Chinese crime network laundered over $1B for Lazarus: ZachXBT
A Chinese organized crime syndicate allegedly laundered over $1 billion in stolen crypto for North Korea's Lazarus Group, according to blockchain investigator ZachXBT.
Intelligence analysis by Gemini 2.5 Flash

Blockchain investigator ZachXBT claims to have infiltrated a Chinese money laundering network by posing as a client, uncovering its role in processing over $1 billion in stolen cryptocurrency for North Korea's Lazarus Group, including funds from the Bybit hack. This investigation provides rare insight into the intermediaries facilitating state-sponsored crypto theft.
Imagine a sneaky group of digital thieves from a country called North Korea who steal lots of digital money, like coins in a video game. They then give this stolen money to a secret group of helpers in China. These helpers are like a special cleaning service that makes the stolen money look brand new so no one can tell it was stolen. A digital detective named ZachXBT pretended to be a customer to join this cleaning service and found out how they helped the thieves hide over a billion dollars, which is like a huge pile of candy that disappeared from a store.
Analysis
ZachXBT's Infiltration
Blockchain investigator ZachXBT successfully infiltrated a sophisticated Chinese money laundering network by posing as a paying client. This operation, initiated in February 2025, just days after the Bybit hack, involved ZachXBT depositing $349,700 in stablecoins and accepting a 5% loss on each transaction to build trust with a network operator known as "Jimmy Green." This daring approach allowed him to gain unprecedented access to the network's operations, which spanned both Hong Kong and mainland China.
The information gathered during this infiltration proved crucial. It enabled ZachXBT to identify a cluster of over $12 million in funds directly linked to the Bybit hack. Following his findings, Tether took action, freezing $442,000 in associated USDt (USDT), demonstrating the tangible impact of such investigative efforts in disrupting illicit financial flows and recovering stolen assets. This incident provides a rare glimpse into the operational mechanics of the alleged intermediaries that facilitate North Korea's extensive crypto theft.
Lazarus Group's Modus Operandi
North Korea's Lazarus Group is notorious for its prolific crypto hacking activities, having stolen an estimated $6.75 billion in digital assets through 2025, according to Chainalysis. Their laundering process is typically multi-staged and complex, designed to obscure the origin and flow of funds. A common method involves "chain-hopping" and "token swapping" across various decentralized exchanges, bridges, and other services, making it exceedingly difficult to trace the stolen assets.
Chinese intermediaries have emerged as a critical component in this elaborate laundering infrastructure. Their involvement is not new; as far back as 2020, U.S. prosecutors charged two Chinese nationals for laundering over $100 million stolen by North Korean hackers from a cryptocurrency exchange in 2018. More recently, in 2023, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) sanctioned two crypto traders, one from Hong Kong and one from China, for their direct role in assisting the Democratic People's Republic of Korea (DPRK) in converting stolen crypto and circumventing financial controls.
Bitget and Kelp DAO Exploits
ZachXBT's investigations extend beyond the Bybit hack, linking Chinese actors to other significant crypto exploits. He has connected these intermediaries to the laundering of funds from the $387.5 million Bitget exploit that occurred in September. In a public post on X, ZachXBT revealed that Chinese actors allegedly involved in laundering funds for North Korean hackers were openly seeking support in public Discord servers and Telegram channels associated with the services they utilized.
Furthermore, ZachXBT identified that one of the operators within this network was also implicated in laundering funds from the $292 million Kelp DAO exploit in April. These repeated connections across multiple high-profile hacks underscore the persistent and systemic nature of these laundering operations. The ability of these networks to facilitate the movement of hundreds of millions of dollars in stolen crypto highlights the ongoing challenge for law enforcement and blockchain security firms in combating state-sponsored cybercrime and protecting digital assets.
Key points
- A Chinese crime network laundered over $1 billion in stolen crypto for North Korea's Lazarus Group.
- Blockchain investigator ZachXBT infiltrated the network by posing as a client, gaining crucial intelligence.
- Information from the infiltration helped trace funds from the $1.5 billion Bybit hack, leading to Tether freezing $442,000 in USDt.
- Chinese intermediaries are a key link in North Korea's multi-stage crypto laundering process, which involves chain-hopping and token swapping.
- Chinese actors have also been linked to laundering funds from the $387.5 million Bitget exploit and the $292 million Kelp DAO exploit.
The successful infiltration by ZachXBT and the subsequent freezing of some stolen funds by Tether demonstrate that proactive investigative efforts can disrupt sophisticated money laundering networks. This could lead to improved security measures and better collaboration between blockchain investigators and asset issuers, potentially deterring future state-sponsored crypto thefts and increasing the chances of asset recovery.
The sheer scale of the laundered funds, exceeding $1 billion, highlights the persistent and sophisticated nature of state-sponsored cybercrime and the challenges in combating it. The continued reliance on Chinese intermediaries suggests a deeply entrenched network that may be difficult to fully dismantle, posing an ongoing threat to the security and integrity of the global cryptocurrency ecosystem.

