OAK — OnChain Attack Knowledge

Worked example · 2026-07

DPRK state banks breached from the inside — former military operators are reported arrested for diverting state funds into overseas crypto wallets and structuring them out through Chinese border brokers — Central Bank of the DPRK / Foreign Trade Bank — 2026-07-12 (reported 2026-07-25)

Loss
Not specified. The report describes "foreign currency and state trade funds" diverted from the Central Bank of the DPRK and the Foreign Trade Bank, without a figure. OAK does not estimate one.
OAK Techniques observed
OAK-T7.010 (Travel-Rule / Reporting-Threshold Evasion — primary as reported. The off-ramp leg is the crypto-native part: proceeds held in overseas crypto wallets were converted to dollars and yuan through Chinese brokers in the border cities of Sinuiju and Hyesan, with transfers split into small amounts to avoid detection. Structuring at an informal off-ramp operates on proceeds already on-chain, which is the direction T7 covers. See techniques/T7.010-travel-rule-evasion.md). OAK-T8.005 (Operational-Security Procedural Failure — cross-referenced, and the reason the operation reportedly ended: detection came from discrepancies in foreign-currency payment approvals and suspicious overseas IP activity, i.e. from the operators' own procedural traces rather than from any crypto-side analysis). The intrusion leg is deliberately left unmapped: the report says the group "breached the internal systems" of the two banks and describes no vector. Consistent with OAK's handling of examples/2025-07-central-bank-brazil-breach-crypto-exit.md, an undescribed compromise of a non-crypto institution is not assigned a Technique on the strength of the word "breached."
Attribution
inferred-weak — single source, partial evidence, per METHODOLOGY.md. The accused are described as former military hackers, arrested by North Korea's National Intelligence Agency on 2026-07-12 at a safe house in Pyongyang. No names, no group designation, and no link to a tracked OAK actor: nothing in the report ties these operators to OAK-G01 (Lazarus), OAK-G07 (APT43/Kimsuky), OAK-G08 (Bluenoroff), OAK-G09 (Andariel), or OAK-G04 (the DPRK IT-worker scheme), and OAK does not infer one from shared nationality or a military background. Per OAK's neutral-framing convention, the operators' affiliation and the identity of the victim are metadata: this is documented as a mechanism, not as a geopolitical event.
Key teaching point
The reported detection path contains no crypto forensics at all — the operation was reportedly surfaced by an accounting reconciliation and an IP anomaly. Officials are said to have noticed discrepancies in foreign-currency payment approvals and suspicious overseas IP activity; the crypto wallets, the border brokers, and the structured transfers were all downstream of a compromise found by conventional internal-control review. That inversion is the transferable point for any institution whose funds can be diverted into crypto: the highest-yield detection surface is the ledger you already own, not the chain the proceeds land on. Structuring, informal brokers, encrypted messaging, unregistered phones, and foreign wireless equipment — all reportedly used here — are countermeasures aimed squarely at external observation, and they do nothing about a payment-approval reconciliation run by the victim. The corollary for defenders on the crypto side is narrower but real: the off-ramp, not the wallet, is where an operation like this is constrained, because converting to physical currency through border brokers is the one step that cannot be performed pseudonymously and that scales badly as amounts grow.

⚠ Single-source, independently unverified. The entire account derives from Daily NK, citing one anonymous source in Pyongyang. Subsequent coverage by CoinDesk and others reproduces that single report rather than corroborating it, and the reporting outlets state explicitly that it could not be independently verified. No DPRK state announcement, no external law-enforcement record, and no on-chain artefact has been published. OAK records this at inferred-weak and readers should treat every specific below as reported-not-established. It is retained because the mechanism shape is documented nowhere else in the corpus, not because the account is confirmed.

Summary

According to a report by Daily NK citing a single anonymous source in Pyongyang — not independently verified — North Korea's National Intelligence Agency arrested a group of former military hackers on 2026-07-12 at a safe house in Pyongyang.

The group is accused of having breached the internal systems of the Central Bank of the DPRK and the Foreign Trade Bank, diverted foreign currency and state trade funds, and moved the money into overseas cryptocurrency wallets. The report describes no intrusion vector and gives no total.

The proceeds were then reportedly converted into dollars and yuan through Chinese brokers in the border cities of Sinuiju and Hyesan. To avoid detection the group is said to have split transfers into small amounts and relied on encrypted messaging applications, unregistered phones, and Chinese wireless equipment.

Detection reportedly came not from any crypto-side analysis but from ordinary institutional controls: officials discovered discrepancies in foreign-currency payment approvals and suspicious overseas IP activity.

