ZachXBT Exposes $1B+ China Laundering Network Tied to North Korea Hackers
Blockchain investigator ZachXBT has uncovered evidence suggesting that a Chinese organized crime syndicate played a key role in laundering over $1 billion stolen by North Korea’s Lazarus Group. In an Oct. 5 thread on X, ZachXBT detailed how intermediaries facilitated the movement of stolen funds through various crypto exploits, highlighting the complex networks involved in laundering DPRK-linked funds.
ZachXBT’s investigation began in February 2025, shortly after the Bybit hack. Posing as a client, he infiltrated part of the laundering operation by providing $349,700 in stablecoins and accepting a 5% loss on each order. This undercover approach helped him identify an intermediary named “Jimmy Green” and trace over $12 million in funds linked to the Bybit hack. Tether later froze $442,000 in associated USDT, demonstrating the potential for compliance actions based on identifiable laundering trails.
The broader pattern aligns with previous actions by US authorities, which have targeted Chinese facilitators for converting stolen crypto and bypassing financial controls. North Korean hackers often rely on multi-stage laundering techniques, including chain-hopping and token swapping, to obscure the origin of stolen funds. Regional intermediaries play a critical role in this process, reducing friction in converting illicit proceeds into harder-to-trace assets.
ZachXBT’s findings also suggest that the laundering process may not be entirely hidden. Public messaging channels like Discord and Telegram have been used by intermediaries to recruit support, providing investigators with additional visibility into these operations. The investigation has linked Chinese actors to multiple high-profile exploits, including the $292 million Kelp DAO exploit in April and the $387.5 million Bitget exploit in September, indicating a recurring pattern of involvement.