Chinese crime network laundered over $1B for Lazarus: ZachXBT

Blockchain investigator ZachXBT says he infiltrated a Chinese organized crime network that laundered more than $1 billion in crypto stolen by North Koreas Lazarus Group. By posing as a customer after the Oct. 2025 Bybit hack, he traced a cluster of linked funds and reported that Tether froze roughly $442,000 in related USDT.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished about 3 hours agoUpdated about 3 hours ago0 views
Chinese crime network laundered over $1B for Lazarus: ZachXBT

Why It Matters

The reporting sheds light on alleged on-the-ground intermediaries who convert and move large volumes of DPRK-linked stolen crypto, a key step in how nation-state-linked thefts are monetized and integrated into broader financial systems. Identifying these networks may help law enforcement and compliance teams target the laundering chain.

Key Facts

  • Investigator: ZachXBT (pseudonymous blockchain investigator)
  • Claimed laundered amount: More than $1 billion
  • Related hack mentioned: $1.5 billion Bybit hack (October 2025)
  • Undercover payment: $349,700 in stablecoins (used by ZachXBT to build trust)
  • Operator name cited: "Jimmy Green"

A pseudonymous blockchain investigator known as ZachXBT said he infiltrated a Chinese organized crime syndicate that laundered more than $1 billion in cryptocurrency stolen by North Koreas Lazarus Group. In an Oct. 5 thread on X, ZachXBT described posing as a paying customer days after the Bybit breach in 2025, using $349,700 in stablecoins and accepting a 5% loss on orders to gain the confidence of a network operator identified as "Jimmy Green."

According to ZachXBT, the syndicates operations covered both Hong Kong and mainland China. Information he obtained from the alleged launderer pointed to a cluster of over $12 million connected to the Bybit theft; Tether later froze about $442,000 in USDt tied to those addresses. The account provides a rare, on-the-ground view of intermediaries who convert and move DPRK-linked stolen funds.

The report aligns with known laundering techniques attributed to North Korean-linked actors, who commonly employ multi-stage processes such as chain-hopping, token swaps, decentralized exchanges and cross-chain bridges to obfuscate fund flows. ZachXBT also linked Chinese actors to laundering activity following other significant breaches: he reported connections to the $387.5 million Bitget exploit in September and said one operator had been involved in laundering proceeds from a $292 million exploit of Kelp DAO in April.

This account follows a broader history of alleged Chinese intermediaries assisting DPRK-related thefts: U.S. prosecutors charged two Chinese nationals in 2020 over laundering more than $100 million stolen by North Korean hackers in 2018, and the U.S. Treasurys OFAC sanctioned two crypto traders in 2023 for helping the DPRK convert stolen crypto and evade financial controls. Chainalysis data cited in the source places total DPRK-linked crypto thefts at least $6.75 billion through 2025.

Keep Reading