Timeline (UTC)

When Event OAK ref
(undated, prior) Group reportedly breaches internal systems of the Central Bank of the DPRK and the Foreign Trade Bank; vector not described (unmapped — no vector established)
(undated, prior) Foreign currency and state trade funds diverted and moved into overseas crypto wallets; amount not specified (fiat-predicate diversion)
(ongoing, prior) Proceeds converted to dollars and yuan via Chinese brokers in Sinuiju and Hyesan; transfers split into small amounts; encrypted messaging, unregistered phones, and Chinese wireless equipment used T7.010
(prior) Officials identify discrepancies in foreign-currency payment approvals and suspicious overseas IP activity T8.005 (detection)
2026-07-12 Arrests by the National Intelligence Agency at a safe house in Pyongyang (enforcement)
2026-07-25 Daily NK publishes the account, citing one anonymous Pyongyang source; reproduced by CoinDesk and others; not independently verified (reporting)

What defenders observed

  • Detection came from the victim's own books. Payment-approval reconciliation and IP-anomaly review — two controls that exist at every financial institution and require no blockchain capability — reportedly surfaced an operation whose crypto leg was specifically engineered against external observation. Institutions worried about internal diversion into crypto should weight internal reconciliation far above chain analytics in their control mix (M05, M23).
  • Structuring defends against thresholds, not against reconciliation. Splitting transfers into small amounts defeats reporting triggers and volume heuristics. It does nothing about a control that compares approved payments against executed ones, because that control does not depend on any transfer being large.
  • The off-ramp is the constraint. Value sitting in overseas wallets is only realised when it becomes spendable currency, and here that required physical brokers in two named border cities. That step is geographically fixed, relationship-dependent, and scales poorly — which makes it both the operation's bottleneck and its most attributable component (M06).
  • Tradecraft inventory is the reusable artefact. Encrypted messaging applications, unregistered phones, and foreign wireless equipment form a coherent, repeatable off-chain toolkit. Where the crypto leg of an operation is designed to be unremarkable, this off-chain kit is often the more distinctive signature, and it is the sort of detail that clusters cases together when a second one appears.
  • No on-chain artefact was published. No addresses, no amounts, no transaction identifiers. Nothing here can be used to seed a cluster, screen a counterparty, or validate a heuristic — which is precisely the limitation of a single-source narrative account and the reason this entry carries the caveat it does.

Public references

  • [coindeskdprkarrests2026] — CoinDesk, "North Korea arrests hackers accused of laundering stolen bank funds through crypto" (the 2026-07-12 arrest by the National Intelligence Agency at a Pyongyang safe house, the Central Bank of the DPRK and Foreign Trade Bank as the breached institutions, the diversion into overseas crypto wallets, conversion to dollars and yuan via Chinese brokers in Sinuiju and Hyesan, the splitting of transfers with encrypted messaging / unregistered phones / Chinese wireless equipment, and detection via foreign-currency payment-approval discrepancies and suspicious overseas IP activity — sourced to Daily NK citing an anonymous Pyongyang source, and explicitly noted as not independently verifiable): https://www.coindesk.com/business/2026/07/25/north-korea-arrests-hackers-accused-of-laundering-stolen-funds-from-country-s-bank-via-crypto
  • [cryptobriefingdprkarrests2026] — Crypto Briefing, "North Korea arrests its own hackers for stealing from state banks and laundering through crypto" (secondary coverage of the same Daily NK account; reproduces rather than corroborates): https://cryptobriefing.com/north-korea-arrests-cyber-operators-bank-hacking/

Discussion

OAK's DPRK material is built almost entirely on the outbound case — state-aligned operators stealing from foreign exchanges and protocols, documented across OAK-G01, G04, G07, G08, and G09 with strong forensic sourcing. This entry is the inverse and, if accurate, the first in the corpus: operators from that same ecosystem reportedly stealing from their own state's banks, and being caught by their own state's internal controls. The corpus should hold that possibility explicitly, because a threat model that treats a national operator cohort as a monolith with uniformly aligned incentives will misread both defection and internal enforcement when they appear.

The scope question is worth stating plainly rather than resolving by assertion. Like the Brazil central-bank case, the predicate crime is fiat, committed against a non-crypto institution, and OAK declines to assign a Technique to an intrusion whose vector nobody has described. The difference — and the reason this entry carries T7.010 where Brazil carries none — is the direction of the crypto leg. In Brazil, stolen fiat was converted into crypto, an on-ramp purchase that no T7 primitive describes. Here, proceeds are reported to have sat in overseas crypto wallets and then been structured out through brokers, which is laundering of on-chain proceeds and squarely the direction T7 covers. That distinction is the useful precedent from this entry regardless of whether the underlying account holds up: the on-ramp is not a laundering Technique; the structured off-ramp is.

A final caution about how this case will be cited. The narrative is vivid, geopolitically resonant, and rests on one anonymous source relayed through a single outlet — precisely the profile of a story that hardens into fact through repetition. OAK's inferred-weak label and the header caveat exist to keep that from happening inside the corpus. If a DPRK state announcement, a defector account, or any on-chain artefact later corroborates or contradicts it, this file should be revised or removed rather than quietly left standing; contributors should treat it as an open item, not a settled one.

Techniques demonstrated (2)