TLDR
The U.S. Department of Justice filed civil complaints to forfeit about $15.1 million in USDT tied to North Koreas APT38 after 2023 crypto platform hacks, with funds first seized by the FBI in March 2025 per a media report.
- The DOJ links the USDT to four overseas platform breaches attributed to APT38 in 2023, with ongoing laundering via mixers and bridges per a report.
- The FBI seized the assets in March 2025; DOJ seeks court approval to return them to victims per coverage.
- In parallel, five individuals pleaded guilty for aiding North Korean IT worker infiltration at 136 U.S. companies per a report.
Deep Dive
1. Amount and Origin
DOJ actions target $15.1 million in USDT traced to APT38 and four 2023 hacks of overseas virtual currency platforms, with laundering through mixers, bridges, exchanges, and OTC brokers per a report.
- The DOJ did not list platforms by name, but timelines align with major 2023 incidents; identification remains unconfirmed per coverage.
- The focus is on cutting off DPRK cyber-theft funding channels and increasing restitution to victims per a policy update.
Enforcement around stolen stablecoins is intensifying. If you track venue risk, watch for faster freezes and seizures on cross-chain paths and OTC routes.
2. Process and Return
The FBI seized the USDT in March 2025%%CKPROTECTED2%%; DOJ filed civil forfeiture complaints to permanently forfeit and enable victim restitution per coverage.
- Civil forfeiture is a court process to convert seized assets into recoverable funds, emphasizing victim compensation per the policy report.
- DOJ notes ongoing tracing and seizures as APT38 keeps moving funds across services per a report.
Recovery can take months. For operations and compliance teams, expect longer claim windows and more formal proofs when funds are returned.
3. Related Actions
Alongside the forfeiture effort, five defendants pleaded guilty for facilitating North Korean IT worker infiltration at 136 U.S. companies, including identity and device hosting schemes per a report.
- The DOJ highlights these labor and identity schemes as core funding sources for DPRK operations per the policy report.
- Authorities emphasize stronger vetting for remote workers and supply chain controls per the policy report.
Beyond crypto theft, enforcement now targets supporting logistics. Companies should tighten remote-identity checks and device policies.
Conclusion
The DOJs sought forfeiture of $15.1 million in USDT linked to APT38 reflects a broader push to disrupt DPRK's crypto theft and return funds to victims. Expect more cross-chain tracing, faster seizures, and parallel actions against identity and labor schemes that facilitate illicit finance.
