Unchained
Unchained

Why North Korea Is Interested in Cryptocurrency - Ep.150

Priscilla Moriuchi, director of strategic threat development at Recorded Future and non-resident fellow at Harvard Kennedy School, explains North Korean usage of the internet and how it has changed over time, how it is reserved only for the few most senior people in the regime, and what the mobile d

Featured Speakers

Priscilla Moriuchi Guest

Topics Discussed

Episode Summary

Executive Summary: Laura Shin interviews Priscilla Moriuchi about how North Korea uses the internet and cryptocurrency. Moriuchi explains that only a tiny elite can access the global internet, but North Korea has become increasingly security-conscious and professionalized online. The discussion covers North Korea’s crypto mining, exchange hacks, scams, malware, ransom laundering, Monero use, fiat off-ramping networks, the WannaCry attack, sanctions, and how cyber talent is cultivated and deployed for regime goals.

Main Topics: North Korea’s limited but revealing internet access (Priority: 5/5): Moriuchi explains that only a very small elite subset of North Koreans can access the global internet, and their online behavior has shifted from leisure to more professional use over time. How North Korea exploits cryptocurrency (Priority: 5/5): The conversation maps five major crypto-related activities: mining, exchange thefts, scams/cryptojacking, low-level crime paid in crypto, and possible token development. WannaCry and laundering through Bitcoin-to-Monero conversion (Priority: 5/5): They discuss the 2017 WannaCry ransomware attack, how ransom Bitcoin was moved through mixers and converted to Monero, and why that made tracing harder. North Korea’s cyber talent pipeline and overseas operations (Priority: 4/5): Moriuchi describes state-run identification, training, and deployment of hackers through schools, universities, the military, intelligence services, and overseas hacker dorms. How North Korea cashes out crypto into fiat (Priority: 4/5): The episode explores illicit physical networks, embassies, consulates, and criminal intermediaries in Asia, Europe, and elsewhere that likely help convert crypto into usable money. Sanctions, Virgil Griffith, and policy responses (Priority: 4/5): The hosts examine whether sanctions hurt ordinary North Koreans more than the regime, the Virgil Griffith case, and whether stronger KYC/AML and updated sanctions are needed.

Key Arguments: North Korea’s global-internet footprint is extremely small, likely under a few hundred people, so online behavior reflects the elite rather than the general population. The regime’s online usage has become more security-conscious over time, with wider use of HTTPS and VPNs that reduce visibility for researchers. North Korea is sophisticated in cybercrime and crypto, having used cryptojacking and related tactics as early as 2015, before most of the world understood Bitcoin. Crypto is valuable to the regime only if it can be laundered into fiat; North Korea likely relies on long-established illicit networks and intermediaries to do that. Monero is favored for anonymity, but Bitcoin remains widely used because it is easier and more liquid. The military, intelligence services, and state institutions support regime goals; cyber activity is not independent entrepreneurship but part of national strategy. WannaCry showed North Korea’s willingness to accept operational risk and use global chaos, not just direct revenue generation, as a strategic objective. Sanctions do harm ordinary North Koreans, but the regime already subordinates civilian welfare to military and nuclear priorities; therefore sanctions remain necessary in the speaker’s view. North Korea’s cyber operators are deliberately trained through a state pipeline, then often moved overseas to evade attribution and leverage foreign infrastructure. Blockchain and crypto firms can help by blocking North Korean IP ranges and improving user/customer controls, though the broader policy challenge requires stronger regulation and updated sanctions.

Data Points: North Korean global internet users: under 300 people - Moriuchi estimates the number of North Koreans with access to the global internet North Korean population: about 25 million - Referenced to contrast the tiny elite online subset with the general population Initial observed North Korean crypto mining: March 2017 - First signs of North Korean interest in cryptocurrency from IP-range monitoring WannaCry ransom wallets: 3 Bitcoin wallets - Ransom from the May 2017 WannaCry attack was directed to three wallets WannaCry cashed-out amount: about 52 BTC - Approximate total emptied from the wallets in August 2017 WannaCry cash-out value: about $142,000 - Approximate dollar value of the 52 BTC when cashed out North Korean crypto theft/banking window: late 2015 to early 2019 - Time period referenced for thefts and fraudulent SWIFT activity contributing to the UN’s estimate Total funds from cyber thefts and banking operations: $2 billion - UN-linked estimate discussed as funding North Korea’s weapons program Confidence threshold for attribution: at least 70% confidence - Moriuchi’s bar for assessing that an operation is North Korean Early Google-like behavior period: early 2017 - Point in time when internet behavior was first being studied Small-scale Litecoin mining: 2018 - Moriuchi notes brief Litecoin mining activity observed in 2018 North Korean hack infrastructure IP ranges: about 3 IP ranges - North Korea regularly uses a very small set of IP ranges for internet access History of cyber operator training: since the 1990s / late 1990s - Defector testimony references early training methods like paper keyboard exercises

Pivotal Quotes: "What many people don't realize is that when you sort of turn on your computer and you go to a website, there's what's called metadata" — Priscilla Moriuchi: Explaining how she studies North Korean activity without hacking into devices "The internet is becoming more of a tool, right, a professional tool for these North Korean leaders as opposed to just kind of a leisure activity." — Priscilla Moriuchi: Describing the shift in North Korean elite internet use over time "Those three wallets were emptied within minutes of each other in six transactions." — Priscilla Moriuchi: Discussing how WannaCry ransom Bitcoin was moved and laundered

Implications: North Korea’s crypto use is a mature, integrated part of state strategy, not a side hustle. Exchanges, protocols, and policymakers should expect sophisticated laundering, attribution evasion, and sanctions evasion, and respond with targeted blocking, stronger compliance, and updated cyber-financial controls.

🔓 Sign Up for Unlimited Episode Search

About Unchained

View all episodes from Unchained