RUSI Maps North Korea’s Crypto-to-Fiat Laundering Vulnerabilities and Compliance Responses

A new research paper from the Royal United Services Institute (RUSI) examines how North Korea converts stolen virtual assets into fiat currency, highlighting the point where blockchain-based activity intersects with banks, payment channels and other parts of the traditional financial system.
Published on 11 August 2026 by RUSI’s Centre for Finance and Security, the paper says North Korea has used virtual asset-to-fiat conversion services to launder large volumes of stolen cryptocurrency, with the proceeds supporting the country’s weapons of mass destruction programmes. The study focuses less on the initial crypto theft itself and more on the “off-ramp” stage — how illicit virtual assets are converted into spendable fiat funds and moved through financial infrastructure.
Where the laundering risk shifts from crypto to fiat
RUSI’s analysis highlights a compliance challenge that extends beyond crypto exchanges. Once stolen virtual assets are converted or routed toward fiat, banks and other financial institutions can become exposed through payment relationships with Virtual Asset Service Providers (VASPs), including indirect relationships involving unlicensed or weakly supervised providers.
The paper therefore treats correspondent and payment relationships between financial institutions and VASPs as an important control point. A bank may not directly service a North Korean-linked actor, but it can still face exposure where a VASP customer is processing transactions linked to another VASP whose ownership, controls or operating model are poorly understood.
Four practical recommendations
RUSI proposes clearer regulatory guidance for correspondent-style relationships between VASPs, particularly where unlicensed VASPs are involved. It also recommends developing standardised onboarding questionnaires for VASPs so financial institutions can consistently capture information on ownership, compliance arrangements and business operations.
A third recommendation is stronger secure information-sharing channels among financial institutions, regulators and VASPs. RUSI says these channels should support the exchange of intelligence such as known exchange identifiers and suspicious wallet addresses, helping firms connect blockchain indicators with activity appearing in conventional payment systems.
The paper also recommends requiring VASPs to include identifiable references in bank-transfer payment messages — for example, a VASP identifier. This would give beneficiary banks more visibility into virtual-asset-related transfers and allow them to identify and investigate potentially higher-risk activity before the crypto-to-fiat conversion disappears into ordinary-looking payment flows.
The findings are especially relevant to sanctions and proliferation-financing compliance because the risk does not end when stolen crypto leaves a blockchain address. Effective controls increasingly depend on linking wallet intelligence, VASP due diligence, payment data and bank monitoring across the full conversion chain.



