Chinese Crime Syndicate Laundered $1B for North Korea’s Lazarus Group
Blockchain investigator ZachXBT has uncovered a sophisticated money laundering operation involving a Chinese crime syndicate and North Korea’s Lazarus Group. In an Oct. 5 report on X, ZachXBT detailed how he infiltrated the network by posing as a client in February 2025, just days after the Bybit hack. He transferred $349,700 in stablecoins, taking a 5% loss on each transaction to gain the trust of a key operator named “Jimmy Green.”
The investigation revealed that the network operated across Hong Kong and mainland China, facilitating the laundering of over $1 billion stolen from multiple crypto exploits. ZachXBT identified a cluster of more than $12 million in Bybit-linked funds, leading Tether to freeze $442,000 in associated USDt (USDT). This operation sheds light on the intermediaries helping North Korean hackers move stolen crypto, who have amassed at least $6.75 billion in digital assets through 2025, according to Chainalysis.
North Korean hackers typically use a multi-stage laundering process, including chain-hopping and token swapping through decentralized exchanges and bridges. Chinese intermediaries have played a critical role in this process. In 2020, U.S. prosecutors charged two Chinese nationals with laundering over $100 million stolen by North Korean hackers from a cryptocurrency exchange in 2018. In 2023, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) sanctioned two crypto traders from Hong Kong and China for their role in converting stolen crypto and bypassing financial controls.
ZachXBT has also linked Chinese actors to the laundering of funds from the $387.5 million Bitget exploit in September 2023. The investigator found that these actors were openly seeking support in public Discord servers and Telegram channels. One operator was previously involved in laundering funds from the $292 million Kelp DAO exploit in April 2023.