvious provenance chain, reduce clustering confidence, and make the funds harder to freeze, flag, or refuse by exchanges and counterparties.

That is why mixing is usually a post-theft step, not a standalone objective. It is less about “hiding forever” and more about creating enough ambiguity that later cash-out options remain open. For North Korea-linked actors, that operational delay buys time, especially when the theft is being watched in near real time.

Mixers work best for the attacker when the stolen asset can be broken into many paths, reused through multiple hops, and combined with other activity that resembles ordinary flow. Public blockchain records still exist, but the analytical burden shifts onto investigators who must separate the theft path from surrounding noise.

Why DeFi platforms are part of the laundering chain

DeFi platforms help because they turn an awkward stolen asset into something more liquid, more fungible, or more useful for subsequent laundering. If the actor can swap into Ether or Bitcoin, they gain access to a wider ecosystem of mixers, bridges, pools, and exchanges, which increases routing options and reduces dependency on any single venue.

That conversion step also matters when the original stolen token is thinly traded, lightly supported, or easy for compliance systems to spot. Moving into a more common asset can reduce slippage, lower attention, and make later fragmentation easier. In practice, DeFi is often used as a conversion layer before funds are pushed through additional obfuscation stages.

The laundering value is therefore not that DeFi erases records. It is that DeFi expands the attacker’s operational flexibility. More swap paths mean more opportunities to split value, time the movement, and route through liquidity pools or cross-protocol hops that complicate tracing and freezing efforts.

Why this combination is effective, even on a transparent chain

The combination of mixers and DeFi platforms is effective because each solves a different laundering problem. DeFi improves convertibility and mobility; mixers reduce attribution confidence. Used together, they force defenders to reason about a sequence of transformations rather than a single wallet-to-wallet transfer.

That said, transparency still matters. Investigators can often reconstruct the path, correlate timing, and identify exit points where funds touch regulated services. The practical advantage for the attacker is not invisibility, but friction, more hops, more ambiguity, and more time before a useful intervention becomes possible.

For North Korea-linked actors, that friction is operationally valuable because it helps preserve proceeds long enough to move them into forms that are harder to recover or seize. The tactic is part of a broader post-compromise monetisation pattern: theft first, conversion next, and obscuration before final cash-out.

Risk and Threat Considerations

The main risk is that each extra conversion step creates another dependency, which can fail if a venue freezes assets, a swap is flagged, or an address cluster is linked to prior theft. The attacker is counting on sufficient liquidity and enough protocol churn to outrun response actions.

Failure mechanism: Mixers and DeFi routing work only while the flow remains hard to correlate across hops. If investigators tie the stolen funds to known laundering patterns, or if regulated endpoints enforce screening, the laundering chain becomes exposed and the exit options narrow quickly.

Impact: The stolen assets become harder to recover in time, and the defender may be forced into a longer tracing and coordination effort across multiple venues instead of a simple freeze or attribution action.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
MITRE ATT&CK TA0010 — Exfiltration Covers post-compromise movement and laundering of stolen crypto proceeds.
Recommendation — Map theft-to-cashout activity to exfiltration chains and hunt for follow-on routing.
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy Applies because defenders need a strategy for tracing, freezing, and prioritising crypto theft response.
Recommendation — Prioritise rapid tracing and response playbooks for high-value theft flows.
NIST SP 800-53 Rev 5 AU-6 — Audit Record Review, Analysis, and Reporting Relevant because blockchain tracing and exchange logs require correlated review and analysis.
Recommendation — Correlate wallet, exchange, and protocol logs to identify laundering paths.
ISO/IEC 27001:2022 A.5.18 — Access rights Supports controlling and reviewing access that could be abused in post-theft transfer chains.
Recommendation — Review and revoke access paths that enable rapid asset movement.
CIS Controls v8 CIS-8 — Audit Log Management Supports monitoring transaction trails and preserving evidence across laundering hops.
Recommendation — Centralise and retain transaction evidence needed to reconstruct the theft path.

Practitioner Guidance

What to prioritise: Focus on the earliest conversion point after theft, because that is often where the actor changes the asset into a more flexible laundering vehicle. The best interception opportunity is usually before funds have been broken into many hops or moved across multiple protocols.

What to verify: Validate whether the post-theft path includes a liquidity conversion into a major asset such as Ether or Bitcoin, then check whether that conversion was followed by mixer use, bridge activity, or repeated small transfers. That sequence is more informative than any single transaction in isolation.

Practitioner takeaway: The critical judgement is to treat mixers and DeFi as complementary laundering stages, not interchangeable ones, because the defender’s best response depends on whether the actor is still converting value or has already started obscuring provenance.