The Hague: Sanctions were designed for a world of banks, ships and border crossings. North Korea has spent the past few years demonstrating how poorly that machinery copes with an adversary that steals its money in cryptocurrency. For the European Union, which screens against the same core designations as the United Nations, the scale of Pyongyang’s digital plunder in 2026 has turned an abstract compliance duty into a live security problem.
The numbers are stark. DPRK-linked hackers stole roughly two billion dollars in cryptocurrency in 2025, a sharp rise on the year before, lifting their cumulative haul to well over six billion. Through the early months of 2026 North Korean actors accounted for the overwhelming majority of all crypto stolen worldwide. The February 2025 theft of around 1.5 billion dollars from the exchange Bybit, attributed by investigators to the Lazarus-linked cluster, remains the largest single cryptocurrency heist on record, and further nine-figure exploits have followed. This is not opportunistic crime; it is a state financing programme run through code.
What makes the threat hard to counter is that it sidesteps the choke points sanctions usually exploit. Russia and Iran evade restrictions by hiding trade and shipping; North Korea simply takes digital assets and launders them through mixers, chain-hopping and a sprawling network of front identities. A parallel operation places North Korean IT workers inside Western technology firms under false identities, harvesting wages, credentials and source code. The proceeds, by widespread assessment, flow toward the regime’s weapons programmes, which is why the activity sits at the intersection of cybercrime and proliferation rather than in either box alone.
For European enforcement the implications are uncomfortable. EU operators must screen against the consolidated list, and the bloc has expanded its sanctions toolkit to capture crypto service providers and even a ruble-backed stablecoin. But a designation only works if someone can identify the wallet, the worker or the front company behind a transaction, and that requires intelligence and technical tracing that traditional sanctions bureaucracies were never built to perform. A European firm can be fully compliant on paper and still unwittingly employ a disguised North Korean engineer or process tainted funds.
The response is increasingly collective. The Multilateral Sanctions Monitoring Team, an eleven-nation coalition that includes several EU member states alongside the United States, Britain, Japan and South Korea, was formed to replace the defunct UN Panel of Experts and focus squarely on cyber and crypto evasion. Its premise is that no single jurisdiction can track funds that cross dozens of borders in seconds; only shared intelligence, common analytics and coordinated designations stand a chance. Private blockchain-analytics firms have become unlikely partners, supplying the forensic capability that states lack.
The broader lesson for Europe is that economic-security policy can no longer treat cyber theft as a niche concern. As long as a sanctioned state can fund itself by draining digital wallets, the credibility of the entire sanctions architecture is in question. Closing the gap will demand investment in tracing capacity, tighter obligations on crypto platforms operating in Europe, and a willingness to share intelligence at the speed the threat moves. The alternative is a sanctions net with a hole precisely where the money now flows.




