Custodial wallet / SaaS in North Korea
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is not permitted in North Korea.
Verdict Details
- Permitted
- no
- Local entity required
- No
- Licensing burden
- None
- Last updated
- 2026-07-13
AML Obligations
- North Korea is subject to FATF's 'Call for Action' (high-risk jurisdiction with strategic AML/CFT deficiencies), requiring all countries to apply enhanced due diligence and counter-measures to any transactions involving the DPRK
- UN Security Council sanctions (UNSC 1718 Committee) impose comprehensive financial restrictions on North Korea
- U.S. OFAC sanctions prohibit U.S. persons and entities from transacting with North Korea or DPRK-linked persons/entities
- EU and other national sanctions regimes impose their own blocking measures on dealings with North Korea
- Any entity facilitating transactions involving North Korea risk enforcement action including asset freezes, sanctions, and criminal prosecution
- No domestic AML/KYC framework exists for private VASPs within North Korea — the state actively works to circumvent global AML/KYC procedures
Key Restrictions
- No legitimate market for private custodial wallet services exists within North Korea
- All crypto activities in the DPRK are state-controlled, state-sponsored, or illicit (cyber theft, sanctions evasion)
- There are no publicly known licensing regimes, qualified-custodian definitions, or custody regulations for private entities
- The FATF lists North Korea as a jurisdiction requiring counter-measures — any VASP engaging with DPRK actors faces severe international sanctions exposure
- Segregation of client assets, insurance/bonding requirements, cold-storage mandates, and proof-of-reserves rules do not exist as regulatory concepts for private custodians
Key Risks
- Extreme sanctions and enforcement risk: OFAC, UNSC, and FATF all target DPRK-linked crypto activity — enforcement actions include asset freezes, indictments, and infrastructure seizures (e.g., Sinbad.io mixer shutdown, Lazarus Group prosecutions)
- Regulatory ambiguity: any internal DPRK laws governing state-controlled crypto activities are classified and inaccessible
- Impossibility of compliant operation: a private custodial wallet operator cannot operate lawfully in/from North Korea while also meeting global AML/CFT and sanctions obligations
- Reputational and financial-exclusion risk: any nexus to North Korea exposes an operator to global financial isolation
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
State-Controlled and Illicit Activity: North Korea operates as a highly isolated, centrally controlled state where the government itself is the primary, if not sole, actor in the cryptocurrency space. Its documented activities in digital assets are almost exclusively related to illicit financing, cybercrime (e.g., ransomware, hacking exchanges), and sanction evasion, often conducted by state-sponsored hacking groups like the Lazarus Group.
No Public Market for Private Services: There is no known legitimate or public market for private cryptocurrency custodial services, exchanges, or investment funds within North Korea. The concept of "client assets" or "private custodians" as distinct from the state's own operations is fundamentally alien to its economic and political structure.
Lack of Transparency: North Korea is one of the most opaque countries in the world. Its laws, especially those concerning financial activities and technology, are rarely, if ever, made public or accessible to the international community. Any internal directives or operational guidelines for state-controlled entities dealing with cryptocurrency would be highly classified.
Custodial License Requirements: There are no publicly known licensing requirements for private entities because such private entities operating legitimate crypto custody services likely do not exist or are not permitted. Any crypto activities are either directly run by the state or under its strict, clandestine control.
Segregation of Client Assets Rules: This concept presupposes clients and service providers. Since there's no public market for private custody, there are no rules for segregating client assets. The state would not distinguish between its own assets and "client" assets in the way a regulated financial institution would.
Insurance/Bonding Requirements: These are market-based protections for customers against loss or insolvency. Given the absence of a public market and private service providers, such requirements do not exist.
Qualified Custodian Definitions: There are no publicly defined "qualified custodians" as the framework for private, regulated financial services does not exist in this domain.
Exchanges, Custody Providers, Payment Processors: There are no publicly known or established licensing regimes or requirements for these types of entities to operate legally and openly within North Korea for a domestic market. Any virtual asset activity occurring within the DPRK is either:
Directly managed by state-affiliated entities (e.g., intelligence agencies, state-owned banks, research institutions).
Carried out by state-sponsored hacking groups (like the Lazarus Group).
Highly controlled and isolated, serving specific state objectives rather than a private market.
Registration vs. Licensing Regime: The distinction between registration and licensing regimes, as understood in conventional financial regulation, does not apply to virtual asset service providers (VASPs) within North Korea. There is no public body for registration or licensing of private crypto businesses.
AML/KYC (Anti-Money Laundering/Know Your Customer): North Korea actively works to circumvent AML/KYC procedures globally. Its primary goal is to hide the origin and destination of funds, making it impossible to identify the ultimate beneficial owner. They exploit weaknesses in VASP AML/KYC processes internationally. Within North Korea, there are no requirements for domestic actors to adhere to AML/KYC in the conventional sense, as their operations are designed to bypass such measures.
FATF Blacklisting: As mentioned, it remains on the FATF's "Call for Action" list, signaling to all countries to apply enhanced due diligence and counter-measures to transactions involving North Korea.
UN Sanctions: North Korea is subject to extensive sanctions imposed by the United Nations Security Council (UNSC) due to its nuclear and ballistic missile programs. These sanctions severely restrict its access to the international financial system.
National Sanctions: Countries like the United States (through OFAC), the European Union, and others implement their own robust sanctions regimes against North Korea, targeting individuals, entities, and financial institutions involved in supporting the DPRK regime's illicit activities.
Financial Exclusion: Due to these sanctions and the high-risk designation, North Korea is largely cut off from the legitimate global financial system. Any entities attempting to transact with North Korea, especially concerning virtual assets, face significant risks of violating sanctions and being subject to severe penalties themselves in other jurisdictions.
Regulator Name: U.S. Department of the Treasury (Office of Foreign Assets Control - OFAC)
Entity Targeted: Cryptocurrency Mixers (e.g., Sinbad.io). Violation Type: Facilitating money laundering for sanctioned entities, including North Korea's Lazarus Group, for proceeds from major cryptocurrency heists. Penalty Amount: Assets frozen, U.S. persons prohibited from transacting with the entity, effective shutdown of the service. (No specific fine amount against the mixer, but the economic impact is a cessation of operations).
Entity Targeted: Individuals and associated cryptocurrency addresses linked to North Korean state-sponsored hacking groups (e.g., Lazarus Group/APT38). Violation Type: Conspiracy to commit money laundering, international money laundering, conspiracy to commit computer fraud, theft of cryptocurrency. Penalty Amount: Indictment of individuals, seizure of tens of millions of dollars in stolen cryptocurrency.
Outcome: Shut down of the Sinbad mixer, seizure of its infrastructure, and disruption of a critical money laundering avenue for North Korean hackers. This followed similar actions against Tornado Cash in August 2022, which was also used by the Lazarus Group.
Outcome: Recovery of a significant portion of stolen funds, disruption of North Korea's ability to cash out illicit gains, and public identification of wallet addresses and laundering techniques used by DPRK actors. The indictments serve as a deterrent and basis for future arrests if individuals leave North Korea.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
No — custodial wallet/SaaS services cannot be lawfully operated in or from North Korea as a private business; the DPRK has no legitimate market for private crypto custodial services, all crypto activities are state-controlled or illicit, and any engagement with DPRK-linked actors carries extreme international sanctions and AML enforcement risk (OFAC, UNSC, FATF).
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?