Chinese Network Laundered $1 Billion for North Korea’s Lazarus Group
Blockchain investigator ZachXBT uncovered a massive crypto laundering operation tied to North Korea’s Lazarus Group. His report reveals that a Chinese crime network laundered over $1 billion for Lazarus, including a significant portion of the $1.5 billion stolen from the Bybit exchange in February 2025. ZachXBT detailed his findings in a 12-part thread on X on October 5, 2026, after spending months undercover as a client of the laundering network.
To gain the operators’ trust, ZachXBT funded a new Ethereum wallet with 349,700 USDC and accepted a 5% loss on each transaction. He compared their private messages with public blockchain records, identifying links to the Bybit hack. His work led to the freezing of 442,000 USDT by Tether and over $75 million connected to North Korean hacks since 2022.
The laundering network converted stolen funds between Bitcoin, Ethereum, Solana, and Tron using the THORChain bridge and low-volume token pools on Uniswap. This made tracing the funds more difficult before they were cashed out. Since North Korea lacks access to the global banking system, Lazarus relies on outside operators to convert traceable coins into usable cash.
The Bybit hack, linked to North Korea by the FBI under the code name TraderTraitor, highlights the risks of storing crypto on exchanges. While individual wallet holders were not directly affected, the breach underscores the vulnerability of exchange-held funds. Crypto holders should evaluate the security of third-party platforms versus self-custody to mitigate risks.