ZachXBT Reveals Chinese Network Laundering $1B in Lazarus Hacked Crypto
Blockchain investigator ZachXBT has uncovered a Chinese organized crime network allegedly responsible for laundering over $1 billion in cryptocurrency stolen by North Korea's Lazarus Group. The investigation, detailed in a recent post on X, involved ZachXBT infiltrating the laundering operation in February 2025, just days after a major Bybit hack. By posing as a client, ZachXBT transferred $349,700 in stablecoins and accepted a 5% loss on each transaction to build trust with an operator known as "Jimmy Green."
The infiltration provided ZachXBT with critical information, allowing him to trace more than $12 million in funds linked to the Bybit hack. Tether later froze $442,000 in associated USDt, disrupting the flow of stolen assets. The investigation highlights the complex, multi-stage laundering processes often used by North Korean hackers, including chain-hopping and token swaps across decentralized exchanges and bridges.
This case aligns with previous regulatory actions targeting Chinese intermediaries involved in laundering North Korean stolen funds. In 2020, U.S. prosecutors charged two Chinese nationals with laundering over $100 million in stolen crypto, and in 2023, the U.S. Treasury sanctioned two crypto traders for their roles in aiding North Korea's financial operations. These actions underscore the importance of identifying intermediary actors in disrupting laundering networks.
The broader context reveals that North Korea-linked hackers have stolen at least $6.75 billion in digital assets through 2025, according to Chainalysis. The volume and complexity of these thefts pose significant challenges for exchanges, stablecoin issuers, and compliance teams. ZachXBT's investigation also points to the potential exposure of laundering networks through public recruitment efforts, such as those seen in Discord and Telegram channels. The next steps to watch include whether additional issuers or exchanges take action based on similar tracing efforts and whether regulators expand enforcement efforts targeting regional intermediaries.