ZachXBT Exposes Chinese Laundering Network Tied to Lazarus Group
Blockchain investigator ZachXBT has uncovered a Chinese organized crime network allegedly involved in laundering over $1 billion in cryptocurrency stolen by North Korea’s Lazarus Group. The investigation began in February 2025, shortly after a major hack on the Bybit exchange. ZachXBT posed as a client to infiltrate the laundering operation, transferring $349,700 in stablecoins and accepting a 5% loss on each transaction to build trust with an operator known as “Jimmy Green.”
Through this infiltration, ZachXBT gathered enough information to identify a cluster of more than $12 million in funds linked to the Bybit hack. Tether later froze $442,000 in associated USDt, disrupting the laundering process. The investigation highlights the complex multi-stage laundering tactics used by North Korean hackers, which often involve chain-hopping, token swaps, and intermediaries in regions like Hong Kong and mainland China.
The findings align with previous U.S. and Treasury actions targeting crypto traders connected to laundering North Korean stolen funds. Regulators have repeatedly focused on intermediary actors who facilitate the conversion of stolen crypto. ZachXBT’s investigation underscores the importance of cooperation with these intermediaries in tracing and freezing stolen assets.
This case is part of a broader pattern of DPRK-linked theft, with Chainalysis reporting that North Korean hackers have stolen at least $6.75 billion in digital assets through 2025. The volume and complexity of these thefts present significant challenges for exchanges, stablecoin issuers, and compliance teams, requiring multi-level detection and response strategies.