Chinese syndicate laundered over $1 billion for North Korea's Lazarus Group, investigator says

Blockchain sleuth ZachXBT claims he infiltrated the network by posing as a paying client after February's Bybit hack

By LineZotpaper
Published
Read Time1 min
A Chinese organized crime syndicate laundered more than $1 billion stolen in multiple cryptocurrency exploits for North Korea's Lazarus Group, according to pseudonymous blockchain investigator ZachXBT, who said he infiltrated the network by posing as a customer.

In an Oct. 5 thread on X, ZachXBT reported that he posed as a paying client to infiltrate the money laundering network in February 2025, just days after the $1.5 billion Bybit hack. The investigator said he put up $349,700 in stablecoins and accepted a 5% loss on each order to build trust with one of the network's operators, known as “Jimmy Green.”

ZachXBT stated that the operations spanned multiple activities, though further details of the network's full scope were not disclosed in his initial post. The investigator has previously tracked funds from high-profile crypto thefts attributed to the Lazarus Group, a state-linked North Korean hacking collective.

The Bybit hack, one of the largest crypto exchange thefts on record, has drawn increased scrutiny of laundering networks that help North Korea convert stolen digital assets into usable funds. Chinese criminal networks have long been suspected of facilitating such operations, but ZachXBT's infiltration claim provides rare first-hand insight into the mechanics of the pipeline.

§

Analysis

Why This Matters

  • The scale of laundering – over $1 billion – underscores how North Korea's cyber operations rely on transnational criminal networks to convert stolen crypto into fiat currency.
  • ZachXBT's infiltration suggests that blockchain tracing techniques combined with undercover tactics can expose the human infrastructure behind anonymous crypto theft.
  • The connection to the Bybit hack (February 2025) keeps pressure on exchanges and regulators to strengthen anti-money laundering controls for large withdrawals.

Background

The Lazarus Group is a North Korean state-sponsored hacking unit blamed for numerous crypto exchange thefts, including the 2022 Axie Infinity bridge hack and the 2017 Yapian hack. Chinese money laundering syndicates have previously been identified as key intermediaries that move stolen funds through peer-to-peer platforms and over-the-counter desks. ZachXBT is a well-known independent blockchain investigator who has publicly traced funds from major exploits, often working with law enforcement.

Key Perspectives

[Law enforcement agencies]: Investigating transnational laundering networks requires coordination across jurisdictions; access to ZachXBT's intelligence could aid ongoing efforts to freeze assets and prosecute operators. [Crypto industry]: Exchanges and DeFi protocols face pressure to improve suspicious transaction monitoring, especially for large stablecoin movements that may indicate layering. [Critics/Skeptics]: Undercover methods involving paying criminals raise ethical questions about entrapment and the legality of staking real funds to build trust. The verifiability of ZachXBT's claims remains limited without independent corroboration.

What to Watch

  • Whether ZachXBT publishes additional evidence, such as wallet addresses or chat logs, that could enable law enforcement actions.
  • Any coordinated takedowns or sanctions against the named individuals and entities linked to the network.
  • The response from Binance, Bybit, and other exchanges regarding enhanced monitoring of stablecoin flows originating from known laundering patterns.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.