Record $158 Billion Illicit Cryptocurrency Flows in 2025 — Threadlinqs Intelligence
As of 2026-05-30, Record $158 Billion Illicit Cryptocurrency Flows in 2025 is a medium-severity threat intel threat attributed to a North Korea (partial)-nexus actor, tracked by Threadlinqs Intelligence with 12 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 40 indicators of compromise.
Threat ID: TL-2026-0027 · Severity: MEDIUM · CVSS: 5 · Status: ACTIVE · Category: THREAT_INTEL
Attribution: North Korea (partial) · FINANCIAL
Chainalysis's 2025 Crypto Crime Report documents a record $51 billion in illicit cryptocurrency transaction volume for 2024, with cumulative illicit flows exceeding $158 billion since comprehensive
The $158 billion in illicit cryptocurrency flows represents the convergence of traditional organized crime, state-sponsored hacking, cybercrime-as-a-service, and financial fraud into a single financial infrastructure that law enforcement and regulators struggle to control.
**Scale of the Problem:**
Chainalysis tracks illicit cryptocurrency activity across multiple categories:
- **Ransomware**: $1.1 billion in direct ransom payments (2023), down from $1.3B peak but still at historically high levels. Includes Conti, LockBit, BlackCat/ALPHV, Cl0p, Royal, Play, Akira.
- **Investment Fraud/Pig Butchering**: $4.57 billion (FBI IC3 2023). Connects to TL-2026-0017. Cryptocurrency is the EXCLUSIVE payment method for pig butchering scams due to irreversibility.
- **Stolen Funds (DeFi/Bridge Hacks)**: $3.8 billion peak (2022), ~$1.7B (2023). Major incidents: Ronin Bridge ($625M), Wormhole ($320M), Nomad Bridge ($190M), Euler Finance ($197M).
- **Sanctioned Entity Transactions**: $14.9 billion annually — includes OFAC-designated exchanges (Garantex), sanctioned nation-state wallets (North Korea, Iran, Russia), and sanctioned mixer services.
- **Darknet Markets**: $1.7 billion (2023). Hydra market ($5.2B lifetime) was seized in 2022; successors include Mega, OMG, Blacksprut.
- **Scams**: $5.9 billion (2023) across romance, giveaway, impersonation, and investment scams.
- **CSAM**: $25.4 million identified on-chain (likely significant undercount).
**The Laundering Pipeline:**
Illicit cryptocurrency follows a consistent laundering pattern:
1. **Placement**: Proceeds deposited to scammer/hacker-controlled wallet
2. **Layering Stage 1**: Rapid transfer through 5-50 intermediate wallets (peel chains)
3. **Layering Stage 2**: Conversion through mixers (Tornado Cash, Sinbad — now sanctioned), cross-chain bridges (RenBridge, THORChain, deBridge), or DEX swaps (Uniswap, 1inch)
4. **Layering Stage 3**: Stablecoin conversion (USDT/USDC) for price stability during layering
5. **Integration**: Conversion to fiat via:
- Unregulated OTC desks (predominantly in China, Russia, UAE)
- Nested exchanges (services that use Binance/other exchange infrastructure but apply minimal KYC)
- Peer-to-peer platforms (LocalBitcoins successor services, Paxful)
- Money mule networks with bank accounts in multiple jurisdictions
**North Korea (Lazarus Group / APT38):**
The DPRK's cryptocurrency theft program is arguably the most significant nation-state financial cybercrime operation in history:
- $1.7 billion stolen in 2022 alone (Chainalysis)
- $600 million Ronin Bridge hack (March 2022) — largest single DeFi theft
- Funds directly finance North Korea's weapons of mass destruction programs (UN Panel of Experts)
- Laundering via China-based OTC desks, Tornado Cash, Sinbad, and cross-chain bridges
- IT worker fraud scheme: DPRK citizens obtain remote tech jobs at Western companies, salary diverted to regime
- Estimated cumulative theft: $3+ billion since 2017
**Stablecoin Shift:**
A fundamental change in the illicit crypto landscape:
- 2020: Bitcoin dominated illicit transactions (~70%)
- 2024: Stablecoins (USDT primarily) account for >60% of illicit transaction volume
- Reasons: faster settlement, lower fees, broader acceptance, price stability during laundering
- Tether (USDT) has frozen $835+ million in addresses associated with illicit activity (as of mid-2024)
- USDC (Circle) has more aggressive compliance — accounts for smaller share of illicit volume
- Challenge: Tether operates primarily outside US jurisdiction, complicating enforcement
**Mixer Disruption & Evolution:**
- Tornado Cash sanctioned by OFAC (August 2022) — developers arrested
- Sinbad seized by FBI/Europol/Netherlands (November 2023)
- ChipMixer seized (March 2023)
- Blender.io sanctioned (May 2022)
- Result: Criminals shifting to cross-chain bridges and DEX swaps which are harder to sanction
- THORChain: $900M+ in illicit flows identified (Chainalysis)
- Cross-chain bridges now th
Target sectors: Finance, Cryptocurrency, All Sectors (ransomware targets)
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 12 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 40 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, MEDIUM, threat intelligence, cybersecurity, T1589, T1596, T1583, T1583, T1585, T1190, T1566, T1566, T1204, T1528