A Chinese organized crime syndicate laundered more than $1 billion stolen in multiple crypto exploits for North Korea’s Lazarus Group, according to blockchain investigator ZachXBT.
Chinese crime network laundered over $1B for Lazarus: ZachXBT
ZachXBT says he infiltrated the network by posing as a customer, gaining information that helped trace funds from the $1.5 billion Bybit hack.
Cointelegraph by Felix Ng
Publisher Cointelegraph
Oct 6, 2026 at 1:47 AM UTC · 2 Min. Lesezeit

In an Oct. 5 thread on X, pseudonymous blockchain investigator ZachXBT said he posed as a paying client to infiltrate the money laundering network in February 2025, just days after the Bybit hack. He put up $349,700 in stablecoins and took a 5% loss on each order to build trust with one of the network’s operators, known as “Jimmy Green.”
ZachXBT said the operations spanned Hong Kong and mainland China, and information supplied by the launderer helped him identify a cluster of more than $12 million in Bybit-linked funds, with Tether later freezing $442,000 in associated USDt (USDT).
The investigation offers rare insight into the alleged intermediaries handling North Korea’s stolen crypto. Hackers linked to the country have stolen at least $6.75 billion in digital assets through 2025, according to Chainalysis.
How North Korea moves stolen crypto
North Korean hackers are known to use a multi-stage laundering process. One method involves chain-hopping and token swapping through decentralized exchanges, bridges and other services to obscure the flow of funds.
Article Intelligence
Topics
Related Coverage
View all relatedSponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
