Cointelegraph
DOGE$0.09615 1.66%
TRX$0.3356 0.18%
LINK$14.04 1.75%
ZEC$1,372.84 5.65%
ADA$0.2737 3.01%
XRP$1.51 1.50%
ETH$2,716.07 0.59%
BTC$86,267.54 1.10%
XMR$562.61 1.24%
BNB$785.70 0.25%
XLM$0.2153 1.36%
SOL$121.28 1.52%
HYPE$92.80 0.12%
Written by Felix Ngstaff editorEdited by Yohan Yunstaff editor

Chinese crime network laundered over $1B for Lazarus: ZachXBT

Latest NewsPublishedOct 6, 2026

ZachXBT says he infiltrated the network by posing as a customer, gaining information that helped trace funds from the $1.5 billion Bybit hack.

A Chinese organized crime syndicate laundered more than $1 billion stolen in multiple crypto exploits for North Korea’s Lazarus Group, according to blockchain investigator ZachXBT. 

In an Oct. 5 thread on X, pseudonymous blockchain investigator ZachXBT said he posed as a paying client to infiltrate the money laundering network in February 2025, just days after the Bybit hack. He put up $349,700 in stablecoins and took a 5% loss on each order to build trust with one of the network’s operators, known as “Jimmy Green.”

ZachXBT said the operations spanned Hong Kong and mainland China, and information supplied by the launderer helped him identify a cluster of more than $12 million in Bybit-linked funds, with Tether later freezing $442,000 in associated USDt (USDT). 

The investigation offers rare insight into the alleged intermediaries handling North Korea’s stolen crypto. Hackers linked to the country have stolen at least $6.75 billion in digital assets through 2025, according to Chainalysis. 

How North Korea moves stolen crypto

North Korean hackers are known to use a multi-stage laundering process. One method involves chain-hopping and token swapping through decentralized exchanges, bridges and other services to obscure the flow of funds.

Related: SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit

Chinese intermediaries have emerged as an important link in that process. In 2020, US prosecutors charged two Chinese nationals with laundering more than $100 million stolen by North Korean hackers from a cryptocurrency exchange in 2018. 

Source: ZachXBT

In 2023, the US Department of the Treasury’s Office of Foreign Assets Control (OFAC) sanctioned two crypto traders, one from Hong Kong and the other from China, for their role in helping the DPRK convert stolen crypto and bypass financial controls. 

Chinese actors allegedly laundering Bitget funds

ZachXBT has also linked Chinese actors to the laundering of funds from the $387.5 million Bitget exploit in September. 

In a post to X on Sept. 28, ZachXBT said Chinese actors allegedly laundering funds on behalf of the North Korean hackers had been openly seeking support in public Discord servers and Telegram channels operated by services they used. ZachXBT said one of the operators had also been involved in laundering funds from the $292 million Kelp DAO exploit in April. 

Magazine: Furious debate about THORChain vs NEAR shows idealism has limits

1 minute letter

Subscribe to daily byte-sized crypto news from Cointelegraph

Subscribe
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

More on the subject