Chinese Crime Network Laundered Over $1B for North Korea's Lazarus Group: ZachXBT
Key Takeaways
- •On-chain investigator ZachXBT alleges a Chinese organized crime syndicate moved more than $1 billion in stolen crypto for North Korea's Lazarus Group across multiple exploits.
- •In February 2025, ZachXBT infiltrated the laundering network by posing as a client, posting $349,700 in stablecoins and accepting a 5% loss per order to earn an operator's trust.
- •The laundering operation ran through Hong Kong and mainland China, and intelligence from it helped identify over $12 million in Bybit-linked funds, of which Tether froze $442,000 in USDt.
- •DPRK-linked hackers have stolen at least $6.75 billion in digital assets through 2025, per Chainalysis, and UN experts estimate cyber theft funds up to half of North Korea's weapons of mass destruction programs.
- •ZachXBT has also tied Chinese actors to laundering proceeds from the $387.5 million Bitget exploit, with one operator allegedly involved in the $292 million Kelp DAO hack in April.

A Chinese organized crime syndicate laundered more than $1 billion stolen in multiple crypto exploits on behalf of North Korea's Lazarus Group, according to on-chain investigator ZachXBT.
In an Oct. 5 thread on X, the pseudonymous investigator said he posed as a paying client to infiltrate the laundering network in February 2025, days after the Bybit hack, the roughly $1.46 billion theft attributed to North Korea's Lazarus Group and the largest crypto theft on record. To build trust with one of the network's operators, known as “Jimmy Green,” he put up $349,700 in stablecoins and accepted a 5% loss on each order.
ZachXBT said the operation spanned Hong Kong and mainland China. Information supplied by the launderer helped him identify a cluster of more than $12 million in Bybit-linked funds, and Tether later froze $442,000 in associated USDt (USDT).
The investigation offers rare insight into the alleged intermediaries handling North Korea's stolen crypto. According to Chainalysis, hackers linked to the country have stolen at least $6.75 billion in digital assets through 2025. United Nations experts have estimated that cyber theft proceeds fund up to half of North Korea's weapons of mass destruction programs, which is why the laundering rails themselves have become a recurring focus of US sanctions and criminal actions.
How North Korea moves stolen crypto
North Korean hackers are known to use a multi-stage laundering process. One method involves chain-hopping and token swaps through decentralized exchanges, bridges and other services to obscure the flow of funds, and Chinese intermediaries have emerged as an important link in that process, in part because sanctions have cut the country off from much of the traditional banking system.
In 2020, US prosecutors charged two Chinese nationals with laundering more than $100 million stolen by North Korean hackers from a cryptocurrency exchange in 2018, according to the US Department of Justice. That case detailed how over-the-counter brokers convert stolen crypto into fiat currency on behalf of North Korean clients.
Source: ZachXBT
In 2023, the US Department of the Treasury's Office of Foreign Assets Control (OFAC) sanctioned two crypto traders, one from Hong Kong and the other from China, for their role in helping the DPRK convert stolen crypto and bypass financial controls. Treasury has framed such designations as part of an effort to cut off the revenue streams behind the country's weapons programs.
Related: SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit
Chinese actors allegedly laundering Bitget funds
ZachXBT has also linked Chinese actors to the laundering of funds from the $387.5 million Bitget exploit in September. In a post to X on Sept. 28, he said Chinese actors allegedly laundering funds on behalf of the North Korean hackers had been openly seeking support in public Discord servers and Telegram channels operated by services they used.
He added that one of the operators had also been involved in laundering funds from the $292 million Kelp DAO exploit in April — an overlap that shows the same operators have repeatedly appeared across separate exploits.
Magazine: Furious debate about THORChain vs NEAR shows idealism has limits