ZachXBT Uncovers $1B+ Crypto Laundering Scheme Linked to Lazarus Group
Blockchain investigator ZachXBT has uncovered evidence suggesting that a Chinese organized crime syndicate laundered over $1 billion in funds stolen by North Korea's Lazarus Group through multiple crypto exploits. The detailed allegations, shared in an October 5 thread on X, reveal how intermediaries facilitate the movement of DPRK-linked funds across exchanges and on-chain routes.
ZachXBT claims to have infiltrated part of the laundering operation in February 2025, just days after the Bybit hack, by posing as a paying client. He provided $349,700 in stablecoins and accepted a 5% loss on each order to build credibility with an intermediary identified as “Jimmy Green.” This undercover approach helped him identify a cluster of more than $12 million in funds linked to the Bybit hack, leading Tether to freeze $442,000 in associated USDT.
The investigation highlights the critical role of regional intermediaries in laundering stolen crypto. Lazarus Group reportedly relies on multi-stage laundering techniques, including chain-hopping and token swapping across decentralized exchanges, to obscure the origin of stolen funds. Chinese facilitators appear to be key players in this process, helping convert illicit proceeds into harder-to-trace assets.
ZachXBT's findings align with prior US and Treasury actions targeting Chinese facilitators. In 2020, two Chinese nationals were charged with laundering over $100 million stolen by North Korean hackers. Similarly, in 2023, the US Treasury sanctioned two crypto traders for aiding the DPRK in converting stolen crypto. The pattern suggests that enforcement and compliance tools are increasingly focused on identifying and disrupting these intermediary networks.