Skip to main content

ZachXBT: Lazarus Laundered $1B+ via China Criminal Network



Blockchain investigator ZachXBT says a Chinese organized crime network helped launder more than $1 billion stolen in multiple crypto exploits tied to North Korea’s Lazarus Group. The claim comes from an investigation that ZachXBT conducted by infiltrating an alleged money-laundering operation in February 2025, shortly after a major Bybit hack.


In an Oct. 5 post on X, ZachXBT described how he posed as a paying client to gain access to the laundering pipeline. He said he provided $349,700 in stablecoins and accepted a 5% loss on each order to build trust with an operator known as “Jimmy Green.” ZachXBT also said information from the laundering network helped him identify a cluster of more than $12 million linked to Bybit, and that Tether later froze $442,000 in associated USDt.



Key takeaways



  • ZachXBT alleges a Chinese intermediary network laundered over $1 billion stolen by Lazarus Group across multiple exploits.

  • The investigation described an infiltration attempt that ZachXBT said began in February 2025, days after the Bybit hack.

  • ZachXBT says data he received helped flag more than $12 million tied to Bybit activity, with Tether freezing $442,000 of related USDT.

  • The story reinforces a broader pattern: North Korea-linked theft often relies on multi-stage laundering involving chain-hopping, token swaps, and external intermediaries.

  • Previous U.S. and Treasury actions show regulators have repeatedly targeted alleged crypto traders connected to laundering proceeds from North Korean activity.



Infiltration tied to Bybit proceeds


ZachXBT said the laundering operation involved contacts across Hong Kong and mainland China and that an operator called “Jimmy Green” was part of the process. According to his account, he deliberately structured his interaction to appear credible to the network, using stablecoins and accepting consistent small losses on orders.


The stated outcome of the infiltration was twofold: first, establishing enough trust to gather information, and second, using that information to trace stolen funds. ZachXBT said the details he received allowed him to identify a cluster of more than $12 million in funds linked to the Bybit hack, and that Tether later froze $442,000 of associated USDt.


While the claims are significant, the practical takeaway for market participants is the reminder that investigations often depend on cooperation with or access to intermediary actors—especially when funds have already been routed through swaps, bridges, and other obfuscation services. Freezes like Tether’s can disrupt liquidity, but tracing and attribution frequently require more than on-chain pattern analysis alone.



Why intermediaries matter in North Korea laundering


North Korea-linked campaigns are often described as running stolen crypto through layered steps intended to reduce traceability. One common approach is chain-hopping and token swapping across decentralized exchanges, bridges, and other services that can fragment transaction histories and complicate attribution.


ZachXBT’s allegation of a Chinese intermediary network fits a wider public record of how regulators and prosecutors have approached similar cases. In 2020, U.S. prosecutors charged two Chinese nationals with laundering more than $100 million stolen by North Korean hackers from a cryptocurrency exchange in 2018. Earlier, that same pattern of intermediaries has also shown up in sanctions actions: in 2023, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) sanctioned two crypto traders—one from Hong Kong and one from China—over their alleged role in helping the DPRK convert stolen crypto and bypass financial controls.


These earlier actions do not prove any specific network involved in the latest allegation, but they help explain why investigators focus on regional intermediary roles. When stolen funds move quickly, attribution often hinges on identifying the nodes that reliably convert or move value between ecosystems.



Context from broader reporting on DPRK-linked theft


The ZachXBT investigation arrives at a time when industry researchers have continued to report substantial DPRK-associated theft. According to Chainalysis, hackers linked to North Korea have stolen at least $6.75 billion in digital assets through 2025.


That figure underscores the operational challenge for exchanges, stablecoin issuers, and compliance teams: the volume of stolen funds, combined with laundering complexity, means that detection and response must operate at multiple levels. On-chain monitoring can flag suspicious activity, but enforcement and remediation often depend on knowing how intermediaries interact with centralized actors—whether through deposits, conversions, or other touchpoints.



Earlier allegations involving other exploits and public channels


ZachXBT has also previously linked Chinese actors to laundering activity related to other Lazarus-associated incidents. In a separate X post on Sept. 28, he said Chinese actors allegedly involved in laundering funds connected to a $387.5 million Bitget exploit had been seeking support in public Discord servers and Telegram channels used by services in their laundering process.


In the same vein, ZachXBT said one operator he identified had also been involved in laundering funds from the $292 million Kelp DAO exploit in April. While these claims reflect an investigative narrative rather than a court outcome, they point to a potentially important shift: intermediaries may not always hide entirely. When laundering support networks recruit assistance through public communities, it can expose operational details—such as messaging workflows, service names, or recurring participants—that later become useful to investigators.


For readers, the key question is what changes next. ZachXBT’s latest claim centers on an alleged pipeline that can be traced to a Bybit-connected cluster and a subsequent Tether freeze. The next signals to watch are whether additional issuers or exchanges take action after similar tracing work, and whether regulators expand enforcement tied to the regional intermediary roles highlighted across multiple public cases.


As investigators keep probing the connections between stolen funds, regional facilitators, and stablecoin ecosystems, the most important development to monitor will be whether interdictions and freezes scale beyond isolated clusters—since that’s often where deterrence becomes tangible for actors attempting to convert stolen crypto into usable value.



https://www.cryptobreaking.com/zachxbt-lazarus-laundered-1b-via/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=ZachXBT:%20Lazarus%20Laundered%20$1B+%20via%20China%20Criminal%20Network%20

Comments

Popular posts from this blog

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...