Home/news/Chinese crime network laundered more than $1 billion for Lazarus, ZachXBT says
news
Chinese crime network laundered more than $1 billion for Lazarus, ZachXBT says
Payments High Risk
6 Oct 2026 · 1 min read
A Chinese organized crime syndicate allegedly laundered more than $1 billion stolen in multiple crypto exploits for North Korea’s Lazarus Group, according to blockchain investigator ZachXBT. For PSPs and compliance teams, the useful part is not the headline number itself but the operating pattern: cross-border intermediaries, stablecoin settlement, and repeated use of the same laundering infrastructure across separate hacks.
In an Oct. 5 thread on X, ZachXBT said he infiltrated the network in February 2025 by posing as a paying client, just days after the Bybit hack. He said he deposited $349,700 in stablecoins and accepted a 5% loss on each order to build trust with one operator known as “Jimmy Green.”
ZachXBT said the laundering activity spanned Hong Kong and mainland China. Information provided by the launderer helped him identify a cluster of more than $12 million in Bybit-linked funds, and Tether later froze $442,000 in associated USDt (USDT).
The investigation gives a rare look at the intermediaries allegedly moving North Korea’s stolen crypto. According to Chainalysis, hackers linked to North Korea have stolen at least $6.75 billion in digital assets through 2025.
North Korean hackers are known to use multi-stage laundering: chain-hopping and token swapping through decentralized exchanges, bridges, and other services to obscure fund flows. The thing is, that process still needs off-ramps and human operators, which is where Chinese intermediaries keep showing up.
The pattern is not new. In 2020, US prosecutors charged two Chinese nationals with laundering more than $100 million stolen by North Korean hackers from a cryptocurrency exchange in 2018. In 2023, OFAC sanctioned two crypto traders, one from Hong Kong and the other from China, for helping the DPRK convert stolen crypto and bypass financial controls.
ZachXBT also linked Chinese actors to laundering proceeds from the $387.5 million Bitget exploit in September. On Sept. 28, he said the actors were openly seeking support in public Discord servers and Telegram channels operated by services they used, and that one operator had also been involved in laundering funds from the $292 million Kelp DAO exploit in April.