Chinese Crime Syndicate Laundered $1B for North Korea’s Lazarus Group
Blockchain investigator ZachXBT has uncovered a sophisticated money laundering operation involving a Chinese crime syndicate and North Korea’s notorious Lazarus Group. In an October 5 thread on X, ZachXBT detailed how he infiltrated the network by posing as a client in February 2025. He transferred $349,700 in stablecoins and accepted a 5% loss on each transaction to gain the trust of a key operator, known as “Jimmy Green.”
The investigation revealed that the syndicate laundered over $1 billion stolen from multiple crypto exploits for Lazarus. ZachXBT identified a cluster of more than $12 million linked to the Bybit hack, with Tether freezing $442,000 in associated USDt. The operations were centered in Hong Kong and mainland China, providing rare insight into the intermediaries facilitating North Korea’s illicit activities.
North Korean hackers, including Lazarus, have stolen at least $6.75 billion in digital assets through 2025, according to Chainalysis. The group typically employs complex laundering methods, such as chain-hopping and token swapping through decentralized exchanges to obscure the flow of funds. Chinese intermediaries have played a crucial role in this process, with past cases involving US prosecutions for laundering over $100 million stolen by North Korean hackers.
ZachXBT also linked Chinese actors to the laundering of funds from the $387.5 million Bitget exploit in September. The investigator found that these actors were openly seeking support in public Discord servers and Telegram channels, with one operator previously involved in laundering funds from the $292 million Kelp DAO exploit in April.