ZachXBT Reveals Chinese Network Laundered Over $1B in Lazarus-Stolen Crypto
Blockchain investigator ZachXBT has uncovered a Chinese organized crime network allegedly responsible for laundering over $1 billion stolen by North Korea’s Lazarus Group in multiple crypto exploits. His investigation began in February 2025, shortly after a major hack on the exchange Bybit. ZachXBT infiltrated the laundering operation by posing as a client, depositing $349,700 in stablecoins and accepting a 5% loss on each transaction to gain the trust of an operator named “Jimmy Green.”
Through this infiltration, ZachXBT gathered information that helped him trace more than $12 million in funds linked to the Bybit hack. Tether later froze $442,000 in associated USDt, disrupting the laundering pipeline. The investigation highlights the complex, multi-stage laundering process often used by North Korean hackers, involving chain-hopping, token swaps, and external intermediaries.
The findings align with previous U.S. and Treasury actions targeting alleged crypto traders connected to laundering North Korean stolen funds. In 2020, two Chinese nationals were charged with laundering over $100 million in stolen crypto, and in 2023, the U.S. Treasury sanctioned two traders for their role in converting stolen crypto. These cases underscore the importance of intermediaries in laundering operations.
ZachXBT’s investigation also revealed that Chinese actors involved in laundering funds from other Lazarus-associated incidents, such as the $387.5 million Bitget exploit and the $292 million Kelp DAO exploit, had sought support in public Discord and Telegram channels. This suggests that laundering networks may sometimes expose operational details through public recruitment efforts.