Chinese crime network laundered over $1B for Lazarus: ZachXBT
ZachXBT says he infiltrated the network by posing as a customer, gaining information that helped trace funds from the $1.5 billion Bybit hack.
According to blockchain investigator ZachXBT, a Chinese organized crime syndicate laundered more than $1 billion stolen from multiple crypto exploits for North Korea's Lazarus Group. He infiltrated the money laundering network by posing as a paying client in February 2025, after the Bybit hack. ZachXBT gained the trust of a network operator known as "Jimmy Green" by investing $349,700 in stablecoins, ultimately incurring a 5% loss on each order.
The operations spanned Hong Kong and mainland China. Information supplied by the launderer helped identify over $12 million in Bybit-linked funds, with Tether freezing $442,000 in associated USDt (USDT). This investigation provides rare insight into the intermediaries handling North Korea's stolen crypto, as hackers have stolen at least $6.75 billion in digital assets through 2025.
Chinese actors have emerged as key links in the North Korean hackers' multi-stage laundering process, which involves chain-hopping and token swapping through decentralized exchanges, bridges, and other services. In 2023, the US Department of the Treasury sanctioned two crypto traders from Hong Kong and China for their role in helping North Korea convert stolen crypto and bypass financial controls.
Written by urgent.news from Cointelegraph's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.