Dandong: Trucks still cross the Yalu River bridge here carrying the physical trade that North Korea sanctions were designed to interrupt, and the customs officers who inspect them are policing the wrong century. The money that matters to Pyongyang now moves as code.
The figures make the point without embellishment. Blockchain analysts attribute roughly 2.02 billion dollars in cryptocurrency theft to North Korea-linked actors during 2025, a rise of about half on the previous year, bringing the cumulative total attributed to those groups to some 6.75 billion dollars. Through the first four months of 2026 they accounted for the large majority of all value stolen in crypto hacks worldwide. No sanctioned state has ever financed itself this way before.
Europe’s response rests on a legal architecture built for a different problem. The Union’s North Korea regime mirrors United Nations designations and adds autonomous listings, and it works the way sanctions regimes have always worked. It names people. It names companies. It freezes assets held by named parties inside European jurisdiction. Every one of those steps assumes an identifiable holder of an identifiable account.
Pyongyang’s revenue model breaks that assumption in two places. Theft produces funds nobody has to hold in a named account. And the parallel operation, in which North Korean nationals take remote technology jobs under stolen or fabricated identities, produces salary income that European employers pay voluntarily to people they believe are elsewhere. American authorities designated further targets tied to that programme in March 2026, and the State Department set out the pattern in January. The scheme has since evolved further, with operatives posing as recruiters to harvest credentials and source code rather than merely applying for jobs.
The enforcement mismatch is structural. A European company that hires a fraudulent contractor through an intermediary platform has probably breached sanctions without ever seeing a listed name. Whether it faces consequences depends on national implementation, which varies across the twenty-seven, and on whether any authority ever reconstructs the chain.
Multilateral machinery has thinned at exactly the wrong moment. The UN Panel of Experts that produced the definitive public accounting of North Korean evasion lost its mandate in 2024 after a Russian veto. A successor arrangement outside the Council now performs part of that function, but it lacks the Council’s formal standing, and European policy has relied heavily on that reporting for its own listings.
Some tools do fit. The Union’s markets in crypto-assets framework brings exchanges under supervision and imposes identification duties that give European authorities visibility they previously lacked. Its anti-money-laundering package tightens the same channels. Neither was designed as a counter-proliferation instrument, and both stop at the Union’s border, which is where most of the laundering begins.
The uncomfortable conclusion is that Europe’s North Korea policy has become largely declaratory. Listings still signal disapproval and still complicate the lives of named individuals. They no longer meaningfully constrain the revenue stream that funds the weapons programme they exist to slow. Closing that gap would mean treating cyber theft as a sanctions problem rather than a cybersecurity one, and nobody in Brussels has proposed the institutional change that would require.




