Chinese Network Laundered $1B in Stolen Crypto for North Korea
Blockchain investigator ZachXBT has exposed a Chinese organized crime network that allegedly laundered over $1 billion in stolen cryptocurrency for North Korea’s Lazarus Group. In an investigation that began in February 2025, ZachXBT posed as a client to infiltrate the operation, depositing $349,700 in stablecoins and accepting a 5% loss on each transaction to gain the trust of a key operator known as “Jimmy Green.” The network’s activities spanned Hong Kong and mainland China, with ZachXBT identifying a cluster of more than $12 million in funds linked to the Bybit hack. Tether later froze $442,000 in associated USDt (USDT) as part of the investigation.
The probe provides a rare glimpse into the intermediaries facilitating North Korea’s crypto thefts. Hackers tied to the country have stolen at least $6.75 billion in digital assets by 2025, according to Chainalysis. North Korean hackers typically use a multi-stage laundering process, including chain-hopping and token swapping through decentralized exchanges and bridges to obscure the flow of funds. Chinese intermediaries have played a crucial role in this process, with U.S. prosecutors previously charging two Chinese nationals in 2020 for laundering over $100 million stolen by North Korean hackers.
ZachXBT’s findings also extend to other high-profile crypto exploits. The investigator linked Chinese actors to the laundering of funds from the $387.5 million Bitget exploit in September 2023. Additionally, one of the operators had previously been involved in laundering funds from the $292 million Kelp DAO exploit in April. These revelations underscore the growing role of Chinese intermediaries in the illicit conversion of stolen cryptocurrency.