Self-custodial wallet / non-custodial software in North Korea
Publisher of software where users hold their own private keys. The publisher never holds, controls, or has access to user funds.
Self-custodial wallet is not permitted in North Korea.
Verdict Details
- Permitted
- no
- Local entity required
- No
- Licensing burden
- None
- Last updated
- 2026-07-13
AML Obligations
- No AML obligations apply to a non-custodial software publisher operating from outside North Korea, as the publisher does not engage in VASP activity (no custody, no control over funds).
- Any AML/KYC obligations that exist in the DPRK context are state-centric — state-affiliated entities actively circumvent global AML/KYC procedures, not comply with them.
- FATF lists North Korea as a high-risk jurisdiction with significant strategic deficiencies, calling for counter-measures from all other jurisdictions.
- UN Security Council sanctions (UNSC 1718) impose comprehensive sanctions on North Korea, restricting access to the international financial system.
Key Restrictions
- The DPRK has no public licensing regime, no regulatory framework for VASPs, and no mechanism for private companies to legally operate crypto services.
- All virtual asset activity within the DPRK is either directly managed by state-affiliated entities (intelligence agencies, state-owned banks) or carried out by state-sponsored hacking groups.
- There is no market for private software publishing; any software-related activity would be state-controlled.
- A publisher of self-custodial software would face extreme sanctions risk globally, as doing business with or in North Korea is subject to comprehensive UN and national (e.g., US OFAC) sanctions.
Key Risks
- Severe sanctions exposure under US OFAC, UNSC, and EU sanctions regimes for any dealings connected to North Korea.
- FATF 'Call for Action' counter-measures require all jurisdictions to apply enhanced due diligence to transactions involving North Korea — any software distributed in or from KP would be high-risk.
- Enforcement precedent shows US DOJ/OFAC aggressively targeting entities facilitating North Korean-linked crypto activity (e.g., Sinbad.io mixer shutdown, seizures of stolen funds).
- North Korean IT workers may fraudulently pose as non-DPRK nationals; a non-custodial wallet publisher could inadvertently facilitate funds flowing to sanctioned entities.
- Complete regulatory opacity — no reliable legal framework exists; any 'permission' would be at the discretion of a hostile, isolated regime.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Exchanges, Custody Providers, Payment Processors: There are no publicly known or established licensing regimes or requirements for these types of entities to operate legally and openly within North Korea for a domestic market. Any virtual asset activity occurring within the DPRK is either:
Directly managed by state-affiliated entities (e.g., intelligence agencies, state-owned banks, research institutions).
Carried out by state-sponsored hacking groups (like the Lazarus Group).
Highly controlled and isolated, serving specific state objectives rather than a private market.
Registration vs. Licensing Regime: The distinction between registration and licensing regimes, as understood in conventional financial regulation, does not apply to virtual asset service providers (VASPs) within North Korea. There is no public body for registration or licensing of private crypto businesses.
AML/KYC (Anti-Money Laundering/Know Your Customer): North Korea actively works to circumvent AML/KYC procedures globally. Its primary goal is to hide the origin and destination of funds, making it impossible to identify the ultimate beneficial owner. They exploit weaknesses in VASP AML/KYC processes internationally. Within North Korea, there are no requirements for domestic actors to adhere to AML/KYC in the conventional sense, as their operations are designed to bypass such measures.
FATF Blacklisting: As mentioned, it remains on the FATF's "Call for Action" list, signaling to all countries to apply enhanced due diligence and counter-measures to transactions involving North Korea.
UN Sanctions: North Korea is subject to extensive sanctions imposed by the United Nations Security Council (UNSC) due to its nuclear and ballistic missile programs. These sanctions severely restrict its access to the international financial system.
National Sanctions: Countries like the United States (through OFAC), the European Union, and others implement their own robust sanctions regimes against North Korea, targeting individuals, entities, and financial institutions involved in supporting the DPRK regime's illicit activities.
No Public Market for Private Services: There is no known legitimate or public market for private cryptocurrency custodial services, exchanges, or investment funds within North Korea. The concept of "client assets" or "private custodians" as distinct from the state's own operations is fundamentally alien to its economic and political structure.
State-Controlled and Illicit Activity: North Korea operates as a highly isolated, centrally controlled state where the government itself is the primary, if not sole, actor in the cryptocurrency space. Its documented activities in digital assets are almost exclusively related to illicit financing, cybercrime (e.g., ransomware, hacking exchanges), and sanction evasion, often conducted by state-sponsored hacking groups like the Lazarus Group.
Lack of Transparency: North Korea is one of the most opaque countries in the world. Its laws, especially those concerning financial activities and technology, are rarely, if ever, made public or accessible to the international community. Any internal directives or operational guidelines for state-controlled entities dealing with cryptocurrency would be highly classified.
There is no public regulatory framework for private digital asset custody services.
Entity Targeted: Cryptocurrency Mixers (e.g., Sinbad.io). Violation Type: Facilitating money laundering for sanctioned entities, including North Korea's Lazarus Group, for proceeds from major cryptocurrency heists. Penalty Amount: Assets frozen, U.S. persons prohibited from transacting with the entity, effective shutdown of the service. (No specific fine amount against the mixer, but the economic impact is a cessation of operations).
Entity Targeted: Individuals and associated cryptocurrency addresses linked to North Korean state-sponsored hacking groups (e.g., Lazarus Group/APT38). Violation Type: Conspiracy to commit money laundering, international money laundering, conspiracy to commit computer fraud, theft of cryptocurrency. Penalty Amount: Indictment of individuals, seizure of tens of millions of dollars in stolen cryptocurrency.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
No — a self-custodial wallet publisher cannot lawfully operate in or from North Korea; there is no public licensing regime for any kind of VASP (including non-custodial software), all crypto activity is state-controlled or illicit, and any connection to DPRK would trigger severe international sanctions exposure.
Questions this verdict aims to answer
- Does software publishing trigger VASP / MSB classification?
- Do AML obligations attach when no custody exists?
- What disclosure or consumer-protection rules apply?