Undercover Investigation Reveals North Korea’s Billion-Dollar Crypto Laundering Network
Blockchain investigator ZachXBT infiltrated a Chinese money-laundering network tied to North Korea’s Lazarus Group, revealing a sprawling operation that has moved over $1 billion in stolen cryptocurrency. Posing as a client, ZachXBT transferred 349,700 USDC to an Ethereum address and interacted with a vendor named “Jimmy Green.” Over weeks, he documented the network’s operations, including plans to launder funds from the February 2025 Bybit hack, which later materialized as described.
The Bybit hack, the largest crypto theft in history at $1.4 to $1.5 billion, was just one of several exploits processed by this laundering infrastructure. ZachXBT’s findings led Tether to freeze 442,000 USDT linked to the Bybit theft, though this represents only a fraction of the operation’s scale. The network’s reach extended to the September 24, 2026 Bitget hack, where Chinese actors moved funds through mixers like Wasabi, according to public communications on Discord and Telegram.
ZachXBT identified recurring aliases such as Cc, Jack, and lolo (also known as Marin), who was linked to the $292 million Kelp DAO exploit. The consistency of these actors and methods suggests North Korea has developed a durable laundering supply chain rather than relying on ad-hoc operations. This poses a significant challenge for compliance teams, as the network’s sophistication makes it difficult to dismantle through freeze orders alone.
The investigation highlights the limitations of post-hack interventions. While Tether and other issuers have frozen stablecoins tied to Lazarus, these actions act as a tax on the operation rather than shutting it down. ZachXBT’s undercover work has provided more insights into the laundering pipeline than exchange compliance departments have managed independently.